# Read workspace api-keys

Every API key the workspace has minted across all its boards and pages in one place — each key's name, prefix, scopes, last use and revocation, never a secret — plus the scopes an admin may mint and the boards and pages a key can be pointed at. ADMIN AND ENTERPRISE only: a member of a lesser plan hears 403 for the seat before the plan is even considered. A board's own key routes are not gated this way.

Access class: `workspace:admin`.

## Endpoint

`GET /v1/workspace/api-keys`

## Parameters

| Name | In | Type | Required |
| --- | --- | --- | --- |
| body | query | null | No |
| params | query | object | No |
| query | query | object | No |

## Responses

### 200

the action's answer

Content type: `application/json`.

```json
{
  "data": {
    "keys": [
      {
        "boardId": "",
        "createdAt": "string",
        "definitionKey": "string",
        "id": "",
        "keyPrefix": "string",
        "lastUsedAt": "string",
        "memberEmail": "string",
        "name": "string",
        "rotatedAt": "string",
        "scopes": [
          "string"
        ],
        "targetLabel": "string"
      }
    ],
    "scopes": [
      "string"
    ],
    "targets": [
      {
        "id": "",
        "kind": "string",
        "label": "string"
      }
    ]
  }
}
```

### default

a refusal: `{"error": "<what a person needs to read>"}`. 401 no credential, 402 the plan does not include this, 403 the seat does not, 404 the thing does not exist or is not yours to see.

Content type: `application/json`.

```json
{
  "error": "string"
}
```
