> ## Documentation Index
> Fetch the complete documentation index at: https://docs.useroutr.com/llms.txt
> Use this file to discover all available pages before exploring further.

# List the application's API keys

> Newest first. Secrets are never included.



## OpenAPI

````yaml /api-reference/openapi.json get /v1/applications/{id}/api-keys
openapi: 3.1.0
info:
  title: Useroutr API
  version: '1'
  description: >-
    Application funding infrastructure. Two authentication layers exist and are
    never interchangeable: developer backends authenticate with an application
    API key (`apiKey`), and the Useroutr dashboard authenticates a human with a
    Useroutr account session (`userSession`, obtained from `/v1/auth/sign-in`).
    Platform operations use the operator platform key. Every response carries an
    `X-Request-ID` header that also appears in error envelopes.
servers:
  - url: https://api.sandbox.useroutr.com
    description: 'Sandbox: ur_test_ keys, Stellar testnet'
  - url: https://api.useroutr.com
    description: 'Production: ur_live_ keys'
security: []
tags:
  - name: Funding Intents
    description: Funding intent lifecycle
  - name: Quotes
    description: 'Route quotes: what a payer must send from a chosen source asset'
  - name: Checkout
    description: Public, token-addressed payer view
  - name: Payments
    description: Observed payments
  - name: Settlements
    description: Settlement state and protocol evidence
  - name: Refunds
    description: Refund requests for payments that did not satisfy an intent
  - name: Ledger
    description: Application balances and ledger entries
  - name: Webhooks
    description: Webhook endpoints, events and deliveries
  - name: Assets
    description: Supported assets
  - name: Applications
    description: Application registration and credentials
  - name: Request logs
    description: Requests made with the application's API keys, kept for 30 days
paths:
  /v1/applications/{id}/api-keys:
    get:
      tags:
        - Applications
      summary: List the application's API keys
      description: Newest first. Secrets are never included.
      parameters:
        - schema:
            type: string
            minLength: 1
            maxLength: 64
          in: path
          name: id
          required: true
      responses:
        '200':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  object:
                    type: string
                    enum:
                      - list
                  data:
                    type: array
                    items:
                      type: object
                      properties:
                        id:
                          type: string
                        object:
                          type: string
                          enum:
                            - api_key
                        environment:
                          type: string
                          enum:
                            - TEST
                            - LIVE
                        name:
                          type:
                            - string
                            - 'null'
                        prefix:
                          type: string
                        status:
                          type: string
                          enum:
                            - ACTIVE
                            - REVOKED
                        created_at:
                          type: string
                        last_used_at:
                          type:
                            - string
                            - 'null'
                        revoked_at:
                          type:
                            - string
                            - 'null'
                      required:
                        - id
                        - object
                        - environment
                        - name
                        - prefix
                        - status
                        - created_at
                        - last_used_at
                        - revoked_at
                      additionalProperties: false
                required:
                  - object
                  - data
                additionalProperties: false
        '401':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  error:
                    type: object
                    properties:
                      code:
                        type: string
                        enum:
                          - BAD_REQUEST
                          - VALIDATION_ERROR
                          - UNAUTHORIZED
                          - FORBIDDEN
                          - NOT_FOUND
                          - CONFLICT
                          - IDEMPOTENCY_KEY_REQUIRED
                          - IDEMPOTENCY_KEY_REUSED
                          - IDEMPOTENCY_REQUEST_IN_PROGRESS
                          - APPLICATION_INACTIVE
                          - INVALID_AMOUNT
                          - UNSUPPORTED_ASSET
                          - INVALID_DESTINATION
                          - INVALID_EXPIRATION
                          - PROTOCOL_REJECTED
                          - PROTOCOL_UNAVAILABLE
                          - NO_ROUTE_AVAILABLE
                          - INSUFFICIENT_INPUT
                          - QUOTE_EXPIRED
                          - QUOTE_NOT_SELECTABLE
                          - QUOTE_NOT_LOCKED
