---
title: "Api Keys List"
method: GET
path: "/api/keys/"
tags: ["users"]
---

# Api Keys List

`GET /api/keys/`

Plug-and-play plan-level count-limit enforcement on resource creation.

A view declares ONE resource tag — its ``permission_resource`` (the same
``Resources`` value that drives the RBAC permission) — and this mixin hooks
``create()`` to enforce that resource's plan count limit automatically. No
separate ``plan_limited_resource``: the resource tag is the single source.

    class DatasetsView(PlanLimitMixin, PermissionMapMixin, ListCreateAPIView):
        permission_resource = Resources.DATASETS
        # RBAC perm AND the dataset count cap both derive from this tag.

The "what" (model/field/filters/error per resource) lives in the
``utils.plan_limits`` registry; ``PLAN_LIMIT_BY_RESOURCE`` maps the resource
tag → its ``GatedResource``. A tag with no registry entry simply has no cap.

How the hook fires: DRF's ``ListCreateAPIView.post()`` delegates to
``self.create()``, and views that override ``post()`` end with
``super().post()`` — both reach this mixin's ``create()`` (it sits before
the generic view in the MRO). Views that define their own ``create()`` just
need to call ``super().create()`` and honour its return value.

Org resolution: ``get_limit_organization()`` defaults to the view's
``get_organization()`` (the org the resource is created under, after any
superadmin injection), falling back to the request user's org. Override it
for bespoke resolution (e.g. a superadmin *target* org).

Custom non-``create()`` handlers (e.g. an ``update_or_create`` upsert) can't
be hooked; those call ``enforce_declared_limit()`` explicitly — still driven
off the same resource tag.

Staff exemption: Respan staff acting on an org's behalf bypass ALL plan
limits — a cross-cutting policy enforced centrally in
``enforce_declared_limit`` (see ``is_plan_limit_exempt``), not re-stated per
view. Every gated resource inherits it.

## Query parameters

- `page` integer
- `page_size` integer

## Headers

- `Authorization` string, required

## Response `200`

- PaginatedOrganizationKeyReadList
  - `count` integer, required
  - `next` string, uri, nullable
  - `previous` string, uri, nullable
  - `total_count` integer
  - `current_filters` FilterParamDictPydantic — Pydantic model for FilterParamDict. A dictionary that maps metric names to their filter parameters. Each key is a metric name (str), and each value can be: - A single MetricFilterParamPydantic (one condition) - A List[MetricFilterParamPydantic] (multiple conditions for same metric) - A FilterBundlePydantic (nested filter bundle with connector) Note: Uses extra="allow" for dynamic metric name fields. The __pydantic_extra__ annotation tells Pydantic what types to expect for extra fields, and generates typed additionalProperties in JSON Schema.
  - `filters_data` PaginatedOrganizationKeyReadListFiltersData
  - `results` OrganizationKeyRead[], required
    - `id` string, required
    - `suffix` string, required
    - `tags` GenericTagDisplay[], required
      - `id` string, required
      - `name` string, required
      - `color` string, required
      - `created_at` string, date-time, required
      - `updated_at` string, date-time, required
    - `status` 'active' | 'expired' | 'revoked', required — * `active` - Active * `expired` - Expired * `revoked` - Revoked
    - `project` string, nullable
    - `prefix` string, required
    - `hashed_key` string, required
    - `created` string, date-time, required
    - `name` string — A free-form name for the API key. Need not be unique. 50 characters max.
    - `revoked` boolean — If the API key is revoked, clients cannot use it anymore. (This cannot be undone.)
    - `expiry_date` string, date-time, nullable — Once API key expires, clients cannot use it anymore.
    - `key_usage` integer, required
    - `max_usage` integer
    - `last_used` string, date-time, required
    - `rate_limit` number, double, nullable
    - `spending_limit` number, double, nullable
    - `spending_in_period` number, double, required
    - `is_test` boolean
    - `is_temporary` boolean
    - `revoked_at` string, date-time, nullable, required
    - `revoked_by_email` string, nullable, required
    - `user` integer, nullable, required
    - `organization` integer, nullable, required
    - `created_by` integer, nullable, required
    - `updated_by` integer, nullable, required

---

[API](https://skmtc.net/keywordsai/apis/api-reference.md) · [All operations](https://skmtc.net/keywordsai/apis/api-reference/llms.txt) · [OpenAPI document](https://skmtc-service-staging.skmtc.workers.dev/v1/apis/keywordsai/api-reference/versions/c26d550029f8/schema)
