> ## Documentation Index
> Fetch the complete documentation index at: https://docs.xpoz.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# List access keys

> List the caller's active API access keys.



## OpenAPI

````yaml https://api.xpoz.ai/openapi.json get /api/tokens
openapi: 3.1.0
info:
  title: XPOZ API
  version: 1.0.0
  description: >-
    Social media data API for Twitter/X, Instagram, Reddit, and TikTok.


    **Data endpoints** (`/api/data/*`) are authenticated with an API access key
    and are metered against the account's credits. Most stored-data endpoints
    share the same query options: `fields` selects which attributes to return,
    `since`/`until` bound the date range, and `responseType` picks between a
    synchronous first page (`fast`), a full paged query run as a background
    operation (`paging`), and a CSV export (`csv`). `/live` endpoints fetch from
    the platform on demand and page with a cursor instead.


    **Account, billing, and crawl-settings endpoints** are used by the XPOZ
    dashboard and authenticate with the user's session.
servers:
  - url: https://api.xpoz.ai
    description: Production
security: []
tags:
  - name: Twitter (live)
    description: >-
      On-demand Twitter/X fetches straight from the platform, cursor-paginated.
      Not available for trial access keys.
  - name: Instagram (live)
    description: >-
      On-demand Instagram fetches straight from the platform, cursor-paginated.
      Not available for trial access keys.
  - name: Reddit (live)
    description: >-
      On-demand Reddit fetches straight from the platform, cursor-paginated. Not
      available for trial access keys.
  - name: TikTok (live)
    description: >-
      On-demand TikTok fetches straight from the platform, cursor-paginated. Not
      available for trial access keys.
  - name: Operations
    description: Polling for background operations started with `responseType=paging`.
  - name: Account
    description: Access keys, plan, and usage of the signed-in user.
  - name: Billing
    description: Stripe checkout, subscription changes, and add-on purchases.
  - name: Crawl Settings
    description: Tracked items collected on a schedule.
  - name: System Status
    description: Platform status page and notifications.
  - name: Platform
    description: Health, metrics, and this spec.
paths:
  /api/tokens:
    get:
      tags:
        - Account
      summary: List access keys
      description: List the caller's active API access keys.
      operationId: getTokens
      responses:
        '200':
          description: Access keys.
          content:
            application/json:
              schema:
                type: object
                properties:
                  success:
                    type: boolean
                    const: true
                  data:
                    type: array
                    items:
                      $ref: '#/components/schemas/AccessKeyRecord'
                  count:
                    type: integer
                required:
                  - success
                  - data
                  - count
        '401':
          $ref: '#/components/responses/UnauthorizedMessage'
        '500':
          description: Server error.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/LegacyFailure'
      security:
        - UserSession: []
components:
  schemas:
    AccessKeyRecord:
      type: object
      properties:
        id:
          type: string
        descopeUserId:
          type: string
        userEmail:
          type: string
        userName:
          type: string
        authProvider:
          type: string
        authProviderId:
          type: string
        accessKeyId:
          type: string
        accessKey:
          type: string
        accessKeyPrefix:
          type: string
        keyName:
          type: string
        tenantId:
          type: string
        createdAt:
          type: string
          format: date-time
        expiresAt:
          anyOf:
            - type: string
              format: date-time
            - type: 'null'
        isActive:
          type: boolean
        metadata:
          type: object
    LegacyFailure:
      type: object
      properties:
        success:
          type: boolean
          const: false
        message:
          type: string
        error:
          type: string
      required:
        - success
        - message
    MessageError:
      type: object
      properties:
        message:
          type: string
      required:
        - message
  responses:
    UnauthorizedMessage:
      description: Missing or invalid credentials.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/MessageError'
  securitySchemes:
    UserSession:
      type: http
      scheme: bearer
      bearerFormat: JWT
      description: >-
        Descope session JWT of a logged-in dashboard user. Send as
        `Authorization: Bearer <session JWT>`.

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.