> ## Documentation Index
> Fetch the complete documentation index at: https://starcovery.com/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# List API keys

> List product API keys. Agent access tokens (names starting with agent:) receive 403; humans mint keys after claim via session or human-minted key.



## OpenAPI

````yaml GET /api/keys
openapi: 3.1.0
info:
  description: >-
    Starcovery helps you find and hire real Instagram and TikTok creators from a
    plain-language brief, on the web or from your agents. REST and MCP API.
    Search accepts unsigned callers. Campaigns, billing state, and keys accept
    browser session, x-api-key, or Bearer. MCP accepts OAuth, x-api-key, Bearer,
    or last-resort ?api_key= (no session). Machine Payments Protocol
    (x-payment-info) on GET /api/search when provisioned. Signup and claim at
    auth.md.
  title: Starcovery
  version: 1.0.0
servers:
  - url: https://www.starcovery.com
security: []
paths:
  /api/keys:
    get:
      summary: List API keys
      description: >-
        List product API keys. Agent access tokens (names starting with agent:)
        receive 403; humans mint keys after claim via session or human-minted
        key.
      responses:
        '200':
          content:
            application/json:
              schema:
                additionalProperties: false
                properties:
                  keys:
                    items:
                      $ref: '#/components/schemas/ApiKeySummary'
                    type: array
                required:
                  - keys
                type: object
          description: API key summaries
        '401':
          description: >-
            unauthorized: missing identity; WWW-Authenticate points at
            protected-resource metadata
        '403':
          description: 'forbidden: agent access token cannot manage keys'
        '429':
          description: Rate limited
      security:
        - ApiKeyHeader: []
        - BearerAuth: []
        - SessionCookie: []
components:
  schemas:
    ApiKeySummary:
      additionalProperties: false
      properties:
        createdAt:
          format: date-time
          type: string
        id:
          type: string
        lastRequest:
          format: date-time
          type:
            - string
            - 'null'
        name:
          type:
            - string
            - 'null'
        start:
          description: Key prefix for display
          type:
            - string
            - 'null'
      required:
        - createdAt
        - id
        - lastRequest
        - name
        - start
      type: object
  securitySchemes:
    ApiKeyHeader:
      description: Product API key or agent access token
      in: header
      name: x-api-key
      type: apiKey
    BearerAuth:
      bearerFormat: access token
      description: >-
        Bearer access token (agent registration), product API key, or MCP OAuth
        access token
      scheme: bearer
      type: http
    SessionCookie:
      description: >-
        Browser better-auth session cookie (REST only; MCP rejects sessions).
        Name is better-auth.session_token, or __Secure-better-auth.session_token
        on HTTPS.
      in: cookie
      name: better-auth.session_token
      type: apiKey

````