---
title: "View API keys"
method: GET
path: "/apps/{app_id}/auth/tokens"
---

# View API keys

`GET /apps/{app_id}/auth/tokens`

View the details of all of your current app API keys (Rich Authentication Token) for a single OneSignal app.

## Path parameters

- `app_id` string, required

## Headers

- `Content-Type` string, required
- `Authorization` string, required

## Response `200`

List of API key tokens for this app. The `formatted_token` field is never populated in this response — the secret is only shown immediately after create or rotate.

- object
  - `tokens` ApiKeyToken[] — All API key tokens registered against this app (ordered by `created_at`).
    - `token_id` string, uuid — OneSignal-generated identifier for this API key. NOT the API key itself — use this to manage the key in subsequent calls.
    - `name` string — Internal name set when the key was created or last updated. Maximum 128 characters.
    - `ip_allowlist_mode` 'disabled' | 'explicit' — When `explicit`, only requests from IP addresses matching `ip_allowlist` may use this key. Defaults to `disabled`.
    - `ip_allowlist` string[] — Allowed CIDR ranges. Only enforced when `ip_allowlist_mode` is `explicit`.
    - `created_at` string, date-time — ISO-8601 timestamp when the key was created.
    - `updated_at` string, date-time — ISO-8601 timestamp when the key was last updated.
    - `formatted_token` string — The actual Rich Authentication Token (REST API Key). Returned in plaintext ONLY by the create and rotate endpoints, and ONLY immediately after that call. OneSignal does not store the secret — if you lose it, you must rotate the key. See [Rotate API Key](/reference/rotate-api-key).

## Other responses

- `400` — 400
- `403` — Forbidden. Your organization permissions do not allow this action.
- `404` — App not found.
- `429` — Rate limit exceeded. Wait the number of seconds in the `Retry-After` header before retrying.
- `503` — Service temporarily unavailable. Retry after a short backoff. The body may be empty or non-JSON in some failure modes.

---

[API](https://skmtc.net/onesignal/apis/api-onesignal-com.md) · [All operations](https://skmtc.net/onesignal/apis/api-onesignal-com/llms.txt) · [OpenAPI document](https://skmtc-service-staging.skmtc.workers.dev/v1/apis/onesignal/api-onesignal-com/versions/0fc223f7e338/schema)
