v14

latestOpenAPI 3.1.02026-08-083813925.4 MB
API Keys

Retrieve API Key

Retrieves an API key with its effective permission grants. The full secret is never returned — rotate the key if it was lost.

get/api_keys/{id}

Response

api key retrieved with grants but never the secret

api_version_date'2025-01-01' | '2026-06-08' | '2026-06-09' | '2026-06-20' | '2026-07-01' | '2026-07-08' | '2026-07-08-1' | '2026-07-18' | '2026-07-20' | '2026-07-22' | '2026-07-23' | '2026-07-25' | '2026-07-26' | '2026-07-27' | '2026-07-29' | '2026-07-29-1' | '2026-07-31' | '2026-08-03' | '2026-08-05' | '2026-08-05-1' required

Dated API version used when requests authenticated with this key omit the Api-Version-Date header.

created_atstring required

When the API key was created, as an ISO 8601 timestamp.

expires_atstring nullable required

When the API key stops working, as an ISO 8601 timestamp. null means it never expires.

idstring required

API key ID, prefixed apik_.

ip_allowliststring[] nullable required
is_default_for_resourceboolean required

Whether this is the resource's default API key. Default keys cannot be updated or deleted, only rotated.

namestring nullable required

Human-readable name identifying the API key, or null when none was set.

obfuscated_secret_keystring required

Masked version of the secret key, so the key can be recognized without revealing the full secret.

secret_keystring

The full secret used to authenticate requests. Returned only once, on create and rotate responses — store it immediately.

system_role'owner' | 'admin' | 'moderator' | 'sales_manager' | 'advertiser' | 'null' nullable required

System role the key inherits its permissions from, or null when it uses an explicit permissions policy. Only account API keys can use a system role.

updated_atstring required

When the API key was last updated, as an ISO 8601 timestamp.

Example response

{
  "api_version_date": "2025-01-01",
  "system_role": "owner"
}