> ## Documentation Index
> Fetch the complete documentation index at: https://www.rootset.app/llms.txt
> Use this file to discover all available pages before exploring further.

# List team keys

> List metadata for workspace-owned API keys. Administrators only.



## OpenAPI

````yaml api-reference/openapi.json GET /v1/orgs/{orgId}/keys
openapi: 3.1.2
info:
  title: Rootset public API
  version: 0.1.0
  description: >-
    Typed MDM storage. Temporal values are UTC only; IDs are opaque ULIDs.
    Runtime table definitions are discovered through the schema endpoint.
servers:
  - url: http://localhost:4310
security: []
paths:
  /v1/orgs/{orgId}/keys:
    get:
      tags:
        - accounts
      summary: List metadata for workspace-owned API keys. Administrators only.
      operationId: listTeamKeys
      parameters:
        - name: orgId
          in: path
          required: true
          schema:
            type: string
            pattern: ^[0-7][0-9A-HJKMNP-TV-Z]{25}$
          example: 01K6J7B8000000000000000000
        - name: limit
          in: query
          required: false
          schema:
            type: integer
            minimum: 1
            maximum: 25000
        - name: cursor
          in: query
          required: false
          content:
            application/json:
              schema:
                anyOf:
                  - type: string
                    maxLength: 131200
                  - type: 'null'
      responses:
        '200':
          description: Authorised operation result.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/listTeamKeysOutput'
        '400':
          description: Malformed request.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorEnvelope'
        '401':
          description: Missing, expired, revoked or wrong-audience credential.
          headers:
            WWW-Authenticate:
              schema:
                type: string
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorEnvelope'
        '403':
          description: Insufficient current authority.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorEnvelope'
        '404':
          description: Unknown or undisclosed target.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorEnvelope'
        '408':
          description: >-
            Ordinary JSON request body did not finish within its bounded read
            deadline.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorEnvelope'
        '409':
          description: Revision, schema, uniqueness or idempotency conflict.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorEnvelope'
        '413':
          description: Payload or output budget exceeded.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorEnvelope'
        '422':
          description: Typed validation failure.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorEnvelope'
        '429':
          description: Rate, concurrency or admission limit.
          headers:
            Retry-After:
              schema:
                type: string
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorEnvelope'
        '500':
          description: Redacted internal failure.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorEnvelope'
        '502':
          description: A required upstream service is unavailable.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorEnvelope'
        '503':
          description: >-
            A required service is unavailable. Check service configuration
            before retrying.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorEnvelope'
      security:
        - apiKey: []
        - oauth:
            - team-keys:manage
components:
  schemas:
    listTeamKeysOutput:
      type: object
      properties:
        data:
          type: array
          items:
            type: object
            properties:
              scope:
                type: string
                enum:
                  - personal
                  - team
              access:
                type: string
                enum:
                  - read
                  - edit
              includeAdmin:
                type: boolean
              id:
                type: string
                pattern: ^[0-7][0-9A-HJKMNP-TV-Z]{25}$
              orgId:
                type: string
                pattern: ^[0-7][0-9A-HJKMNP-TV-Z]{25}$
              name:
                type: string
                minLength: 1
                maxLength: 120
              userId:
                anyOf:
                  - type: string
                    pattern: ^[0-7][0-9A-HJKMNP-TV-Z]{25}$
                  - type: 'null'
              prefix:
                type: string
              createdAt:
                type: string
                pattern: >-
                  ^(?!0000)\d{4}-\d{2}-\d{2}T(?:[01]\d|2[0-3]):[0-5]\d:[0-5]\d(?:\.\d{1,3})?Z$
                format: date-time
                description: >-
                  UTC instant with mandatory Z and at most three fractional
                  digits.
                examples:
                  - '2024-01-01T12:30:00.000Z'
              expiresAt:
                anyOf:
                  - type: string
                    pattern: >-
                      ^(?!0000)\d{4}-\d{2}-\d{2}T(?:[01]\d|2[0-3]):[0-5]\d:[0-5]\d(?:\.\d{1,3})?Z$
                    format: date-time
                    description: >-
                      UTC instant with mandatory Z and at most three fractional
                      digits.
                    examples:
                      - '2024-01-01T12:30:00.000Z'
                  - type: 'null'
              revokedAt:
                anyOf:
                  - type: string
                    pattern: >-
