List access keys
Reviewed on
Returns every AK/SK credential attached to a service account, along with its metadata. The list never contains secret keys: they are only available in the creation response.
Permissions
This action requires the following IAM (Identity and Access Management) permission:
- iam.accessKey.get
- API
API
List all the AK/SK credentials attached to a service account, with their status and lifetime.
Prerequisites: the service account must exist (create a service account ↗).
This operation requires an access token and the permissions listed at the top of the page.
GET https://api.eu-west-2.numspot.com/iam/organisations/{organisationId}/serviceAccounts/{serviceAccountId}/aksk
Full documentation for this endpoint ↗
Parameters
| Parameter | Location | Required | Type | Example | Description |
|---|---|---|---|---|---|
organisationId | path | yes | UUID | 123e4567-e89b-12d3-a456-426614174000 | Organisation owning the service account |
serviceAccountId | path | yes | UUID | 123e4567-e89b-12d3-a456-426614174000 | Service account whose credentials are listed |
Example
export TOKEN="{TOKEN}"
curl 'https://api.eu-west-2.numspot.com/iam/organisations/{ORGANISATION-ID}/serviceAccounts/{SERVICE-ACCOUNT-ID}/aksk' \
--header "Authorization: Bearer $TOKEN"
| Variable | Represents | Where to find its value |
|---|---|---|
{TOKEN} | OAuth 2.0 access token of the request | Generated by the API authentication flow (see Access token) |
{ORGANISATION-ID} | Organisation owning the service account | Numspot console (active organisation) |
{SERVICE-ACCOUNT-ID} | Service account whose credentials are listed | Response of the List service accounts ↗ API |
Response
200 OK — a paginated list of credentials:
| Field | Type | Description |
|---|---|---|
nextPageToken | string | Cursor of the next page, absent on the last page |
totalSize | integer | Total number of credentials |
items[].id | string | Key pair identifier |
items[].accessKey | string | Access key of the credential |
items[].status | string | ACTIVE, INACTIVE or EXPIRED |
items[].createdAt | string | Creation date |
items[].expiresAt | string | Expiration date |
items[].lastUsedAt | string | Date of the last use, if the credential has already authenticated a session |
{
"nextPageToken": "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9",
"totalSize": 2,
"items": [
{
"id": "019db8c2-1a7b-7de1-8a42-797176d8bbf0",
"accessKey": "AKIAIOSF",
"status": "ACTIVE",
"createdAt": "2026-10-07T10:15:30.485Z",
"expiresAt": "2027-10-07T10:15:30.485Z",
"lastUsedAt": "2026-10-07T14:02:11.220Z"
}
]
}
The secret key is never returned in this list: it is only available in the creation response. Use the id of a credential in the details and delete operations.