                          - EXECUTION_NOT_FAILED
                          - EXECUTION_NOT_RESUMABLE
                          - LOGO_FORMAT_UNSUPPORTED
                          - LOGO_DIMENSIONS_INVALID
                          - LOGO_STORAGE_UNAVAILABLE
                          - ROUTE_UNAVAILABLE
                          - RATE_LIMITED
                          - INVALID_CREDENTIALS
                          - EMAIL_NOT_VERIFIED
                          - EMAIL_ALREADY_REGISTERED
                          - SESSION_EXPIRED
                          - INVALID_TOKEN
                          - INTERNAL_ERROR
                      message:
                        type: string
                      requestId:
                        type: string
                      retryable:
                        type: boolean
                      details:
                        type: array
                        items:
                          type: object
                          properties:
                            path:
                              type: string
                            message:
                              type: string
                          required:
                            - path
                            - message
                          additionalProperties: false
                    required:
                      - code
                      - message
                      - requestId
                    additionalProperties: false
                required:
                  - error
                additionalProperties: false
        '404':
          description: Default Response
          content:
            application/json:
              schema:
                type: object
                properties:
                  error:
                    type: object
                    properties:
                      code:
                        type: string
                        enum:
                          - BAD_REQUEST
                          - VALIDATION_ERROR
                          - UNAUTHORIZED
                          - FORBIDDEN
                          - NOT_FOUND
                          - CONFLICT
                          - IDEMPOTENCY_KEY_REQUIRED
                          - IDEMPOTENCY_KEY_REUSED
                          - IDEMPOTENCY_REQUEST_IN_PROGRESS
                          - APPLICATION_INACTIVE
                          - INVALID_AMOUNT
                          - UNSUPPORTED_ASSET
                          - INVALID_DESTINATION
                          - INVALID_EXPIRATION
                          - PROTOCOL_REJECTED
                          - PROTOCOL_UNAVAILABLE
                          - NO_ROUTE_AVAILABLE
                          - INSUFFICIENT_INPUT
                          - QUOTE_EXPIRED
                          - QUOTE_NOT_SELECTABLE
                          - QUOTE_NOT_LOCKED
                          - EXECUTION_NOT_FAILED
                          - EXECUTION_NOT_RESUMABLE
                          - LOGO_FORMAT_UNSUPPORTED
                          - LOGO_DIMENSIONS_INVALID
                          - LOGO_STORAGE_UNAVAILABLE
                          - ROUTE_UNAVAILABLE
                          - RATE_LIMITED
                          - INVALID_CREDENTIALS
                          - EMAIL_NOT_VERIFIED
                          - EMAIL_ALREADY_REGISTERED
                          - SESSION_EXPIRED
                          - INVALID_TOKEN
                          - INTERNAL_ERROR
                      message:
                        type: string
                      requestId:
                        type: string
                      retryable:
                        type: boolean
                      details:
                        type: array
                        items:
                          type: object
                          properties:
                            path:
                              type: string
                            message:
                              type: string
                          required:
                            - path
                            - message
                          additionalProperties: false
                    required:
                      - code
                      - message
                      - requestId
                    additionalProperties: false
                required:
                  - error
                additionalProperties: false
      security:
        - apiKey: []
      x-codeSamples:
        - lang: typescript
          label: Node.js SDK
          source: >-
            import { Useroutr } from "@useroutr/sdk";


            const useroutr = new Useroutr({ apiKey: process.env.USEROUTR_API_KEY
            });


            const { data: keys } = await
            useroutr.applications.listApiKeys("app_5c1e0a9f");
        - lang: bash
          label: cURL
          source: >-
            curl -X GET
            "https://api.sandbox.useroutr.com/v1/applications/app_5c1e0a9f/api-keys"
            \
              -H "Authorization: Bearer $USEROUTR_API_KEY"
components:
  securitySchemes:
    apiKey:
      type: http
      scheme: bearer
      description: >-
        Application API authentication for developer backends: `Authorization:
        Bearer ur_test_...` or `ur_live_...`. Resolves the application, its
        environment and the key's status. Never a dashboard login.

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.