> ## Documentation Index
> Fetch the complete documentation index at: https://tbd-6fc993ce-hypeship-changelog-august-13.mintlify.site/llms.txt
> Use this file to discover all available pages before exploring further.

# List API keys

> List API keys for the authenticated organization. API keys are masked.



## OpenAPI

````yaml https://api.onkernel.com/spec.json get /org/api_keys
openapi: 3.1.0
info:
  description: Developer tools and cloud infrastructure for AI agents to use web browsers
  title: Kernel API
  version: 0.1.0
servers:
  - description: API Server
    url: https://api.onkernel.com
security:
  - bearerAuth: []
tags:
  - description: Create and manage browser sessions.
    name: Browsers
  - description: Control mouse, keyboard, and screen on the browser instance.
    name: Browser Computer Controls
  - description: Execute Playwright code against the browser instance.
    name: Browser Playwright
  - description: Read, write, and manage files on the browser instance.
    name: Browser Filesystem
  - description: Execute and manage processes on the browser instance.
    name: Browser Processes
  - description: Record and manage browser session video replays.
    name: Browser Replays
  - description: Stream logs from the browser instance.
    name: Browser Logs
  - description: Stream live telemetry events from a browser session.
    name: Browser Telemetry
  - description: Create, list, retrieve, and delete browser profiles.
    name: Profiles
  - description: Create and manage proxy configurations for routing browser traffic.
    name: Proxies
  - description: Create, list, retrieve, and delete browser extensions.
    name: Extensions
  - description: Create and manage browser pools for acquiring and releasing browsers.
    name: Browser Pools
  - description: Inspect the identity and authorization context for the current request.
    name: Authentication
  - description: >-
      Create and manage auth connections for automated credential capture and
      login.
    name: Managed Auth
  - description: Create and manage credentials for authentication.
    name: Credentials
  - description: Configure external credential providers like 1Password.
    name: Credential Providers
  - description: List applications and versions.
    name: Apps
  - description: Create and manage app deployments and stream deployment events.
    name: Deployments
  - description: Invoke actions and stream or query invocation status and events.
    name: Invocations
  - description: Read and manage organization-level limits.
    name: Organization
  - description: |
      Create and manage projects for resource isolation within an organization.
      When projects are disabled for the organization, project operations return
      `404` with code `projects_disabled`.
    name: Projects
  - description: Create and manage API keys for organization and project-scoped access.
    name: API Keys
  - description: Read audit log records for the authenticated organization.
    name: Audit Logs
  - description: Resolve browser and proxy recommendations for bot-protected sites.
    name: Site Configs
paths:
  /org/api_keys:
    get:
      tags:
        - API Keys
      summary: List API keys
      description: List API keys for the authenticated organization. API keys are masked.
      operationId: listApiKeys
      parameters:
        - description: Maximum number of results to return
          in: query
          name: limit
          required: false
          schema:
            default: 20
            maximum: 100
            type: integer
        - description: Number of results to skip
          in: query
          name: offset
          required: false
          schema:
            default: 0
            type: integer
        - description: >-
            Case-insensitive substring match against API key name, creator, and
            project. API key identifiers and masked keys match by exact value or
            prefix.
          in: query
          name: query
          required: false
          schema:
            type: string
        - description: >-
            Exact-match filter on API key name using the database collation. In
            production, matching is case- and accent-insensitive. Names are not
            required to be unique, so multiple keys may match. When status=all
            or include_deleted=true is set, soft-deleted keys with the same name
            may also match.
          in: query
          name: name
          required: false
          schema:
            type: string
        - description: Field to sort API keys by.
          in: query
          name: sort_by
          required: false
          schema:
            default: created_at
            enum:
              - created_at
              - name
              - expires_at
            type: string
        - description: Sort direction for API keys.
          in: query
          name: sort_direction
          required: false
          schema:
            default: desc
            enum:
              - asc
              - desc
            type: string
        - description: >-
            Filter API keys by status. "active" returns keys that are not
            deleted (default; expired-but-not-deleted keys are still included),
            "deleted" returns only soft-deleted keys, "all" returns both.
          in: query
          name: status
          required: false
          schema:
            default: active
            enum:
              - active
              - deleted
              - all
            type: string
        - deprecated: true
          description: >-
            Deprecated: use status=all instead. When true, include deleted
            (soft-deleted) API keys in the results for audit purposes.
          in: query
          name: include_deleted
          required: false
          schema:
            default: false
            type: boolean
      responses:
        '200':
          content:
            application/json:
              schema:
                items:
                  $ref: '#/components/schemas/ApiKey'
                type: array
          description: List of API keys
          headers:
            X-Has-More:
              description: Whether there are more results
              schema:
                type: boolean
            X-Next-Offset:
              description: >-
                The offset where the next page starts. 0 when there are no more
                results.
              schema:
                type: integer
        '401':
          $ref: '#/components/responses/Unauthorized'
        '500':
          $ref: '#/components/responses/InternalError'
      security:
        - bearerAuth: []
components:
  schemas:
    ApiKey:
      properties:
        created_at:
          description: When the API key was created
          format: date-time
          type: string
        created_by:
          $ref: '#/components/schemas/ApiKeyCreator'
        deleted_at:
          description: >-
            When the API key was deleted (soft-deleted). Null for keys that have
            not been deleted.
          format: date-time
          nullable: true
          type: string
        expires_at:
          description: When the API key expires
          format: date-time
          nullable: true
          type: string
        id:
          description: Unique API key identifier
          example: ckv9w8q2f000001l5r3j7k9m4
          type: string
        masked_key:
          description: Masked version of the API key
          example: sk_1234...abcd
          type: string
        name:
          description: >-
            Label for the API key. API keys are not addressable by name; use the
            ID or key identifier for stable references.
          example: production
          type: string
        project_id:
          description: Project identifier for project-scoped API keys. Null means org-wide.
          example: proj_abc123
          nullable: true
          type: string
        project_name:
          description: >-
            Project name for project-scoped API keys. Null means the key is
            org-wide or the project name is unavailable.
          example: Production
          nullable: true
          type: string
      required:
        - id
        - name
        - created_at
        - created_by
        - expires_at
        - deleted_at
        - project_id
        - project_name
        - masked_key
      type: object
    ApiKeyCreator:
      properties:
        email:
          description: Email address of the creator.
          example: user@example.com
          format: email
          type: string
        id:
          description: Kernel user ID of the creator.
          example: user-abc123
          type: string
        name:
          description: Display name of the creator, if available.
          example: Jane Doe
          nullable: true
          type: string
      required:
        - id
        - email
        - name
      type: object
    Error:
      properties:
        code:
          description: Application-specific error code (machine-readable)
          example: bad_request
          type: string
        details:
          description: Additional error details (for multiple errors)
          items:
            $ref: '#/components/schemas/ErrorDetail'
          type: array
        inner_error:
          $ref: '#/components/schemas/ErrorDetail'
        message:
          description: Human-readable error description for debugging
          example: 'Missing required field: app_name'
          type: string
      required:
        - code
        - message
      type: object
    ErrorDetail:
      properties:
        code:
          description: Lower-level error code providing more specific detail
          example: invalid_input
          type: string
        message:
          description: Further detail about the error
          example: Provided version string is not semver compliant
          type: string
      type: object
  responses:
    Unauthorized:
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
      description: Unauthorized – missing or invalid authorization token
    InternalError:
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
      description: Internal Server Error
  securitySchemes:
    bearerAuth:
      scheme: bearer
      type: http

````