API / list-endpoint-acls-via-management-api

API

List endpoint ACLs via the xAI Management API

Retrieve every endpoint ACL string your team can attach to an inference API key so create and update calls grant only the routes you intend, such as chat, image, or tokenize, instead of guessing ACL spellings. Official Accounts and Authorization documents GET /auth/teams/{teamId}/endpoints on https://management-api.x.ai, authorized with a management key. The Management API guide covers the same endpoint under ACL management and shows how those strings pair with api-key:model: grants. The response body includes acls, an array of objects with acl, description, namespace, key, and optional value. Create the management key first with Create a management key in the xAI Console if you do not already have one.

What you need

A management key that can read team auth routes, the team id from Console Settings → Team, and a short inventory of which inference surfaces the key must reach before you write the create body. Neighboring key jobs include List team models via the xAI Management API, Create an xAI API key via the Management API, and Update an xAI API key via the Management API. More API jobs live on the API hub.

List endpoint ACL strings

  1. Export the management key and team id outside of source control:
export XAI_MANAGEMENT_KEY="your_management_key"
export XAI_TEAM_ID="your_team_id"
  1. List possible endpoint ACLs for the team:
curl "https://management-api.x.ai/auth/teams/${XAI_TEAM_ID}/endpoints" \
  -H "Authorization: Bearer ${XAI_MANAGEMENT_KEY}"
  1. Read each object in acls. The documented sample returns strings such as api-key:endpoint:chat, api-key:endpoint:embed, api-key:endpoint:image, api-key:endpoint:models, api-key:endpoint:sample, api-key:endpoint:tokenize, and api-key:endpoint:documents. Copy the acl field exactly into your create or update payload. Use description, namespace, key, and value only for operator notes; the grant string the Management API accepts on a key is the full acl value.

  2. Decide between a narrow list and the wildcard. The guide allows api-key:endpoint:* when a key should reach every endpoint available to the team, and it calls out api-key:endpoint:chat for chat and vision traffic and api-key:endpoint:image for image generation when you want tighter scope. Combine endpoint ACLs with model ACLs from List team models via the xAI Management API; keys without both kinds of grant fail requests even when the secret looks valid.

Keep every call on https://management-api.x.ai. An inference API key against https://api.x.ai will not answer Management auth routes.

Wire the list into key provisioning

Run this GET in the same checklist that creates or updates a key so ACL typos never reach production. After xAI adds or renames an endpoint ACL for your team, re-list before you copy yesterday's strings into a new key. Pair with Manage API keys with the xAI Management API when you also need list, rotate, or delete flows around the same secret.

Pitfalls

Inventing ACL strings such as api-key:endpoint:completions that never appear in acls produces keys that cannot call the route you meant. Granting only endpoint ACLs and omitting model ACLs leaves every inference call denied. Treating description as the grant value instead of the acl field breaks create bodies. Mixing Console UI labels with these Management strings invents a permission vocabulary the API never accepts.