One change
Retrieve API Key (Admin API)
api/admin/api_keys/retrieve
Nearest release: v2.1.250, published an hour before this site recorded the change. Shown because the two are within 24 hours of each other. Nothing here says the release caused the edit.
api/admin/api_keys/retrieve Changed · +58 / -12 lines
from line 34
ID of the actor that created the object. - - `type: string` + - `type: "service_account" or "user"` Type of the actor that created the object. + - `"service_account"` + + - `"user"` + - `expires_at: string or null` RFC 3339 datetime string indicating when the API Key expires, or `null` if it never expires.
from line 56
Partially redacted hint for the API key. - - `principal: object or null` + - `principal: object or object or null` - The ID and type of the principal the API key acts as, or `null` if the key is not bound to a principal. + The principal the API key acts as (a User or a Service Account), or `null` if the API key is not bound to a principal. - - `id: string` + - `UserActor object` - ID of the principal the API key acts as: a User ID (`user_...`) when the type is `user`, or a Service Account ID (`svac_...`) when the type is `service_account`. + - `type: "user_actor"` - - `type: "service_account" or "user"` + Principal type. Always `"user_actor"` for a User. - Type of the principal the API key acts as. + default: user_actor - - `"service_account"` + - `user_id: string` - - `"user"` + ID of the User the API key acts as. + - `ServiceAccountActor object` + + - `service_account_id: string` + + ID of the Service Account the API key acts as. + + - `type: "service_account_actor"` + + Principal type. Always `"service_account_actor"` for a Service Account. + + default: service_account_actor + + - `scope: object or object` + + Where the API key belongs: its Workspace (`{"type": "workspace", "workspace_id": "wrkspc_..."}`, with the Workspace's real ID even when it is the organization's default Workspace), or the organization (`{"type": "organization"}`) for a principal-bound API key that has no Workspace. + + - `Organization object` + + - `type: "organization"` + + Scope type. Always `"organization"`: the API key has no Workspace. Only a principal-bound API key can have this scope. + + default: organization + + - `Workspace object` + + - `type: "workspace"` + + Scope type. Always `"workspace"`: the API key belongs to one Workspace. + + default: workspace + + - `workspace_id: string` + + ID of the Workspace the API key belongs to. Unlike the deprecated top-level `workspace_id`, this is the Workspace's real ID even for the organization's default Workspace. + - `status: "active" or "archived" or "expired" or "inactive"` Status of the API key.
from line 130
- `workspace_id: string or null` - ID of the Workspace associated with the API key, or `null` if the API key belongs to the default Workspace. + **Deprecated**: Use `scope` instead. `workspace_id` is `null` both for an API key in the default Workspace and for a principal-bound API key that has no Workspace. + Deprecated: use `scope` instead. ID of the Workspace associated with the API key, or `null` if the API key belongs to the default Workspace. Also `null` for a principal-bound API key that has no Workspace; `scope` tells the two apart. + ## Example ```bash
from line 156
"name": "Developer Key", "partial_key_hint": "sk-ant-api03-R2D...igAA", "principal": { - "id": "user_01WCz1FkmYMm4gnmykNKUu3Q", - "type": "user" + "type": "user_actor", + "user_id": "user_01WCz1FkmYMm4gnmykNKUu3Q" + }, + "scope": { + "type": "workspace", + "workspace_id": "wrkspc_01JwQvzr7rXLA5AGx3HKfFUJ" }, "status": "active", "type": "api_key",