> ## Documentation Index
> Fetch the complete documentation index at: https://docs.modulex.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# List API keys

> List all API keys for the current user. Only masked keys are returned — the full key is shown only once, at creation.



## OpenAPI

````yaml /api-reference/openapi.json get /api-keys
openapi: 3.0.3
info:
  title: ModuleX API
  version: 0.1.2
  description: >-
    ModuleX REST API. Authenticate with a user API key (`Authorization: Bearer
    mx_live_*`, or the `X-API-KEY` header) and supply the organization context
    header `X-Organization-ID` on org-scoped endpoints. Routers carry NO `/v1`
    version segment. Billing-gated surfaces (workflow run, managed knowledge
    search) reject before any write with a flat `DenialEnvelope` (402/403/429).
servers:
  - url: https://api.modulex.dev
    description: Production
security:
  - bearerAuth: []
    orgHeader: []
tags:
  - name: Workflows
    description: Create, read, update and delete workflow definitions.
  - name: Runs
    description: Execute workflows. Subject to the billing admission gate.
  - name: Schedules
    description: Recurring (cron / interval) workflow executions.
  - name: Knowledge
    description: Knowledge bases and semantic search.
  - name: Credentials
    description: Integration credentials (API key, bearer, OAuth2, ModuleX-managed).
  - name: Integrations
    description: Catalog of available tools, LLM providers and knowledge providers.
  - name: Organizations
    description: Organization management.
  - name: API keys
    description: User-owned API keys for programmatic access.
paths:
  /api-keys:
    get:
      tags:
        - API keys
      summary: List API keys
      description: >-
        List all API keys for the current user. Only masked keys are returned —
        the full key is shown only once, at creation.
      operationId: listApiKeys
      parameters:
        - name: include_revoked
          in: query
          required: false
          description: Include revoked keys in the response.
          schema:
            type: boolean
            default: false
      responses:
        '200':
          description: The user's API keys.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApiKeyListResponse'
        '401':
          $ref: '#/components/responses/Unauthorized'
components:
  schemas:
    ApiKeyListResponse:
      type: object
      required:
        - keys
        - total
        - max_keys
      properties:
        keys:
          type: array
          items:
            $ref: '#/components/schemas/ApiKey'
        total:
          type: integer
        max_keys:
          type: integer
          description: Maximum keys allowed per user.
    ApiKey:
      type: object
      description: API key details (without the secret).
      properties:
        id:
          type: string
          format: uuid
        name:
          type: string
        key_hint:
          type: string
          description: First 8 characters of the key.
          example: 2J9vK4xM
        masked_key:
          type: string
          example: mx_live_2J9vK4xM********
        organization_id:
          type: string
          nullable: true
          description: Organization scope (null = all orgs).
        expires_at:
          type: string
          format: date-time
          nullable: true
        is_expired:
          type: boolean
        is_active:
          type: boolean
        rate_limit_per_minute:
          type: integer
        last_used_at:
          type: string
          format: date-time
          nullable: true
        created_at:
          type: string
          format: date-time
        revoked_at:
          type: string
          format: date-time
          nullable: true
    Error:
      type: object
      description: Standard FastAPI error response.
      properties:
        detail:
          description: >-
            Human-readable error message, or a structured object (some endpoints
            return `{message, code, ...}`).
          oneOf:
            - type: string
            - type: object
              additionalProperties: true
  responses:
    Unauthorized:
      description: >-
        Authentication required or invalid. Provide `Authorization: Bearer
        <key>` or `X-API-KEY`.
      headers:
        WWW-Authenticate:
          schema:
            type: string
          description: Bearer
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      description: >-
        User API key: `Authorization: Bearer mx_live_*`. The `X-API-KEY:
        mx_live_*` header is also accepted.
    orgHeader:
      type: apiKey
      in: header
      name: X-Organization-ID
      description: Required organization context for org-scoped endpoints.

````