---
title: "List stored BYOK LLM keys"
method: GET
path: "/v1/llm/keys"
tags: ["keys"]
---

# List stored BYOK LLM keys

`GET /v1/llm/keys`

Scope: `llm_keys` (granted to new live keys by default). Requires a live API key; sandbox keys cannot inspect the production credential store. Returns non-secret metadata only: provider, sha256-prefix fingerprint, timestamps. The key itself is never returned.

A key-store outage returns 503 DB_UNAVAILABLE with Retry-After, not a bare 500, so a transient failure is distinguishable from a permanent one and is safe to retry.

## Response `200`

Stored keys (non-secret metadata).

- ListLlmKeysResponse
  - `keys` LlmKeyListItem[], required
    - `provider` 'anthropic' | 'openai', required
    - `key_fingerprint` string, required
    - `created_at` string, nullable
    - `updated_at` string, nullable

## Other responses

- `400` — Invalid request body or parameters.
- `401` — Missing, invalid, or revoked API key. Pass `X-API-Key: sk-coasty-live-...` (or test).
- `403` — API key lacks the required scope or tier-feature is unavailable on the caller's plan.
- `404` — Resource not found in this key's namespace.
- `409` — The resource state conflicts with this operation.
- `413` — The request body exceeds the endpoint limit.
- `422` — The JSON shape is valid but one or more values violate the endpoint contract.
- `429` — Rate or concurrency limit exceeded.
- `500` — Unexpected server error. Retry with exponential backoff.
- `502` — An upstream dependency returned an invalid response.
- `503` — A required service is temporarily unavailable.
- `504` — An upstream dependency timed out.

---

[API](https://skmtc.net/coasty/apis/coasty-public-api.md) · [All operations](https://skmtc.net/coasty/apis/coasty-public-api/llms.txt) · [OpenAPI document](https://skmtc-service-staging.skmtc.workers.dev/v1/apis/coasty/coasty-public-api/revisions/f50d93b0d8a1/schema)
