> ## Documentation Index
> Fetch the complete documentation index at: https://docs.truthlocks.com/llms.txt
> Use this file to discover all available pages before exploring further.

# List consumer API keys

> Returns all API keys for the authenticated consumer. Secrets are never returned in list responses.

Returns all API keys belonging to the authenticated consumer. Secrets are never included in list responses — only the key prefix is shown.

### Responses


## OpenAPI

````yaml mint-openapi.yaml GET /v1/consumer/api-keys
openapi: 3.0.3
info:
  title: Truthlocks API
  description: >
    Truthlocks is a universal verification infrastructure for documents,
    credentials, and digital assets.

    This specification defines the canonical API for interacting with Truthlocks
    services.


    ## Base URLs

    - **Production**: `https://api.truthlocks.com`

    - **Sandbox**: `https://sandbox-api.truthlocks.com`


    ## Authentication

    - **API Keys**: Use `X-API-Key` header for machine-to-machine operations

    - **Bearer Tokens**: Use `Authorization: Bearer <jwt>` for user-initiated
    operations


    ## Tenant Identity

    In production, tenant identity is derived from the authenticated context
    (API key or JWT).

    The `X-Tenant-ID` header is ignored in production to prevent spoofing.
  version: 1.0.0
  contact:
    name: Truthlocks Support
    url: https://truthlocks.com/support
    email: support@truthlocks.com
servers:
  - url: https://api.truthlocks.com
    description: Production API
  - url: https://sandbox-api.truthlocks.com
    description: Sandbox Environment
security:
  - APIKey: []
tags:
  - name: Authentication
    description: API key and token management
  - name: Issuers
    description: Issuer registration and trust management
  - name: Keys
    description: Cryptographic key management for issuers
  - name: Attestations
    description: Attestation lifecycle (mint, revoke, supersede)
  - name: Verification
    description: Attestation verification and proof bundles
  - name: Governance
    description: Issuer governance workflows (admin only)
  - name: Identity
    description: Organization, user, and role management
  - name: Audit
    description: Audit event queries
  - name: Platform
    description: Platform administration (super admin only)
  - name: Platform Review
    description: Staff review workflows for issuer applications
  - name: Tenant Console
    description: Tenant profile and lifecycle endpoints
  - name: Health
    description: Service health and readiness endpoints
  - name: Risk
    description: Risk signal ingestion and fraud detection
  - name: Risk Enforcement
    description: Risk enforcement actions — block, challenge, quarantine, and configuration
  - name: Billing
    description: Billing, subscription, and addon management
  - name: Machine Identity
    description: >-
      Machine Agent Identity Protocol (MAIP) — agent registration, sessions,
      trust, witness, compliance, orchestration, and observability
externalDocs:
  description: Transparency read-only API (separate service spec)
  url: >-
    https://github.com/truthlocks/truthlock/blob/main/docs/transparency/openapi.yaml
paths:
  /v1/consumer/api-keys:
    get:
      tags:
        - Consumer
      summary: List Consumer API Keys
      description: >-
        Returns all API keys for the authenticated consumer. Secrets are never
        returned in list responses.
      responses:
        '200':
          description: List of consumer API keys
          content:
            application/json:
              schema:
                type: array
                items:
                  $ref: '#/components/schemas/ConsumerAPIKey'
              example:
                - key_id: a1b2c3d4-e5f6-7890-abcd-ef1234567890
                  name: My integration key
                  prefix: tlk_abcd1234
                  status: active
                  scopes:
                    - consumer:read
                    - consumer:write
                    - attestations:mint
                    - attestations:read
                    - verify:read
                  created_at: '2026-03-01T12:00:00Z'
                  expires_at: '2026-05-30T12:00:00Z'
                  last_used_at: '2026-03-20T09:15:00Z'
        '401':
          description: Authentication required
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorEnvelope'
              example:
                code: AUTH_REQUIRED
                message: Authentication required
                http_status: 401
      security:
        - BearerAuth: []
components:
  schemas:
    ConsumerAPIKey:
      type: object
      properties:
        key_id:
          type: string
          format: uuid
        name:
          type: string
          description: Human-readable label for the key
        prefix:
          type: string
          description: First 12 characters of the key, for display purposes
        status:
          type: string
          enum:
            - active
            - revoked
        scopes:
          type: array
          items:
            type: string
          description: Permission scopes granted to this key
        created_at:
          type: string
          format: date-time
        expires_at:
          type: string
          format: date-time
          description: Keys expire 90 days after creation
        last_used_at:
          type: string
          format: date-time
          description: Timestamp of the last request made with this key
    ErrorEnvelope:
      type: object
      required:
        - code
        - message
        - http_status
      properties:
        code:
          type: string
          description: Machine-readable error code
          enum:
            - AUTH_REQUIRED
            - AUTH_INVALID
            - PERMISSION_DENIED
            - TENANT_IDENTITY_UNVERIFIED
            - NOT_FOUND
            - VALIDATION_ERROR
            - CONFLICT
            - PAYLOAD_TOO_LARGE
            - RATE_LIMIT_EXCEEDED
            - QUOTA_EXCEEDED
            - SERVICE_UNAVAILABLE
            - INTERNAL_ERROR
        message:
          type: string
          description: Human-readable error message
        http_status:
          type: integer
          description: HTTP status code
        retry_after_ms:
          type: integer
          description: Milliseconds to wait before retrying (for rate limits)
        details:
          type: object
          description: Additional error context
      example:
        code: AUTH_REQUIRED
        message: Authentication required
        http_status: 401
  securitySchemes:
    APIKey:
      type: apiKey
      in: header
      name: X-API-Key
      description: API key for machine-to-machine authentication
    BearerAuth:
      type: http
      scheme: bearer
      bearerFormat: JWT
      description: JWT for user-initiated operations

````