> ## Documentation Index
> Fetch the complete documentation index at: https://docs.anycrm.anyreach.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# List Organization API Keys

Organization API keys (`ak_…`) are AnyCRM's own credential type — see [Authentication](/authentication) for how they differ from user personal access tokens. All eight PAT/key management endpoints are gated on the [token-management scopes](/authentication#scopes) (`pats:read`, `pats:create`, `pats:delete`), which every default role carries.

### Auth

Requires `pats:read` and an active organization. Results are filtered to the caller's own `user_id` and, through row-level security, the token's active organization.

A caller holding `organizations:manage` (the `admin` role) instead gets **every** key in the organization, so an admin can revoke a departed member's key — see [Delete an Organization API Key](/api-reference/pats/delete-org-key). Keys owned by another member carry `owner_user_id` and `owner_name`; the admin's own keys leave both `null`, so the two are always distinguishable.

### Response

`200 OK` — a bare JSON array (no envelope), ordered newest-first.

| Field           | Type             | Description                                                                                                                                                     |
| --------------- | ---------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| `id`            | `string` (uuid)  | The key's row id in the `pats` table — use this for [Delete an Organization API Key](/api-reference/pats/delete-org-key).                                       |
| `name`          | `string`         | Label given at creation.                                                                                                                                        |
| `pat_key`       | `null`           | Always `null` on list — the plaintext secret is only ever returned once, on create.                                                                             |
| `key_id`        | `string`         | First 15 characters of the internal `ak_<hex>` key id — a display-only partial identifier, not the full id and not enough to reconstruct the secret.            |
| `expires_at`    | `string \| null` | ISO 8601 timestamp, or `null` if the key never expires.                                                                                                         |
| `created_at`    | `string \| null` | ISO 8601 timestamp.                                                                                                                                             |
| `owner_user_id` | `string \| null` | The Logto user id of the member who owns the key — set only when that isn't you, so it is always `null` outside the admin view.                                 |
| `owner_name`    | `string \| null` | Display name (or email) for `owner_user_id`. `null` when the key is yours, or when the name couldn't be resolved — the listing still succeeds, just unlabelled. |


## OpenAPI

````yaml GET /organization-pats
openapi: 3.1.0
info:
  title: anycrm-api
  version: 0.0.1
servers: []
security: []
tags:
  - name: Customer Intelligence
    description: >-
      Company research and ICP-fit scoring — create a research run, track its
      progress, and read back scored companies as leads.
  - name: Outreach
    description: >-
      The cold-email management console — domains, mailboxes, and campaigns — as
      a thin control plane over the SalesForge stack.
  - name: AnyCard
    description: >-
      Authenticated CRUD for AnyCard, the org's digital business-card /
      lead-capture product.
  - name: AnyCard Events
    description: >-
      Event-attribution analytics for AnyCard — which captured leads converted,
      broken down by source, owner, and deal.
  - name: AnyCard Share Links
    description: >-
      Unauthenticated endpoints reached by anyone who scans a QR code or opens a
      shared AnyCard link.
  - name: AI
    description: >-
      A streaming (SSE) AI chat endpoint with account-commit actions it can take
      on the caller's behalf.
  - name: Analytics Assistant
    description: >-
      The natural-language analytics assistant — a guarded text-to-SQL loop
      (SSE) that answers ad-hoc questions over the org's CRM data as a
      least-privilege, read-only database role.
  - name: Account Readiness
    description: >-
      Account Readiness Profiles — AI-scored signals on whether an account is
      ready for outreach or expansion, computed via a Temporal workflow.
  - name: Integrations
    description: >-
      Pipedream Connect — issuing connect tokens and managing the org's
      connected third-party accounts.
  - name: Feedback
    description: >-
      User-submitted platform feedback (bug reports, feature requests) — global,
      not scoped to one organization.
  - name: Public Media
    description: >-
      Unauthenticated image reads for publicly-embeddable assets (card photos,
      inline email images) — allowlisted by key shape; everything else in the
      storage bucket stays private.
  - name: Service Health
    description: Service liveness.
paths:
  /organization-pats:
    get:
      tags:
        - PATs
      summary: List Pats
      operationId: list_pats_organization_pats_get
      responses:
        '200':
          description: Successful Response
          content:
            application/json:
              schema:
                items:
                  $ref: '#/components/schemas/PatResponse'
                type: array
                title: Response List Pats Organization Pats Get
      security:
        - HTTPBearer: []
components:
  schemas:
    PatResponse:
      properties:
        id:
          type: string
          title: Id
        name:
          type: string
          title: Name
        pat_key:
          anyOf:
            - type: string
            - type: 'null'
          title: Pat Key
        expires_at:
          anyOf:
            - type: string
            - type: 'null'
          title: Expires At
        created_at:
          anyOf:
            - type: string
            - type: 'null'
          title: Created At
        key_id:
          type: string
          title: Key Id
        owner_user_id:
          anyOf:
            - type: string
            - type: 'null'
          title: Owner User Id
        owner_name:
          anyOf:
            - type: string
            - type: 'null'
          title: Owner Name
      type: object
      required:
        - id
        - name
        - key_id
      title: PatResponse
  securitySchemes:
    HTTPBearer:
      type: http
      scheme: bearer

````