# GET /v1/tokens

List the keys

Every key of the server, revoked ones included.

Takes a server key (`sk_…`, or `sk_test_…` on a test server) as a bearer token. TypeScript: `sendora.tokens.list()`. Python: `sendora.tokens.list()`.

## Responses

### 200 Every key of the server, revoked ones included.

- `tokens` (array of object, required)
  - `tokenId` (string (uuid), required)
  - `name` (string, required): The name given at creation, for people to tell keys apart.
  - `prefix` (string, required): The first characters of the key, to match it with a value in hand.
  - `createdAt` (string (date-time), required)
  - `revokedAt` (string (date-time) or null, required)

Example:

```json
{
  "tokens": [
    {
      "tokenId": "3b0c9e2f-6d4a-4e8b-8a1c-9f2d7e6c5b40",
      "name": "Invoicing system",
      "prefix": "sk_a1b2c3d4e5",
      "createdAt": "2026-09-15T12:00:00.000Z",
      "revokedAt": null
    }
  ]
}
```

## Errors

Every error answers `error`, the code, and `message`, a sentence for a person. A code that adds fields is shown in full below the table.

| Code | Status | Meaning |
| --- | --- | --- |
| `unauthorized` | 401 | The key is missing, malformed or revoked. |
| `wrong_token_kind` | 403 | The key is of the other kind: a server key (sk_) where an account key (ak_) is needed, or the reverse. The message names the kind the operation takes. |
