On this page
apiKey
query · in the family API key
What it does
Look up one record — an API key — a machine credential for integrations.
A ApiKey by id, within the caller's OWN org-group family; requires authentication. A cross-tenant id reads as null (not-found) AND trips the rootId tripwire server-side.
What happens
Reads only — changes nothing.
Who may call it
Capability area: System and integration setup — Registers, connections and the settings your systems run on.
- Owner
- System Administrator
- An API key whose scope allows
api:apiKey
Arguments
| Name | Type | Required | Notes |
|---|---|---|---|
id | ID ID! | yes | The id of the record. |
Returns
ApiKey — An ApiKey — the third-party / programmatic access credential. Issued ONLY by an org-group-level OWNER (the engine's LIVE ownership gate — the minting actor is a User whose Account holds group ownership); parent = the minting User. REACH DERIVES LIVE from the minter's CURRENT ownerships — the key works on exactly the group's orgs where the minter is also currently an org owner; ownership loss/re-grant is never a transition (re-grant REVIVES a not-doomed key). Descriptors ride the Roles grammar (allow/disallow, default-deny, disallow-wins), IMMUTABLE at birth; mandatory expiry ≤ 12 months (the scheduler fires active → expired — a DISTINCT doomed terminal). The secret shows ONCE at mintApiKey, hash-only at rest, and is presented only to exchangeApiKey → a 24 h-absolute no-idle API session. NOT searchable; the reads are -gated (integration config, off the floor).
Example request
query ExampleApiKey($id: ID!) {
apiKey(id: $id) {
id
sysId
type
caption
status
parentId
rootId
createdAt
updatedAt
revisionNum
revision
expiresAt
}
}
Variables:
{
"id": "01900000-0000-7000-8000-37386ae00000"
}
Example response
{
"data": {
"apiKey": {
"id": "01900000-0000-7000-8000-37386ae00000",
"sysId": "AK-EXMP-0000-000F",
"type": "ApiKey",
"caption": "Blue jeans",
"status": "active",
"parentId": "01900000-0000-7000-8000-065235280000",
"rootId": "01900000-0000-7000-8000-a093dd800000",
"createdAt": "2027-01-31T00:00:00.000Z",
"updatedAt": "2027-01-31T00:00:00.000Z",
"revisionNum": 1,
"revision": "01900000-0000-7000-8000-b7960e180000",
"expiresAt": "2027-01-31T00:00:00.000Z"
}
},
"extensions": {
"at": {
"callId": "01EXAMPLE-CALL-ID",
"version": {
"requested": null,
"serviced": {
"name": "genesis",
"number": 0
}
}
}
}
}
Errors this call can answer
VALIDATION/INVALID— Something in the request is not valid. (VALIDATION)AUTHN/REQUIRED— Sign in to do this. (AUTHN)AUTHZ/FORBIDDEN— Your role does not allow this action. (AUTHZ)RATE_LIMIT/THROTTLED— Too many requests in a short time. (RATE_LIMIT)NOT_FOUND/*— That record could not be found. (NOT_FOUND)