# List API keys

> GET /api-keys — list your API keys (metadata only).

`GET /api-keys`

Lists your API keys. Each entry includes a non-secret token **prefix** (`token`) for display — the full secret is stored only as a hash and is shown once, at creation, never again. The `limit` parameter is optional — if you omit it, up to 1,000 keys are returned in one response, with `has_more` set to `true` when more exist beyond that ceiling. Page through the remainder with `after`.

> **Note:** Unlike creating, updating and revoking keys — which are [dashboard-only](https://www.sendping.co/docs/api/api-keys-create) — listing is unchanged and **is** callable with an API key. It is read-only: it returns metadata, never a secret.

**Query parameters**

| Name | Type | Required | Description |
| --- | --- | --- | --- |
| `limit` | number | No | Number of API keys to retrieve. Minimum `1`, maximum `100`. |
| `after` | string | No | The ID after which to retrieve more keys (pagination). The ID itself is excluded. Cannot be combined with `before`. |
| `before` | string | No | The ID before which to retrieve more keys (pagination). The ID itself is excluded. Cannot be combined with `after`. |

**Node.js**

```js
import { SendPing } from 'sendping';

const mb = new SendPing('mb_xxxxxxxxx');

const { data, error } = await mb.apiKeys.list();
console.log({ data, error });
```

**Ruby**

```ruby
require "sendping"

SendPing.api_key = "mb_xxxxxxxxx"

SendPing::ApiKeys.list
```

**PHP**

```php
<?php
require 'vendor/autoload.php';

use SendPing\SendPing;

$sendping = SendPing::client('mb_xxxxxxxxx');

$sendping->apiKeys->list();
```

**Python**

```python
import sendping

sendping.api_key = "mb_xxxxxxxxx"

sendping.ApiKeys.list()
```

**Go**

```go
import "github.com/shekhu10/sendping-sdks/sendping-go"

client := sendping.NewClient("mb_xxxxxxxxx")

keys, err := client.ApiKeys.List(nil)
```

**Rust**

```rust
use sendping::SendPing;

let mb = SendPing::new("mb_xxxxxxxxx");

let _keys = mb.api_keys.list(None).await?;
```

**Java**

```java
import co.sendping.SendPing;
import co.sendping.SendPingResponse;

SendPing sendping = new SendPing("mb_xxxxxxxxx");

SendPingResponse response = sendping.apiKeys().list();
```

**.NET**

```csharp
using SendPing;

ISendPing sendping = SendPingClient.Create("mb_xxxxxxxxx");

var resp = await sendping.ApiKeyListAsync();
```

**cURL**

```bash
curl -X GET 'https://www.sendping.co/api/api-keys' \
  -H 'Authorization: Bearer mb_xxxxxxxxx'
```

**CLI**

```bash
sendping api-keys list
```

### Response

Each entry carries the key `name`, a non-secret `token` prefix, its `permission` (`full_access` or `sending_access`), the `domain_ids` it is restricted to (`null` for account-wide keys; `domain_id` is the legacy single-domain field, set only when exactly one domain), `created_at`, and a `last_used_at` timestamp (`null` if the key has never been used). `has_more` indicates whether further pages exist.

```json
{
  "object": "list",
  "has_more": false,
  "data": [
    {
      "id": "1042",
      "name": "Production server",
      "token": "mb_AbC12",
      "permission": "full_access",
      "domain_id": null,
      "domain_ids": null,
      "created_at": "2026-06-23T10:00:00.000Z",
      "last_used_at": "2026-06-25T17:09:51.813Z"
    }
  ]
}
```
