> ## Documentation Index
> Fetch the complete documentation index at: https://docs.snappy.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Get API keys

> Use this endpoint to retrieve a paginated list of API keys for the calling Company. Use this when building a key-management view inside a dashboard or admin tool.

###### Pagination
- `page[number]` - 1-indexed page number (default `1`)
- `page[size]` - keys per page (max `100`, default `100`)

###### Optional headers
- `Snappy-Account-Id` - optional account scoping
- `Snappy-Company-Id` - required for multi-company users to select the target Company

###### Please note
- The actual API key secret is **never returned by this endpoint**. The secret is shown only once - in the response to `POST /v3/authentication/api-keys` - and is not retrievable afterward.

#### Permissions
Authenticated via `Authorization: Bearer <dashboard user JWT>`. Only Company owners and tools admins have access.



## OpenAPI

````yaml get /v3/authentication/api-keys
openapi: 3.0.3
info:
  title: Snappy Public API v3
  version: 3.0.0
  contact:
    name: Snappy Support
    email: info@snappy.com
  description: >-
    Welcome to the Snappy API reference documentation!

    You can use this API to integrate with Snappy and spread smiles to your
    employees/clients/customers and much more.

    So let's get started!
servers:
  - url: https://api.snappy.com/public-api
    description: Base API URL
  - url: https://mtls-api.snappy.com/public-api
    description: >-
      ## mTLS URL

      You can also use mTLS to enhance your API security. To get your specific
      certificates please contact our support.

      Once you configure the certificated correctly, you need to also update
      endpoints to use the following secure api base URL:
security: []
tags:
  - name: Products
    description: >-
      Use these endpoints to retrieve products and tags for building catalog and
      browse experiences in your UI.
  - name: Collections
    description: >-
      Use these endpoints to retrieve products within curated collections for
      marketplace and browse experiences.
  - name: Variants
    description: >-
      Use these endpoints to retrieve variants, variant pricing, and country
      availability for orderable product SKUs.
  - name: Billing Methods
    description: >-
      A **Billing Method** is the funding source attached to an **Account** -
      for example, a Purchase Order (PO), Invoice, Prepay deposit, or Credit
      Card. Use these endpoints to retrieve billing method details such as
      remaining balance, status, and expiration.
  - name: Accounts
    description: >-
      An **Account** is a sub-entity within a **Company**, used to organize
      campaigns and gift sends. Use these endpoints to list, retrieve, and
      create accounts.
  - name: API Keys
    description: >-
      Use these endpoints to manage API keys for programmatic access. Key
      management requires company owner privileges.
  - name: Orders
    description: >-
      Use these endpoints to place, retrieve, cancel, and validate orders and
      shipping addresses.
paths:
  /v3/authentication/api-keys:
    get:
      tags:
        - Api_keys
      summary: List API keys
      description: >-
        Use this endpoint to retrieve a paginated list of API keys for the
        calling Company. Use this when building a key-management view inside a
        dashboard or admin tool.


        ###### Pagination

        - `page[number]` - 1-indexed page number (default `1`)

        - `page[size]` - keys per page (max `100`, default `100`)


        ###### Optional headers

        - `Snappy-Account-Id` - optional account scoping

        - `Snappy-Company-Id` - required for multi-company users to select the
        target Company


        ###### Please note

        - The actual API key secret is **never returned by this endpoint**. The
        secret is shown only once - in the response to `POST
        /v3/authentication/api-keys` - and is not retrievable afterward.


        #### Permissions

        Authenticated via `Authorization: Bearer <dashboard user JWT>`. Only
        Company owners and tools admins have access.
      parameters:
        - schema:
            type: integer
            minimum: 1
            default: 1
            description: 1-indexed page number.
            example: 1
          required: false
          description: 1-indexed page number.
          name: page[number]
          in: query
        - schema:
            type: integer
            minimum: 1
            maximum: 100
            default: 100
            description: Number of API keys per page (max 100, default 100).
            example: 100
          required: false
          description: Number of API keys per page (max 100, default 100).
          name: page[size]
          in: query
        - schema:
            type: string
            description: Optional account identifier for swag validation/filtering.
            example: acc123456
          required: false
          description: Optional account identifier for swag validation/filtering.
          name: snappy-account-id
          in: header
        - schema:
            type: string
            description: Optional company identifier for swag validation/filtering.
            example: cmp123456
          required: false
          description: Optional company identifier for swag validation/filtering.
          name: snappy-company-id
          in: header
      responses:
        '200':
          description: Page of API keys plus pagination links.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/GetApiKeysV3Response'
        '400':
          description: Bad Request - Invalid query parameters.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponseV3'
        '403':
