> ## Documentation Index
> Fetch the complete documentation index at: https://docs.orq.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# List management keys

> Returns management keys in the current workspace, ordered by creation time with the newest key first. The `api_key` and `token_hash` fields are never returned by this endpoint; only `token_prefix` is included.

<Note>
  **Related guide**: Management keys guide. See the [Management keys guide](/ai-studio/organization/management-keys) for a walkthrough with examples.
</Note>


## OpenAPI

````yaml get /v2/management-keys
openapi: 3.1.0
info:
  title: orq.ai API
  version: '2.0'
  description: orq.ai API documentation
servers:
  - url: https://my.orq.ai
security:
  - ApiKey: []
tags:
  - name: Chunking
    description: Split text into smaller chunks for retrieval and generation workflows.
  - name: File Systems
    description: >-
      Create and manage persistent file systems that agents and MCP clients read
      from and write to.
  - name: Knowledge Bases
    description: Create and manage knowledge bases used by agents and retrieval workflows.
  - name: Memory Stores
    description: Create and manage memory stores, memories, and memory documents.
  - name: Evals
    description: Run an evaluator against a conversation and its result
  - name: Logs
    description: >-
      OpenTelemetry log query API. Search, filter, aggregate, and facet log
      records ingested via OTLP.
  - name: Reporting
    description: >-
      GenAI reporting API over canonical analytics rollups. Accepts a metric
      name, time range, grain, group-by, and filters; returns a typed time
      series and optional totals.
  - name: Traces
    description: >-
      Query and inspect ingested trace data: search trace summaries, aggregate
      metrics, and read individual traces and their spans.
  - description: List models available through the AI Router.
    name: Models
  - name: Policies
  - name: Alerts
    description: >-
      Alerts evaluate a Reporting API metric on a fixed interval and fire
      notifications through notifiers when the value breaches a threshold. Each
      breach opens a trigger that tracks the incident until the value recovers.
  - name: Annotation Queues
    description: Annotation queues collect spans for human review.
  - name: API keys
    description: >-
      API keys authenticate programmatic access to the workspace. They expose
      opaque tokens, per-domain access grants, and budget and rate-limit
      constraints.
  - name: Audit Logs
    description: Audit logs record workspace entity changes and access-relevant events.
  - name: Budgets
    description: >-
      Budgets govern spend, token usage, and request rate across six scopes:
      workspace, project, identity, API key, provider, and model. Every
      applicable budget is enforced, and the most restrictive limit applies per
      dimension.
  - name: Files
    description: File upload and retrieval operations.
  - name: Guardrail Rules
    description: >-
      Guardrail Rules conditionally enforce evaluators and plugins for AI
      Gateway traffic. Rules may be scoped to a project or the whole workspace.
  - name: Hub
    description: Hub items are reusable templates available to a workspace.
  - name: Identities
    description: >-
      Identities represent end users from your system for usage and engagement
      tracking.
  - name: Management keys
    description: >-
      Management keys are workspace-scoped credentials that authenticate
      programmatic access to workspace administration surfaces (API keys,
      budgets). Unlike project-scoped API keys, a management key always operates
      at the workspace level.
  - name: MCP Gateway
    description: >-
      Register upstream MCP servers, discover and sync their tools, and assemble
      gateways that expose a curated tool surface to MCP clients.
  - name: Model Catalog
    description: >-
      Browse the orq.ai model catalog: every model orq offers, across every
      provider, with pricing, capabilities and benchmark data. List endpoints
      only return models that are not deprecated. This API is public, requires
      no authentication, and is rate limited to 120 requests per minute per IP.
      Responses carry a 5-minute cache-control max-age.
  - name: Notifiers
    description: Notifier destinations used to send delivery and workflow notifications.
  - name: Projects
    description: Projects organize resources within a workspace
  - name: Routing Rules
    description: >-
      Routing Rules conditionally select models and enforce request plugins for
      AI Gateway traffic. Rules are evaluated by ascending priority and may be
      scoped to a project or the whole workspace.
  - name: Threads
    description: Threads group related trace invocations and their aggregate usage
  - name: Skills
    description: >-
      Skills are modular instructions you can use to codify processes and
      conventions
  - name: Smart Routers
    description: >-
      Create and manage workspace Smart Routers. A Smart Router selects a model
      from an eligible pool for each request according to a quality, balanced,
      or cost profile.
  - name: Webhooks
    description: >-
      Create and manage webhooks that deliver workspace events to external HTTPS
      endpoints.
  - name: Workspaces
    description: >-
      A workspace is the tenant. Create is called from a user session during
      onboarding; Get, List, and Update are the public management surface.
  - name: Workspace Security
    description: >-
      Workspace-level domain verification and IP allowlist controls. These
      operations are restricted to workspace administrators.
  - name: Workspace Settings
    description: >-
      Workspace-level settings managed with a workspace credential. A workspace
      is the tenant, so these settings are a singleton — there is nothing to
      create or delete, only read and update.
  - name: Responses
  - description: Run agents on a cron cadence. Minimum firing interval is 1 hour.
    name: Agent Schedules
  - name: Embeddings
  - name: Telemetry
    description: >-
      Unified query envelope for traces, metrics, and logs. One request shape,
      one filter dialect, and one response shape per source, validated by a
      per-source registry.
  - description: Beta. Run typed classification questions against a classify model.
