KintsugiKintsugi

List API keys

GET/api-keys

List API keys. Requires a user credential (an Owner or Admin) or a PORTFOLIO-scope Api-Key. Select an organization with an Organization-Id to list that organization's keys (active toggles current vs archived); omit it to list a portfolio's keys if you are a portfolio Owner or Admin bearer. Paging is forward-only and offset-backed (the cursor encodes a page number, not a keyset bound): pass limit and the opaque cursor from a prior response's nextCursor to page forward; hasMore is false on the last page, and previousCursor / hasPrevious are always null/false. On a portfolio listing, optional scope (PORTFOLIO or ORGANIZATION) splits the mixed set for dual-table UIs; omit it for every key. A cursor is only valid for the limit, active, scope, and organization or portfolio it was issued under; change any of those and start from the first page.

Authorization

Api-KeystringRequired

Your secret API key. Include it with every request.

Headers

Api-Versiondate

Release date, as YYYY-MM-DD. Defaults to 2026-07-21.

Organization-Idstring

Target organization id (Organization-Id selector). Omit to manage portfolio keys as a bearer. Required for a PORTFOLIO-scope Api-Key, which may only manage one client org's keys at a time.

Connection-Idstring

Target connection id; resolves to its organization.

Entity-Idstring

Platform entity id; resolves to a connection's organization.

Entity-Sourcestring

Optional source to disambiguate an Entity-Id.

Query

Every query parameter below is optional. Combine as many as you need and append them to the endpoint as a query string. The example shows a few to get you started.

/api-keys?active=<active>&scope=<scope>&limit=<limit>
activeboolean

For an organization's own keys, list current (true, the default) or archived (false) keys. A portfolio or client listing has no archived state, so false is rejected there rather than ignored.

scopePublicApiKeyScopeEnum

On a portfolio listing (no Organization-Id), keep only PORTFOLIO keys or only ORGANIZATION keys (including null-scope legacy keys). Omit for the full mixed set. Rejected on an organization or client listing.

Available options:ORGANIZATIONPORTFOLIO
limitinteger

Maximum number of items to return.

cursorstring

Opaque cursor from a prior response's nextCursor or previousCursor. Omit for the first page.

Response

itemsApiKey[]Required

API keys on this page.

nextCursorstring

Opaque cursor for the next page, or null on the last page. Echo it as the request cursor to page forward. Pages are not a stable snapshot: if the key set changes while you walk it, a key can shift across a page boundary.

previousCursorstring

Always null: this family pages forward only.

hasMoreboolean

Whether a next page exists.

hasPreviousboolean

Always false: this family pages forward only.

200

Successful Response

400

The request was invalid.

401

Authentication failed or was missing.

403

The credential is not permitted for this request.

404

The requested resource was not found.

422

The request failed validation.

503

A service this request depends on was unavailable. Retry the request.

cURL
GET /api-keys?active={active}&scope={scope}&limit=50
-H "Api-Key: ***"
-H "Api-Version: 2026-07-21"
Example request
https://api.trykintsugi.com/api-keys?active={active}&scope={scope}&limit=50
Response
{
"items": [
{
"id": "3f6c2b1e-8a4d-4c2e-9b1f-2d7e5a6c9f10",
"scope": "ORGANIZATION",
"organizationId": "orgn_2mNpQr7Ls8f3k",
"clientOrganizationId": "3f6c2b1e-8a4d-4c2e-9b1f-2d7e5a6c9f10",
"clientOrganizationName": "Acme Corp",
"createdAt": "2026-07-28T12:00:00Z",
"expiresAt": "2026-07-28T12:00:00Z"
}
],
"nextCursor": "eyJpZCI6InRyYW5fMm1OcFFyN0xzOGYzayJ9",
"previousCursor": "eyJpZCI6InRyYW5fMm1OcFFyN0xzOGYzayJ9",
"hasMore": false,
"hasPrevious": false
}
List API keys (2026-07-21) | Kintsugi API Reference