Skip to main content
You need a root key with the permissions listed on this page. Create one in the dashboard under Settings > Root Keys. See Permission reference for every permission.
List the keys of an API. Results come in pages. Pass the cursor from one response to get the next page. Calls POST /v2/apis.listKeys. See Listing keys.

Usage

Flags

string
required
Id of the API whose keys to list.
string
Cursor from the previous response’s pagination.cursor.
boolean
default:"false"
Include the plaintext key in each result. Only keys created with --recoverable have one, and the root key needs decrypt_key. The call fails with 412 unless the keyspace has key encryption turned on, which only we can do, through a support request.
string
Return only keys linked to the identity with this external id. An external id that matches no identity returns an empty page, not an error.
integer
Maximum number of keys per page. 1 to 100. Defaults to 100.
boolean
default:"false"
Accepted, but does nothing today.

Shared flags

Every unkey api command takes these. See CLI output and shared flags.
string
Root key used for the request. Falls back to UNKEY_ROOT_KEY, then to the key stored by unkey auth login.
string
default:"https://api.unkey.com"
Base URL of the API. Falls back to UNKEY_API_BASE_URL. You don’t normally need to set it.
string
default:"~/.unkey/config.toml"
Path of the config file written by unkey auth login. Falls back to UNKEY_CONFIG.
string
Output format. Falls back to UNKEY_OUTPUT. json prints the full response. Any other value prints the request ID and data.
string
Send this JSON as the whole request body instead of using the command’s flags. You can’t combine it with them.

Required permissions

api.*.read_key or api.<apiId>.read_key, together with api.*.read_api or api.<apiId>.read_api. --decrypt also needs api.*.decrypt_key or api.<apiId>.decrypt_key. Without the permission you get a 404, not a 403, so the response doesn’t reveal whether the API exists. See Root key permissions.

Examples

First page
Keys of one identity
Or send the whole request as JSON:
Raw body
Last modified on September 29, 2026