Skip to main content
GET
List API keys (masked)

Authorizations

Authorization
string
header
required

Either a Supabase user access token (from a password login, or the passwordless magic-link flow) or a long-lived forge_sk_… API key. Both are sent as Authorization: Bearer <value> and resolve to the same owner, so every endpoint accepts either. Session tokens expire in ~1h; API keys do not expire and are the credential for MCP clients, CI, and partner integrations.

Response

Masked listing

keys
object[]