Skip to main content
GET
curl
The response body shown here is a static example, not live data. After you click Send, your live result appears in a separate panel headed 200 OK. The panel under the status-code tabs is a fixed sample from the spec — its field values (fees, prices, sizes, IDs, timestamps) are placeholders. Use Send, or call the endpoint, for current values.
Returns all API keys associated with the given Ethereum address. No authentication required — API keys are Ed25519 public keys and are not secret. Use this to bootstrap: check whether a locally stored key is still active before attempting authenticated requests, and trigger key creation if not. With no accountIndex, the listing spans every subaccount of the address (plus any all-subaccounts keys). A single-subaccount key entry is tagged with the accountIndex it belongs to; an all-subaccounts key entry omits accountIndex and sets allSubaccounts: true — use that flag as the scope discriminator. Pass accountIndex to scope the listing to one single-subaccount partition. Because the response is all-or-nothing across subaccounts, a 200 is safe to treat as the complete set for the requested window — an unreadable subaccount surfaces as a 500 rather than a short list that would look like a revoked key. Results are ordered newest-first by createdAt and capped at limit (default and max 1000). Narrow the set with limit / from / to; createdAt is epoch milliseconds, the same unit the bounds take, so a value read from one page is a valid bound for the next.

Query Parameters

address
string
required

Master Ethereum address for this API key (must match address from POST /createApiKey for the same key). Required on REST for account-scoped reads and for place/cancel. Invalid hex → 400; mismatch with key → 403.

20-byte EVM address as hex: optional 0x or 0X prefix and exactly 40 hexadecimal digits. API responses normalize to lowercase a–f after 0x.

Pattern: ^(0x|0X)?[0-9a-fA-F]{40}$
accountIndex
integer

Subaccount index (0–9) to scope the listing to. Omit it to list the keys of every subaccount — unlike other account-scoped reads, this parameter has no default, and an omitted value is not the same as accountIndex=0. A single-subaccount key entry carries its own accountIndex; an all-subaccounts key entry omits accountIndex and sets allSubaccounts: true instead. Group an unscoped listing client-side on allSubaccounts first, then accountIndex — no need for one request per subaccount. Non-integer or out-of-range values → 400 (never a silent fallback to 0).

Required range: 0 <= x <= 9
limit
integer
default:1000

Maximum number of API keys to return. Default and maximum are both 1000; requests above the maximum are silently clamped. The window is applied before this cap, so a windowed page still carries up to limit keys. When no accountIndex is given the cap is global across every subaccount — the page is the limit most recently created keys the address holds.

Required range: 1 <= x <= 1000
from
integer<int64>

Start of the time window, filtering on createdAt (epoch milliseconds, inclusive) — the same unit and field the response reports, so a createdAt read from one page is a valid bound for the next with no conversion. Omit (or pass 0) for an open-ended start.

Note: unlike the time-series list endpoints (orders, fills, …) whose bounds are microseconds, this endpoint's timestamps are milliseconds; bounds match that unit.

Required range: x >= 0
Example:

1785801600123

to
integer<int64>

End of the time window, filtering on createdAt (epoch milliseconds, inclusive) — the same unit and field the response reports, so a createdAt read from one page is a valid bound for the next with no conversion. Omit (or pass 0) for an open-ended end.

Required range: x >= 0
Example:

1785801699001

Response

List of API keys — for every subaccount of the address, or for the single subaccount named by accountIndex. Ordered newest-first by createdAt and capped at limit.

apiKeys
object[]
required