API Keys
List workspace API keys
Returns the API keys for a workspace. The secret key value is never returned; only its prefix and metadata are shown.
Request Body
application/json
TypeScript Definitions
Use the request body type in TypeScript.
Response Body
application/json
application/json
application/json
application/json
application/json
application/json
curl -X POST "https://loading/accounts.v1.Accounts/ListAPIKeys" \ -H "Content-Type: application/json" \ -d '{}'{
"apiKeys": [
{
"id": "CgsMDQ4PEBESExQVFhcYGQ==",
"name": "CI deploy key",
"keyPrefix": "gm_live_8f3a",
"workspaceId": "AAECAwQFBgcICQoLDA0ODw==",
"lastUsedAt": "2026-06-28T22:14:00Z",
"expiresAt": "2027-06-29T00:00:00Z",
"createdAt": "2026-06-29T12:00:00Z",
"policies": [
"trading",
"analytics"
]
}
]
}{
"code": "invalid_argument",
"message": "The request was malformed, such as a missing required field or an unparseable cursor."
}{
"code": "unauthenticated",
"message": "The request lacks a valid API key in the Authorization header."
}{
"code": "permission_denied",
"message": "The API key is not allowed to perform this action on this workspace."
}{
"code": "resource_exhausted",
"message": "The request was rate limited. Slow down and retry later."
}{
"code": "internal",
"message": "An internal server error occurred."
}DeleteAPIKey
Permanently revokes an API key. Requests authenticated with that key stop working immediately.
SetAPIKeyPolicies
Replaces the policies granted to an existing API key, changing what it may do without changing the key itself. The secret value is untouched, so every consumer keeps working. A recent two-factor re-verification is required, exactly as creating a key is.