          description: Forbidden - Owner privileges required.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponseV3'
      security:
        - BearerTokenAuthentication: []
        - ApiKeyAuthentication: []
components:
  schemas:
    GetApiKeysV3Response:
      type: object
      properties:
        data:
          type: array
          items:
            $ref: '#/components/schemas/ApiKeyV3'
          description: API keys for the requested page.
        links:
          $ref: '#/components/schemas/PaginationLinksV3'
      required:
        - data
        - links
      description: Paginated API keys response.
    ErrorResponseV3:
      type: object
      properties:
        message:
          type: string
          description: Human-readable error message.
          example: Product not found.
        errorCode:
          type: string
          description: Structured error code.
          example: 404_PROD_001
        errors:
          type: array
          items:
            type: object
            properties:
              message:
                type: string
                example: Product with id 'q1w2e3r4t5' was not found
              path:
                type: string
                description: Dot-separated path to the field that caused the error.
                example: pathParameters.productId
              errorCode:
                type: string
                example: 404_PROD_001
            required:
              - message
              - path
          description: Optional field-level error details.
      required:
        - message
        - errorCode
      description: Standard v3 error envelope.
    ApiKeyV3:
      type: object
      properties:
        id:
          type: string
          description: The API key id.
          example: abc123456
        expirationDate:
          type: string
          nullable: true
          description: >-
            The date the API key will expire. Date Format:
            YYYY-MM-DDThh:mm:ss.sZ.
          example: '2022-12-06T09:50:38.536Z'
        createdAt:
          type: string
          description: >-
            The date the API key was created. Date Format:
            YYYY-MM-DDThh:mm:ss.sZ.
          example: '2022-12-06T09:50:38.536Z'
        enforceMtls:
          type: boolean
          description: Whether the API key requires mTLS.
          example: false
        name:
          type: string
          description: The name of the API key.
          example: My API key
        companyId:
          type: string
          description: The company id.
          example: abc12345678
        permissions:
          $ref: '#/components/schemas/ApiKeyPermissionsV3'
        accountsAccess:
          $ref: '#/components/schemas/AccountsAccessV3'
      required:
        - id
        - expirationDate
        - enforceMtls
        - name
      description: API key object (without secret).
    PaginationLinksV3:
      type: object
      properties:
        first:
          type: string
          nullable: true
          description: Link to the first page.
          example: >-
            /v3/products/655277e68e0719000d6c3fd5/variants?page[size]=100&page[number]=1
        next:
          type: string
          nullable: true
          description: Link to the next page, or `null` on the final page.
          example: >-
            /v3/products/655277e68e0719000d6c3fd5/variants?page[size]=100&page[number]=2
        prev:
          type: string
          nullable: true
          description: Link to the previous page, or `null` when not applicable.
          example: null
      required:
        - first
        - next
        - prev
      description: >-
        Top-level JSON:API-style pagination links for paginated list responses.
        `first`, `next`, and `prev` are all required and all nullable. `prev` is
        `null` on cursor-paginated endpoints (backward navigation not
        supported).
    ApiKeyPermissionsV3:
      type: array
      items:
        type: string
        enum:
          - gifts:create
          - gifts:create:demo
          - gifts:update
          - gifts:read:unmasked
          - gifts:read:masked
          - orders:create
          - orders:cancel
          - orders:read:unmasked
          - orders:read:masked
          - campaigns:create
          - campaigns:update
          - campaigns:read
          - collections:read
          - products:read
          - products:read:prices
          - recipients:create
          - recipients:update
          - recipients:read:unmasked
          - recipients:read:masked
          - recipients:delete
          - accounts:create
          - accounts:read
          - billingMethods:read
      description: The permissions of the API key.
    AccountsAccessV3:
      type: object
      properties:
        scope:
          type: string
          enum:
            - all-accounts
            - specific-accounts
        ids:
          type: array
          items:
            type: string
      required:
        - scope
        - ids
      description: The accounts access of the API key.
  securitySchemes:
    BearerTokenAuthentication:
      type: http
      scheme: bearer
      bearerFormat: JWT
      description: >-
        ## User Bearer Authentication


        Use a dashboard user JWT in the `Authorization` header when managing API
        keys from the Snappy dashboard:

        ```

        Authorization: Bearer YOUR_JWT

        ```


        For multi-company users, also pass `Snappy-Company-Id` to select the
        target company.
    ApiKeyAuthentication:
      type: apiKey
      in: header
      name: X-Api-Key
      description: |-
        ## Company Level Authentication

        Include your API key in the `X-Api-Key` header for every request:
        ```
        X-Api-Key: YOUR_API_KEY
        ```

````