API / list-api-keys-via-management-api

API

List API keys via the xAI Management API

Inventory every inference API key on a team over HTTP when you need apiKeyId values for update, rotate, delete, or propagation checks, or when an audit must show names, ACL strings, rate limits, and disabled state without opening Console for each key. Official Accounts and Authorization documents GET /auth/teams/{teamId}/api-keys on https://management-api.x.ai, authorized with a management key. Admins receive all team keys; members receive only the keys they created. The Management API guide shows the same list call with pageSize and paginationToken. Create the management key first with Create a management key in the xAI Console if you do not already have one.

What you need

A management key that can list API keys for the team, the team id from Console Settings → Team, and a place to store apiKeyId values for later jobs. List responses return redactedApiKey only; the full secret appears solely on create or rotate. Optional query filters include aclFilters, activeOnly (non-expired keys when true), pageSize, and paginationToken for follow-up pages. Neighboring key jobs include Create an xAI API key via the Management API, Update an xAI API key via the Management API, and Delete an xAI API key via the Management API. More API jobs live on the API hub.

List keys for the team

  1. Export the management key and team id outside of source control:
export XAI_MANAGEMENT_KEY="your_management_key"
export XAI_TEAM_ID="your_team_id"
  1. List the first page of API keys, matching the guide's pagination query shape:
curl "https://management-api.x.ai/auth/teams/${XAI_TEAM_ID}/api-keys?pageSize=10&paginationToken=" \
  -H "Authorization: Bearer ${XAI_MANAGEMENT_KEY}"
  1. Walk each object in apiKeys and capture apiKeyId, name, disabled, expireTime, rate fields (qps, qpm, tpm), and aclStrings (or the snake_case acl_strings shape shown in some docs samples). Use redactedApiKey only as a human hint rather than a usable Bearer secret, and when the response includes paginationToken, repeat the GET with that token until the token is absent or undefined, which marks the last page.

  2. Narrow the list when runbooks need a subset by setting activeOnly=true to skip expired keys or passing aclFilters when you only want keys that match specific ACL strings. After you have apiKeyId, hand off to Update an xAI API key via the Management API, Rotate an xAI API key via the Management API, Check API key propagation via the xAI Management API, or Delete an xAI API key via the Management API.

Keep every call on https://management-api.x.ai, because an inference API key against https://api.x.ai will not list Management auth keys.

Feed ops and audits

Run this GET before mass ACL updates so you edit the correct apiKeyId set, and pair with List audit events via the xAI Management API when a compliance checklist needs both the current key inventory and the recent admin event trail. For the broader create–list–update–delete loop in one place, keep Manage API keys with the xAI Management API beside this dedicated list job.

Pitfalls

Expecting the list response to re-expose the full apiKey secret forces an unnecessary rotate. Stopping after the first page when paginationToken is still set hides keys from later pages. Filtering as a member while an admin expected a full team inventory undercounts keys other users created. Calling list against https://api.x.ai with an inference Bearer never hits this Management route.