---
title: "List agent keys"
method: GET
path: "/agent-keys"
tags: ["Agent Keys"]
---

# List agent keys

`GET /agent-keys`

List agent keys

## Query parameters

- `agentId` string — Filter to keys bound to this agent (agt_*).
- `cursor` string — Cursor from the previous page.
- `limit` integer — Maximum results per page.

## Headers

- `X-Agent-ID` string, nullable
- `X-Instance-ID` string, nullable

## Response `200`

Successful Response

- object
  - `data` object[], required
    - `type` 'agentKey', required
    - `id` string, required — Agent key ID (agk_*).
    - `attributes` object, required
      - `agentKeyPrefix` string, required — Non-secret prefix of the agent key, e.g. `ak_ntl_prod_abc123`.
      - `status` 'ACTIVE' | 'REVOKED', required — Status (ACTIVE or REVOKED).
      - `createdAt` string, date-time, required — When this key was created.
      - `lastUsedAt` string, date-time, nullable, required — When this key was last used.
      - `revokedAt` string, date-time, nullable, required — When this key was revoked.
      - `createdBy` string, nullable, required — User who created this key (usr_*).
      - `revokedBy` string, nullable, required — User who revoked this key (usr_*).
      - `expiresAt` string, date-time, nullable, required — When this key stops authenticating, or null if it has no scheduled expiration.
    - `relationships` object, required
      - `party` object, required — Party that owns the agent key.
        - `data` object, required — Related resource identifier.
          - `type` 'party', required
          - `id` string, required
      - `agent` object, required — Agent this key is bound to.
        - `data` object, required — Related resource identifier.
          - `type` 'agent', required
          - `id` string, required
  - `meta` object, required
    - `pagination` object, required
      - `hasMore` boolean, required — Whether more results are available.
      - `nextCursor` string, nullable, required — Cursor for the next page, or null when there are no more results.

## Other responses

- `400` — Validation Error
- `401` — Unauthorized
- `403` — Forbidden
- `404` — Not Found. Returned when the resource does not exist, or when it exists but is not accessible to your account. The two cases are intentionally indistinguishable, so that resource IDs cannot be enumerated by probing.
- `409` — Conflict
- `422` — Validation Error
- `428` — Precondition Required
- `429` — Too Many Requests
- `500` — Internal Server Error
- `501` — Not Implemented
- `502` — Bad Gateway
- `503` — Service Unavailable

---

[API](https://skmtc.net/natural/apis/natural-api.md) · [All operations](https://skmtc.net/natural/apis/natural-api/llms.txt) · [OpenAPI document](https://skmtc-service-staging.skmtc.workers.dev/v1/apis/natural/natural-api/versions/9561339ea461/schema)
