# List all Access Keys

```
POST https://mgmt.storage.dev/v1/providers/:provider_id/orgs/:org_id/keys
```

Lists all the access keys for a user in the organization account.

## Request

### Path Parameters

**provider_id** string required  
Provider ID

**org_id** string required  
Organization ID

- application/json
- Body
- Example (auto)

### Body **required**

**user_id** string required  
ID of the user for whom the access keys are being listed

**user_role** OrgMembership  
Role of the user in the organization. Controls what the user can do through the Partner API management endpoints.

- `Admin`: Full org access. Can list and manage all access keys in the org, update org settings, and manage users. ListAccessKeys returns all keys in the org.
- `Member`: Standard access. Can only manage their own access keys. ListAccessKeys returns only keys owned by this user.

If omitted, defaults to `Member` behavior.

**Possible values:** [`Admin`, `Member`]

**limit** integer  
Maximum number of keys to return. Defaults to 100, max 1000.

**continuation_token** string  
Token from previous response to fetch next page.

**key_id_prefix** string  
List only keys with specific ID prefix

```json
{
  "user_id": "string",
  "user_role": "Admin",
  "limit": 0,
  "continuation_token": "string",
  "key_id_prefix": "string"
}
```

## Responses

- 200
- default  
OK

- application/json

**Schema**

**keys** object[] required  
Array [
  
**id** string required  
Access key ID  
  
**name** string required  
Name of the access key  
  
**status** string required  
Status of the access key.

**Possible values:** [`Active`, `Inactive`]
  
**buckets_roles** object[]  
Array [  
  
**bucket_name** string required  
Name of the bucket  
  
**role** string required  
The role defines the permissions for the associated bucket:
  
- `ReadOnly`: Read-only access to the bucket. Permits read operations like GetObject, HeadObject, ListObjects.
- `Editor`: Read and write access to the bucket. Includes everything in ReadOnly, plus PutObject, DeleteObject, and bucket configuration operations.
- `Admin`: Full access to all buckets in the org, bypasses all permission checks. When used with `bucket_name: "*"`, the access key is treated as a full org admin. The value of `bucket_name` should always be `*` when using this role.

Example:

```json
{
    "bucket_name": "*",
    "role": "Admin"
}
```

**Possible values:** [`ReadOnly`, `Editor`, `Admin`]

]

**next_continuation_token** string  
Pass as continuation_token for next page. Empty if no more results.

```json
{
  "keys": [
    {
      "id": "string",
      "name": "string",
      "status": "Active",
      "buckets_roles": [
        {
          "bucket_name": "string",
          "role": "ReadOnly"
        }
      ]
    }
  ],
  "next_continuation_token": "string"
}
```

Unexpected error

- application/json

**Schema**

**message** string

```json
{
  "message": "string"
}
```

#### Authorization: X-Tigris-Signature

``` 
name: X-Tigris-Signature  
type: apiKey  
in: header  
description: HMAC-SHA256 of the canonical request signed using the signing key.
To create the signature, concatenate the HTTP method, URL, timestamp, and nonce with a newline character in between.
Then, calculate the HMAC-SHA256 of the concatenated string using the signing key. Example:

Create the `canonical_request` as:
```
POST
https://mgmt.storage.dev/provider/your-provider-id/orgs/user-org-id/provision
1731703213870
f8d133cb-5a42-47b1-9ef2-874bb55bab72
```
Then, calculate HMAC-SHA256 of the canonical request using the signing key as:
```
Signature = hex(sha256sign(canonical_request, "signing_key"))
```
```

name: X-Tigris-Nonce  
type: apiKey  
in: header  
description: Random unique string to identify the request and prevent replay attacks. Example: "f8d133cb-5a42-47b1-9ef2-874bb55bab72"
```

```
name: X-Tigris-Time  
type: apiKey  
in: header  
description: Unix timestamp in milliseconds of the request. Example: 1731703213870
```

```csharp
var client = new HttpClient();
var request = new HttpRequestMessage(HttpMethod.Post, "https://mgmt.storage.dev/v1/providers/:provider_id/orgs/:org_id/keys");
request.Headers.Add("Accept", "application/json");
request.Headers.Add("X-Tigris-Signature", "<X-Tigris-Signature>");
request.Headers.Add("X-Tigris-Nonce", "<X-Tigris-Nonce>");
request.Headers.Add("X-Tigris-Time", "<X-Tigris-Time>");
var content = new StringContent("{\n  \"user_id\": \"string\",\n  \"user_role\": \"Admin\",\n  \"limit\": 0,\n  \"continuation_token\": \"string\",\n  \"key_id_prefix\": \"string\"\n}", null, "application/json");
request.Content = content;
var response = await client.SendAsync(request);
response.EnsureSuccessStatusCode();
Console.WriteLine(await response.Content.ReadAsStringAsync());
```

Request Collapse all

Base URL

Edit

https://mgmt.storage.dev

Auth

Signature

Nonce

Timestamp

Parameters

provider_id — path required  
org_id — path required

Body required

```json
{
  "user_id": "string",
  "user_role": "Admin",
  "limit": 0,
  "continuation_token": "string",
  "key_id_prefix": "string"
}
```

Send API Request

Response Clear

Click the `Send API Request` button above and see the response here!
