> For clean Markdown of any page, append .md to the page URL. > For a complete documentation index, see https://docs.getunleash.io/api/get-pats/llms.txt. > For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://docs.getunleash.io/_mcp/server. # Get all personal access tokens (PATs) for the current user. GET https://app.unleash-instance.example.com/api/admin/user/tokens Returns all of the [personal access tokens](https://docs.getunleash.io/concepts/api-tokens-and-client-keys#personal-access-tokens) (PATs) belonging to the current user. Reference: https://docs.getunleash.io/api/get-pats ## Authentication - `Authorization` header (required) — API key needed to access this API - `Authorization` header (bearer token, required) — API key needed to access this API, in Bearer token format ## Response ### 200 #/components/schemas/patsSchema - `pats` (list of patSchema, optional) — A collection of PATs. ## Errors ### 401 Unauthorized Error Authorization information is missing or invalid. Provide a valid API token as the `authorization` header, e.g. `authorization:*.*.my-admin-token`. - `id` (string, optional) — The ID of the error instance - `name` (string, optional) — The name of the error kind - `message` (string, optional) — A description of what went wrong. ### 403 Forbidden Error The provided user credentials are valid, but the user does not have the necessary permissions to perform this operation - `id` (string, optional) — The ID of the error instance - `name` (string, optional) — The name of the error kind - `message` (string, optional) — A description of what went wrong. ### 404 Not Found Error The requested resource was not found. - `id` (string, optional) — The ID of the error instance - `name` (string, optional) — The name of the error kind - `message` (string, optional) — A description of what went wrong. ## Types ### patSchema Describes a [personal access token](https://docs.getunleash.io/concepts/api-tokens-and-client-keys#personal-access-tokens), or PAT. PATs are automatically scoped to the authenticated user. - `id` (integer, required) — The PAT's ID. PAT IDs are incrementing integers. In other words, a more recently created PAT will always have a higher ID than an older one. - `createdAt` (string, required) — The date and time of when the PAT was created. - `description` (string, required) — The PAT's description. - `expiresAt` (string, required) — The PAT's expiration date. - `secret` (string, optional) — The token used for authentication. It is automatically generated by Unleash when the PAT is created and that is the only time this property is returned. - `seenAt` (string, optional, nullable) — When the PAT was last seen/used to authenticate with. `null` if it has not been used yet. - `userId` (integer, optional) — The ID of the user this PAT belongs to. - `expiryWarning` (enum, optional) — A warning about the expiration of this PAT, absent when there is nothing to warn about. `expires-soon` means the PAT is past the middle of its lifetime and expires within one of the configured `tokenExpiryNotificationDays` lead times; `expired` means it is no longer usable. - Allowed values: `expires-soon`, `expired` ## Examples **Response** ```json { "pats": [ { "id": 1, "createdAt": "2023-04-19T08:15:14.000Z", "description": "user:xyzrandomstring", "expiresAt": "2023-04-19T08:15:14.000Z", "secret": "user:xyzrandomstring", "seenAt": "2023-04-19T08:15:14.000Z", "userId": 1337, "expiryWarning": "expires-soon" } ] } ``` **SDK Code** ```python import requests url = "https://app.unleash-instance.example.com/api/admin/user/tokens" headers = {"Authorization": ""} response = requests.get(url, headers=headers) print(response.json()) ``` ```javascript const url = 'https://app.unleash-instance.example.com/api/admin/user/tokens'; const options = {method: 'GET', headers: {Authorization: ''}}; try { const response = await fetch(url, options); const data = await response.json(); console.log(data); } catch (error) { console.error(error); } ``` ```go package main import ( "fmt" "net/http" "io" ) func main() { url := "https://app.unleash-instance.example.com/api/admin/user/tokens" req, _ := http.NewRequest("GET", url, nil) req.Header.Add("Authorization", "") res, _ := http.DefaultClient.Do(req) defer res.Body.Close() body, _ := io.ReadAll(res.Body) fmt.Println(res) fmt.Println(string(body)) } ``` ```ruby require 'uri' require 'net/http' url = URI("https://app.unleash-instance.example.com/api/admin/user/tokens") http = Net::HTTP.new(url.host, url.port) http.use_ssl = true request = Net::HTTP::Get.new(url) request["Authorization"] = '' response = http.request(request) puts response.read_body ``` ```java import com.mashape.unirest.http.HttpResponse; import com.mashape.unirest.http.Unirest; HttpResponse response = Unirest.get("https://app.unleash-instance.example.com/api/admin/user/tokens") .header("Authorization", "") .asString(); ``` ```php request('GET', 'https://app.unleash-instance.example.com/api/admin/user/tokens', [ 'headers' => [ 'Authorization' => '', ], ]); echo $response->getBody(); ``` ```csharp using RestSharp; var client = new RestClient("https://app.unleash-instance.example.com/api/admin/user/tokens"); var request = new RestRequest(Method.GET); request.AddHeader("Authorization", ""); IRestResponse response = client.Execute(request); ``` ```swift import Foundation let headers = ["Authorization": ""] let request = NSMutableURLRequest(url: NSURL(string: "https://app.unleash-instance.example.com/api/admin/user/tokens")! as URL, cachePolicy: .useProtocolCachePolicy, timeoutInterval: 10.0) request.httpMethod = "GET" request.allHTTPHeaderFields = headers let session = URLSession.shared let dataTask = session.dataTask(with: request as URLRequest, completionHandler: { (data, response, error) -> Void in if (error != nil) { print(error as Any) } else { let httpResponse = response as? HTTPURLResponse print(httpResponse) } }) dataTask.resume() ```