Skip to main content

List access keys

Reviewed on

Returns every AK/SK credential attached to a service account, along with its metadata. The list never contains secret keys: they are only available in the creation response.

Permissions​

info

This action requires the following IAM (Identity and Access Management) permission:

  • iam.accessKey.get

API​

List all the AK/SK credentials attached to a service account, with their status and lifetime.

info

Prerequisites: the service account must exist (create a service account ↗).

This operation requires an access token and the permissions listed at the top of the page.

GET https://api.eu-west-2.numspot.com/iam/organisations/{organisationId}/serviceAccounts/{serviceAccountId}/aksk

Full documentation for this endpoint ↗

Parameters​

ParameterLocationRequiredTypeExampleDescription
organisationIdpathyesUUID123e4567-e89b-12d3-a456-426614174000Organisation owning the service account
serviceAccountIdpathyesUUID123e4567-e89b-12d3-a456-426614174000Service account whose credentials are listed

Example​

export TOKEN="{TOKEN}"

curl 'https://api.eu-west-2.numspot.com/iam/organisations/{ORGANISATION-ID}/serviceAccounts/{SERVICE-ACCOUNT-ID}/aksk' \
--header "Authorization: Bearer $TOKEN"
VariableRepresentsWhere to find its value
{TOKEN}OAuth 2.0 access token of the requestGenerated by the API authentication flow (see Access token)
{ORGANISATION-ID}Organisation owning the service accountNumspot console (active organisation)
{SERVICE-ACCOUNT-ID}Service account whose credentials are listedResponse of the List service accounts ↗ API

Response​

200 OK — a paginated list of credentials:

FieldTypeDescription
nextPageTokenstringCursor of the next page, absent on the last page
totalSizeintegerTotal number of credentials
items[].idstringKey pair identifier
items[].accessKeystringAccess key of the credential
items[].statusstringACTIVE, INACTIVE or EXPIRED
items[].createdAtstringCreation date
items[].expiresAtstringExpiration date
items[].lastUsedAtstringDate of the last use, if the credential has already authenticated a session
{
"nextPageToken": "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9",
"totalSize": 2,
"items": [
{
"id": "019db8c2-1a7b-7de1-8a42-797176d8bbf0",
"accessKey": "AKIAIOSF",
"status": "ACTIVE",
"createdAt": "2026-10-07T10:15:30.485Z",
"expiresAt": "2027-10-07T10:15:30.485Z",
"lastUsedAt": "2026-10-07T14:02:11.220Z"
}
]
}

The secret key is never returned in this list: it is only available in the creation response. Use the id of a credential in the details and delete operations.

Was this page helpful?