    name: Classify
  - description: Search Gateway with managed credits or BYOK.
    name: Web Search
externalDocs:
  url: https://docs.orq.ai
  description: orq.ai Documentation
paths:
  /v2/management-keys:
    get:
      tags:
        - Management keys
      summary: List management keys
      description: >-
        Returns management keys in the current workspace, ordered by creation
        time with the newest key first. The `api_key` and `token_hash` fields
        are never returned by this endpoint; only `token_prefix` is included.
      operationId: ManagementKeyList
      parameters:
        - name: limit
          in: query
          description: Page size, 1–200. Unset uses the server default (25).
          schema:
            type: integer
            format: int32
        - name: starting_after
          in: query
          description: |-
            Cursor for forward pagination. Set to the `management_key_id` of the
             last item from the previous page.
          schema:
            type: string
        - name: ending_before
          in: query
          description: >-
            Cursor for backward pagination. Set to the `management_key_id` of
            the
             first item from the previous page.
          schema:
            type: string
        - name: status
          in: query
          description: 'Optional filter: only return keys with this status.'
          schema:
            $ref: '#/components/schemas/ManagementKeyStatus'
        - name: search
          in: query
          description: |-
            Optional case-insensitive substring match against the management-key
             name. Empty means no name filter.
          schema:
            type: string
        - name: permission_mode
          in: query
          description: |-
            Optional filter: only return keys whose permission mode is one of
             the listed presets. Empty means no permission-mode filter.
          schema:
            type: array
            items:
              $ref: '#/components/schemas/ManagementPermissionMode'
      responses:
        '200':
          description: OK
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ListManagementKeysResponse'
components:
  schemas:
    ManagementKeyStatus:
      type: string
      enum:
        - MANAGEMENT_KEY_STATUS_UNSPECIFIED
        - MANAGEMENT_KEY_STATUS_ACTIVE
        - MANAGEMENT_KEY_STATUS_DISABLED
        - MANAGEMENT_KEY_STATUS_REVOKED
    ManagementPermissionMode:
      type: string
      enum:
        - MANAGEMENT_PERMISSION_MODE_UNSPECIFIED
        - MANAGEMENT_PERMISSION_MODE_ALL
        - MANAGEMENT_PERMISSION_MODE_RESTRICTED
        - MANAGEMENT_PERMISSION_MODE_READ_ONLY
    ListManagementKeysResponse:
      required:
        - object
        - data
        - has_more
      type: object
      properties:
        object:
          type: string
          description: Object discriminator for list responses; always `list`.
        data:
          type: array
          items:
            $ref: '#/components/schemas/ManagementKey'
          description: |-
            Page of management-keys, ordered newest first. `token_hash` and
             `api_key` are always elided in list responses.
        has_more:
          type: boolean
          description: >-
            Whether more management-keys are available in the selected
            pagination
             direction.
    ManagementKey:
      required:
        - management_key_id
        - name
        - permission_mode
        - token_prefix
        - status
        - created_at
        - updated_at
      type: object
      properties:
        management_key_id:
          type: string
          description: |-
            Canonical key identifier (ULID). Embedded in opaque tokens as
             `sk-orq-<id>-<secret>`.
        name:
          type: string
          description: Human-readable name shown in the dashboard.
        permission_mode:
          $ref: '#/components/schemas/ManagementPermissionMode'
          description: |-
            Permission preset. `all` and `read_only` resolve at auth time from
             the management capability catalog. `restricted` reads the per-domain
             `access` map.
        access:
          type: object
          additionalProperties:
            $ref: '#/components/schemas/AccessLevel'
          description: |-
            Per-domain access map. Only populated when `permission_mode` is
             `MANAGEMENT_PERMISSION_MODE_RESTRICTED`. The authoritative list of
             valid keys (Domain.id values) is returned by the List management
             capability catalog endpoint (GET /v2/management-keys/capabilities).
        token_prefix:
          type: string
          description: |-
            Displayable prefix for UI listings (e.g. "sk-orq-01HXY..."). Safe
             to expose.
        status:
          $ref: '#/components/schemas/ManagementKeyStatus'
          description: Lifecycle status.
        created_by_id:
          type: string
          description: 'Audit: user who created the key.'
        updated_by_id:
          type: string
          description: 'Audit: user who last updated the key.'
        created_at:
          type: string
          description: Time the key was created.
          format: date-time
        updated_at:
          type: string
          description: Time the key was last updated.
          format: date-time
        last_used_at:
          type: string
          description: Last authenticated use.
          format: date-time
        expires_at:
          type: string
          description: |-
            Optional expiration. The authenticate hot-path rejects keys whose
             `expires_at` is in the past. Unset means the key never expires.
          format: date-time
      description: |-
        ManagementKey defines permissions, expiration, and revocation for a
         management key. Management keys are always
         workspace-scoped — there is no project_scope field, and they have no
         per-user owner (every management key is workspace-owned;
         `created_by_id` records who created it).
    AccessLevel:
      type: string
      enum:
        - ACCESS_LEVEL_NONE
        - ACCESS_LEVEL_READ
        - ACCESS_LEVEL_WRITE
  securitySchemes:
    ApiKey:
      type: http
      scheme: bearer
      bearerFormat: JWT

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.