> ## Documentation Index
> Fetch the complete documentation index at: https://docs.ontime.hosai.app/llms.txt
> Use this file to discover all available pages before exploring further.

# List API keys (no secrets)

> List API keys (no secrets)



## OpenAPI

````yaml /api-reference/openapi.json get /api/api-access/keys
openapi: 3.1.0
info:
  title: ontime API
  description: APIs for ontime.v2
  version: 1.0.0
servers:
  - url: https://app.ontime.hosai.app
    description: Production
security:
  - apiKey: []
paths:
  /api/api-access/keys:
    get:
      tags:
        - API access
      summary: List API keys (no secrets)
      description: List API keys (no secrets)
      operationId: getApiApiAccessKeys
      responses:
        '200':
          description: Success
          content:
            application/json:
              schema:
                type: object
                properties:
                  keys:
                    type: array
                    items:
                      type: object
                      properties:
                        id:
                          type: string
                          format: uuid
                          pattern: >-
                            ^([0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[1-8][0-9a-fA-F]{3}-[89abAB][0-9a-fA-F]{3}-[0-9a-fA-F]{12}|00000000-0000-0000-0000-000000000000|ffffffff-ffff-ffff-ffff-ffffffffffff)$
                        label:
                          type: string
                        scope:
                          type: string
                          enum:
                            - ReadOnly
                            - ReadWrite
                        prefix:
                          type: string
                        employeeId:
                          anyOf:
                            - type: string
                              format: uuid
                              pattern: >-
                                ^([0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[1-8][0-9a-fA-F]{3}-[89abAB][0-9a-fA-F]{3}-[0-9a-fA-F]{12}|00000000-0000-0000-0000-000000000000|ffffffff-ffff-ffff-ffff-ffffffffffff)$
                            - type: 'null'
                        lastUsedAt:
                          anyOf:
                            - type: string
                            - type: 'null'
                        revoked:
                          type: boolean
                        createdAt:
                          type: string
                      required:
                        - id
                        - label
                        - scope
                        - prefix
                        - employeeId
                        - lastUsedAt
                        - revoked
                        - createdAt
                required:
                  - keys
components:
  securitySchemes:
    apiKey:
      type: http
      scheme: bearer
      bearerFormat: ont_ API key
      description: >-
        Issue keys in Settings → API. Send them as `Authorization: Bearer ont_…`
        (an `X-Api-Key: ont_…` header is also accepted). Session-cookie routes
        are used by the OnTime web apps and are shown for completeness.

````