Auth: X-API-KEY: <your key> header (or Authorization: Bearer <access_token>)
Use when: Before creating a key, or when the user asks which keys exist.
Example request
curl https://app.smartcapitalcenter.com/api/v2/public/api-keys \
-H "X-API-KEY: $SCC_API_KEY"
Response 200
List of API keys retrieved successfully. Key values are masked.
Standard envelope with data as a list of:
| Field |
Type |
Description |
id |
integer |
Unique identifier of the API key. |
maskedKeyValue |
string |
Masked key for display. Example: sq_1...j0k9. |
name |
string |
Name of the API key. |
description |
string |
Description of the API key's purpose. |
createdAt |
string |
When the API key was created. |
expiresAt |
string |
When the API key expires (null if no expiration). |
lastUsedAt |
string |
When the API key was last used. |
isActive |
boolean |
Whether the API key is active. |
Next: deleteApiKey to revoke one, or createApiKey if none fits.
# getUserApiKeys
`GET /api/v2/public/api-keys`
Lists the active API keys for the authenticated user.
**Auth:** `X-API-KEY: <your key>` header (or `Authorization: Bearer <access_token>`)
**Use when:** Before creating a key, or when the user asks which keys exist.
## Notes for agents
- Never print full key values back to the user.
## Example request
```bash
curl https://app.smartcapitalcenter.com/api/v2/public/api-keys \
-H "X-API-KEY: $SCC_API_KEY"
```
## Response `200`
List of API keys retrieved successfully. Key values are masked.
Standard envelope with `data` as a list of:
| Field | Type | Description |
|---|---|---|
| `id` | integer | Unique identifier of the API key. |
| `maskedKeyValue` | string | Masked key for display. Example: `sq_1...j0k9`. |
| `name` | string | Name of the API key. |
| `description` | string | Description of the API key's purpose. |
| `createdAt` | string | When the API key was created. |
| `expiresAt` | string | When the API key expires (null if no expiration). |
| `lastUsedAt` | string | When the API key was last used. |
| `isActive` | boolean | Whether the API key is active. |
**Next:** `deleteApiKey` to revoke one, or `createApiKey` if none fits.