> ## Documentation Index
> Fetch the complete documentation index at: https://support.lilt.com/llms.txt
> Use this file to discover all available pages before exploring further.

# List API keys

> Retrieve all non-deleted API keys scoped to the caller's current organization.

Callers with the `apiKey.read` permission see all keys in the organization; all other callers see only their own keys. The plaintext secret is never returned by this endpoint — only the key prefix is shown.




## OpenAPI

````yaml /api-reference/openapi-bundled.yaml get /v2/api-keys
openapi: 3.0.3
info:
  title: LILT API
  description: >
    LILT API Support: https://lilt.atlassian.net/servicedesk/customer/portals


    The LILT API enables programmatic access to the full-range of LILT backend
    services including:
      * Training of and translating with interactive, adaptive machine translation
      * Large-scale translation memory
      * The Lexicon (a large-scale termbase)
      * Programmatic control of the LILT CAT environment
      * Translation memory synchronization


    Requests and responses are in JSON format. The REST API only responds to
    HTTPS / SSL requests.


    The base url for this REST API is `https://api.lilt.com/`.


    ## Authentication


    Requests are authenticated via API key, which requires the Business plan.


    Requests are authenticated using [HTTP Basic
    Auth](https://en.wikipedia.org/wiki/Basic_access_authentication). Add your
    API key as both the `username` and `password`.


    For development, you may also pass the API key via the `key` query
    parameter. This is less secure than HTTP Basic Auth, and is not recommended
    for production use.


    ## Quotas


    Our services have a general quota of 4000 requests per minute. Should you
    hit the maximum requests per minute, you will need to wait 60 seconds before
    you can send another request.
  version: v3.0.3
  license:
    name: LILT Platform Terms and Conditions
    url: https://lilt.com/lilt-platform-terms-and-conditions
servers:
  - url: https://api.lilt.com
security:
  - BasicAuth: []
  - ApiKeyAuth: []
paths:
  /v2/api-keys:
    get:
      tags:
        - API Keys
      summary: List API keys
      description: >
        Retrieve all non-deleted API keys scoped to the caller's current
        organization.


        Callers with the `apiKey.read` permission see all keys in the
        organization; all other callers see only their own keys. The plaintext
        secret is never returned by this endpoint — only the key prefix is
        shown.
      operationId: listApiKeys
      responses:
        '200':
          description: An array of API key objects.
          content:
            application/json:
              schema:
                type: array
                items:
                  $ref: '#/components/schemas/ApiKey'
        '400':
          description: The authenticated user has no active organization.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ApiKeyError'
        '401':
          description: The request is not authenticated.
        default:
          description: Unexpected error.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Error'
components:
  schemas:
    ApiKey:
      type: object
      description: >-
        A user API key. The plaintext secret is never returned after creation;
        only the prefix is stored for display purposes.
      properties:
        id:
          type: string
          description: The unique identifier for the API key.
          example: uuid-1234
        name:
          type: string
          description: A human-readable label for the key.
          example: CI bot
        prefix:
          type: string
          description: >-
            The first 8 characters of the key's random portion — the part that
            follows the `lilt_` prefix. Safe to display.
          example: aaaaaaaa
        createdAt:
          type: string
          format: date-time
          description: ISO-8601 timestamp when the key was created.
          example: '2026-04-29T00:00:00Z'
        expiresAt:
          type: string
          format: date-time
          nullable: true
          description: >-
            ISO-8601 timestamp when the key expires, or null if it does not
            expire.
          example: '2027-01-01T00:00:00Z'
        lastUsedAt:
          type: string
          format: date-time
          nullable: true
          description: ISO-8601 timestamp of the last successful authentication, or null.
          example: '2026-05-01T12:00:00Z'
        revokedAt:
          type: string
          format: date-time
          nullable: true
          description: >-
            ISO-8601 timestamp when the key was revoked, or null if still
            active.
          example: null
        ownerEmail:
          type: string
          nullable: true
          description: >-
            Email address of the user who owns the key. Returned by the list
            endpoint; omitted by `GET /v2/api-keys/{id}`.
          example: developer@lilt.com
        ownerUserId:
          type: integer
          nullable: true
          description: >-
            Numeric identifier of the user who owns the key. Returned by the
            list endpoint; omitted by `GET /v2/api-keys/{id}`.
          example: 42
      required:
        - id
        - name
        - prefix
        - createdAt
    ApiKeyError:
      type: object
      description: >-
        Error response returned by the API Keys endpoints. The human-readable
        message is carried in the `error` field.
      properties:
        error:
          type: string
          description: A human-readable message describing the error.
          example: No active organization
    Error:
      type: object
      properties:
        message:
          type: string
          description: A human-readable message describing the error.
      description: |
        Response in the event of an unexpected error.
      example:
        message: Internal server error.
  securitySchemes:
    BasicAuth:
      type: http
      scheme: basic
    ApiKeyAuth:
      type: apiKey
      name: key
      in: query

````