# apiKeys

query · in the family [API key](/reference/api-key/)

## What it does

The api key list — each entry is an API key — a machine credential for integrations.

The caller's org-group family's ACTIVE LISTING of ApiKeys — doomed records DROP from listings. PAGINATED: `limit` clamps to \[1, 200], default 100; `nextToken` = the prior page's cursor, verbatim — opaque + tenant-bound (a malformed or foreign token → VALIDATION/INVALID). Walk until `nextToken` is null (a page may hold fewer than `limit` — doomed drop per page). STRUCTURED FILTER + SORT: `filter` = AND across clauses, OR within a clause's values; `sort` = one declared field, asc/desc. The declared ApiKey roster: `caption` (text) · `parentId` (ref) · `expiresAt` (date) · `createdAt` (date) · `updatedAt` (date). An illegal filter/sort refuses VALIDATION/INVALID NAMING the exact problem (an unknown field teaches the roster). A filtered/sorted read evaluates the WHOLE family server-side, returns the EXACT `matchCount`, and its `nextToken` binds to THE ONE filter+sort that minted it — replaying it under a different filter/sort refuses. Absent both, the unfiltered lane is unchanged (`matchCount` null).

## What happens

Reads only — changes nothing.

## Who may call it

Capability area: **System and integration setup** — Registers, connections and the settings your systems run on.

- Owner
- System Administrator
- An API key whose scope allows `api:apiKeys`

## Arguments

| Name | Type | Required | Notes |
| --- | --- | --- | --- |
| `filter` | [FilterInput](/types/FilterInput/) | no | Which records to answer — clauses over the family’s filterable fields (the FilterInput type and the paging guide carry the grammar). |
| `sort` | [SortInput](/types/SortInput/) | no | The order to answer in — one declared field and a direction (the SortInput type carries the grammar). |
| `limit` | [Int](/types/#scalars) | no | How many records to answer at most; a page may hold fewer. |
| `nextToken` | [String](/types/#scalars) | no | The cursor from the previous page, passed back exactly as received. |

## Returns

[ApiKeyPage](/types/ApiKeyPage/) `ApiKeyPage!` — One page of the apiKeys listing — the records + the opaque resume cursor.

This is a page: `items` holds the records and `nextToken` the cursor for the next page — pass it back verbatim until it is null. See [paging](/guides/paging-and-the-cursor-grammar/).

## Example request

```graphql
query ExampleApiKeys($filter: FilterInput) {
  apiKeys(filter: $filter) {
    items {
      id
      sysId
      type
      caption
      status
      parentId
      rootId
      createdAt
      updatedAt
      revisionNum
      revision
      expiresAt
    }
    nextToken
    matchCount
  }
}
```

Variables:

```json
{
  "filter": {
    "clauses": [
      {
        "field": "caption",
        "op": "contains",
        "values": [
          "Blue"
        ]
      }
    ]
  }
}
```

## Example response

```json
{
  "data": {
    "apiKeys": {
      "items": [
        {
          "id": "01900000-0000-7000-8000-37386ae00000",
          "sysId": "AK-EXMP-0000-000F",
          "type": "ApiKey",
          "caption": "Blue jeans",
          "status": "active",
          "parentId": "01900000-0000-7000-8000-065235280000",
          "rootId": "01900000-0000-7000-8000-a093dd800000",
          "createdAt": "2027-01-31T00:00:00.000Z",
          "updatedAt": "2027-01-31T00:00:00.000Z",
          "revisionNum": 1,
          "revision": "01900000-0000-7000-8000-b7960e180000",
          "expiresAt": "2027-01-31T00:00:00.000Z"
        }
      ],
      "nextToken": "<the cursor from the previous page>",
      "matchCount": 1
    }
  },
  "extensions": {
    "at": {
      "callId": "01EXAMPLE-CALL-ID",
      "version": {
        "requested": null,
        "serviced": {
          "name": "genesis",
          "number": 0
        }
      }
    }
  }
}
```

## Errors this call can answer

- `VALIDATION/INVALID` — Something in the request is not valid. ([VALIDATION](/errors/VALIDATION/))
- `AUTHN/REQUIRED` — Sign in to do this. ([AUTHN](/errors/AUTHN/))
- `AUTHZ/FORBIDDEN` — Your role does not allow this action. ([AUTHZ](/errors/AUTHZ/))
- `RATE_LIMIT/THROTTLED` — Too many requests in a short time. ([RATE_LIMIT](/errors/RATE_LIMIT/))

## Used in

- [Manage your integrations’ keys and plugins](/use-cases/manage-integration-keys-and-plugins/)