                      ^(?!0000)\d{4}-\d{2}-\d{2}T(?:[01]\d|2[0-3]):[0-5]\d:[0-5]\d(?:\.\d{1,3})?Z$
                    format: date-time
                    description: >-
                      UTC instant with mandatory Z and at most three fractional
                      digits.
                    examples:
                      - '2024-01-01T12:30:00.000Z'
                  - type: 'null'
              lastUsedAt:
                anyOf:
                  - type: string
                    pattern: >-
                      ^(?!0000)\d{4}-\d{2}-\d{2}T(?:[01]\d|2[0-3]):[0-5]\d:[0-5]\d(?:\.\d{1,3})?Z$
                    format: date-time
                    description: >-
                      UTC instant with mandatory Z and at most three fractional
                      digits.
                    examples:
                      - '2024-01-01T12:30:00.000Z'
                  - type: 'null'
            required:
              - scope
              - access
              - includeAdmin
              - id
              - orgId
              - name
              - userId
              - prefix
              - createdAt
              - expiresAt
              - revokedAt
              - lastUsedAt
            additionalProperties: false
        nextCursor:
          type:
            - string
            - 'null'
        hasMore:
          type: boolean
      required:
        - data
      additionalProperties: false
    ErrorEnvelope:
      type: object
      required:
        - error
      additionalProperties: false
      properties:
        error:
          type: object
          required:
            - code
            - message
            - requestId
          additionalProperties: false
          properties:
            code:
              type: string
              description: >-
                Known domain codes are published in ErrorCode; unknown future
                codes remain valid.
              x-rootset-known-error-codes:
                - VALIDATION_FAILED
                - UNAUTHENTICATED
                - ACCESS_DENIED
                - FORBIDDEN
                - LAST_ADMIN
                - INSUFFICIENT_SCOPE
                - PERSONAL_IDENTITY_REQUIRED
                - DELEGATION_EXCEEDS_AUTHORITY
                - RESOURCE_NOT_FOUND
                - ROW_VERSION_CONFLICT
                - SCHEMA_VERSION_CONFLICT
                - UNIQUE_CONFLICT
                - ROW_SIZE_LIMIT
                - ROW_LIMIT_REACHED
                - PAYLOAD_TOO_LARGE
                - REQUEST_TIMEOUT
                - QUERY_TIMEOUT
                - CURSOR_INVALID
                - STEP_UP_REQUIRED
                - IDEMPOTENCY_CONFLICT
                - JOB_FAILED
                - RATE_LIMITED
                - CAPACITY_LIMIT
                - SCHEMA_MAINTENANCE
                - ARTIFACT_UNVERIFIED
                - ARTIFACT_EXPIRED
                - CONFIGURATION_INVALID
                - DEPENDENCY_UNAVAILABLE
                - INTERNAL_ERROR
            message:
              type: string
            requestId:
              type: string
            details: {}
  securitySchemes:
    apiKey:
      type: http
      scheme: bearer
      bearerFormat: Rootset personal API key
    oauth:
      type: oauth2
      flows:
        authorizationCode:
          authorizationUrl: http://localhost:4310/oauth/authorize
          tokenUrl: http://localhost:4310/oauth/token
          scopes:
            profile:manage: >-
              Current profile:manage authority; the live role ceiling still
              applies.
            account:security: >-
              Current account:security authority; the live role ceiling still
              applies.
            org:read: Current org:read authority; the live role ceiling still applies.
            org:manage: Current org:manage authority; the live role ceiling still applies.
            members:read: >-
              Current members:read authority; the live role ceiling still
              applies.
            members:manage: >-
              Current members:manage authority; the live role ceiling still
              applies.
            keys:manage: >-
              Current keys:manage authority; the live role ceiling still
              applies.
            team-keys:manage: >-
              Current team-keys:manage authority; the live role ceiling still
              applies.
            databases:read: >-
              Current databases:read authority; the live role ceiling still
              applies.
            databases:manage: >-
              Current databases:manage authority; the live role ceiling still
              applies.
            tables:read: >-
              Current tables:read authority; the live role ceiling still
              applies.
            tables:manage: >-
              Current tables:manage authority; the live role ceiling still
              applies.
            schema:manage: >-
              Current schema:manage authority; the live role ceiling still
              applies.
            rows:read: Current rows:read authority; the live role ceiling still applies.
            rows:write: Current rows:write authority; the live role ceiling still applies.
            history:read: >-
              Current history:read authority; the live role ceiling still
              applies.
            exports:read: >-
              Current exports:read authority; the live role ceiling still
              applies.
            jobs:read: Current jobs:read authority; the live role ceiling still applies.
            jobs:cancel: >-
              Current jobs:cancel authority; the live role ceiling still
              applies.
            jobs:retry: Current jobs:retry authority; the live role ceiling still applies.

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.