> For clean Markdown of any page, append .md to the page URL. > For a complete documentation index, see https://docs.getunleash.io/api/get-all-api-tokens/llms.txt. > For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://docs.getunleash.io/_mcp/server. # Get API tokens GET https://app.unleash-instance.example.com/api/admin/api-tokens Retrieves all API tokens that exist in the Unleash instance. Reference: https://docs.getunleash.io/api/get-all-api-tokens ## Authentication - `Authorization` header (required) — API key needed to access this API - `Authorization` header (bearer token, required) — API key needed to access this API, in Bearer token format ## Response ### 200 apiTokensSchema - `tokens` (list of apiTokenSchema, required) — A list of Unleash API tokens. ## Errors ### 401 Unauthorized Error Authorization information is missing or invalid. Provide a valid API token as the `authorization` header, e.g. `authorization:*.*.my-admin-token`. - `id` (string, optional) — The ID of the error instance - `name` (string, optional) — The name of the error kind - `message` (string, optional) — A description of what went wrong. ### 403 Forbidden Error The provided user credentials are valid, but the user does not have the necessary permissions to perform this operation - `id` (string, optional) — The ID of the error instance - `name` (string, optional) — The name of the error kind - `message` (string, optional) — A description of what went wrong. ## Types ### apiTokenSchema An overview of an [Unleash API token](https://docs.getunleash.io/concepts/api-tokens-and-client-keys). - `tokenName` (string, required) — A unique name for this particular token - `type` (enum, required) — The type of API token - Allowed values: `client`, `admin`, `frontend`, `backend` - `projects` (list of string, required) — The list of projects this token has access to. If the token has access to specific projects they will be listed here. If the token has access to all projects it will be represented as `[*]` - `createdAt` (string, required) — When the token was created. - `secret` (string, optional, nullable) — The token used for authentication. - `environment` (string, optional, default: development) — The environment the token has access to. - `project` (string, optional) — The project this token belongs to. - `expiresAt` (string, optional, nullable) — The token's expiration date. NULL if the token doesn't have an expiration set. - `seenAt` (string, optional, nullable) — When the token was last seen/used to authenticate with. NULL if the token has not yet been used for authentication. - `alias` (string, optional, nullable) — Alias is no longer in active use and will often be NULL. It's kept around as a way of allowing old proxy tokens created with the old metadata format to keep working. - `secure` (boolean, optional, nullable) — True if using the new api token format. This means copy token will no longer work ## Examples **Response** ```json { "tokens": [ { "tokenName": "some-user", "type": "client", "projects": [ "developerexperience", "enterprisegrowth" ], "createdAt": "2023-04-19T08:15:14.000Z", "secret": "project:environment.xyzrandomstring", "environment": "development", "project": "developerexperience", "expiresAt": "2023-04-19T08:15:14.000Z", "seenAt": "2023-04-19T08:15:14.000Z", "alias": "randomid-or-some-alias", "secure": true } ] } ``` **SDK Code** ```python import requests url = "https://app.unleash-instance.example.com/api/admin/api-tokens" headers = {"Authorization": ""} response = requests.get(url, headers=headers) print(response.json()) ``` ```javascript const url = 'https://app.unleash-instance.example.com/api/admin/api-tokens'; const options = {method: 'GET', headers: {Authorization: ''}}; try { const response = await fetch(url, options); const data = await response.json(); console.log(data); } catch (error) { console.error(error); } ``` ```go package main import ( "fmt" "net/http" "io" ) func main() { url := "https://app.unleash-instance.example.com/api/admin/api-tokens" req, _ := http.NewRequest("GET", url, nil) req.Header.Add("Authorization", "") res, _ := http.DefaultClient.Do(req) defer res.Body.Close() body, _ := io.ReadAll(res.Body) fmt.Println(res) fmt.Println(string(body)) } ``` ```ruby require 'uri' require 'net/http' url = URI("https://app.unleash-instance.example.com/api/admin/api-tokens") http = Net::HTTP.new(url.host, url.port) http.use_ssl = true request = Net::HTTP::Get.new(url) request["Authorization"] = '' response = http.request(request) puts response.read_body ``` ```java import com.mashape.unirest.http.HttpResponse; import com.mashape.unirest.http.Unirest; HttpResponse response = Unirest.get("https://app.unleash-instance.example.com/api/admin/api-tokens") .header("Authorization", "") .asString(); ``` ```php request('GET', 'https://app.unleash-instance.example.com/api/admin/api-tokens', [ 'headers' => [ 'Authorization' => '', ], ]); echo $response->getBody(); ``` ```csharp using RestSharp; var client = new RestClient("https://app.unleash-instance.example.com/api/admin/api-tokens"); var request = new RestRequest(Method.GET); request.AddHeader("Authorization", ""); IRestResponse response = client.Execute(request); ``` ```swift import Foundation let headers = ["Authorization": ""] let request = NSMutableURLRequest(url: NSURL(string: "https://app.unleash-instance.example.com/api/admin/api-tokens")! as URL, cachePolicy: .useProtocolCachePolicy, timeoutInterval: 10.0) request.httpMethod = "GET" request.allHTTPHeaderFields = headers let session = URLSession.shared let dataTask = session.dataTask(with: request as URLRequest, completionHandler: { (data, response, error) -> Void in if (error != nil) { print(error as Any) } else { let httpResponse = response as? HTTPURLResponse print(httpResponse) } }) dataTask.resume() ```