> ## Documentation Index
> Fetch the complete documentation index at: https://langwatch.ai/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Get an API key

> Read one API key by id, including its role bindings, permission mode and explicit permissions. Returns your own keys; organization admins may read any key in the organization. The secret is never returned. An id that does not exist, belongs to another organization, or belongs to another member all answer 404 api_key_not_found, so the response cannot be used to probe for keys.



## OpenAPI

````yaml GET /api/api-keys/{id}
openapi: 3.1.0
info:
  title: LangWatch API
  version: 1.0.0
  description: LangWatch openapi spec
servers:
  - url: https://app.langwatch.ai
security:
  - project_api_key: []
paths:
  /api/api-keys/{id}:
    get:
      summary: Get an API key
      description: >-
        Read one API key by id, including its role bindings, permission mode and
        explicit permissions. Returns your own keys; organization admins may
        read any key in the organization. The secret is never returned. An id
        that does not exist, belongs to another organization, or belongs to
        another member all answer 404 api_key_not_found, so the response cannot
        be used to probe for keys.
      operationId: getApiKey
      parameters:
        - name: id
          in: path
          required: true
          schema:
            type: string
          description: API key ID
      responses:
        '200':
          description: The API key
          content:
            application/json:
              schema:
                type: object
                properties:
                  id:
                    type: string
                  name:
                    type: string
                  description:
                    type: string
                    nullable: true
                  keyType:
                    type: string
                    enum:
                      - personal
                      - service
                  assignedToUserId:
                    type: string
                    nullable: true
                    description: The member who owns the key; null for a service key.
                  createdByUserId:
                    type: string
                    nullable: true
                  permissionMode:
                    type: string
                    enum:
                      - all
                      - readonly
                      - restricted
                  permissions:
                    type: array
                    items:
                      type: string
                    description: >-
                      The resource:action permissions a restricted key grants.
                      Empty for the other modes.
                  createdAt:
                    type: string
                    format: date-time
                  expiresAt:
                    type: string
                    format: date-time
                    nullable: true
                  lastUsedAt:
                    type: string
                    format: date-time
                    nullable: true
                  revokedAt:
                    type: string
                    format: date-time
                    nullable: true
                  roleBindings:
                    type: array
                    items:
                      type: object
                      properties:
                        id:
                          type: string
                        role:
                          type: string
                          enum:
                            - ADMIN
                            - MEMBER
                            - VIEWER
                            - CUSTOM
                        scopeType:
                          type: string
                          enum:
                            - ORGANIZATION
                            - TEAM
                            - PROJECT
                        scopeId:
                          type: string
                  bindings:
                    type: array
                    items:
                      type: object
                      properties:
                        role:
                          type: string
                          enum:
                            - ADMIN
                            - MEMBER
                            - VIEWER
                            - CUSTOM
                        scopeType:
                          type: string
                          enum:
                            - ORGANIZATION
                            - TEAM
                            - PROJECT
                        scopeId:
                          type: string
        '401':
          description: Invalid or missing API key token
        '403':
          description: Insufficient permissions (requires organization:view)
        '404':
          description: API key not found (api_key_not_found)
      security:
        - admin_api_key: []
components:
  securitySchemes:
    project_api_key:
      type: apiKey
      in: header
      name: X-Auth-Token
      description: >-
        Project API key for sending traces and accessing project-scoped
        resources. Format: sk-lw-... (no underscore). Obtain one by creating a
        project via the Admin API or the LangWatch UI.
    admin_api_key:
      type: http
      scheme: bearer
      description: >-
        Admin API key for organization-level operations (managing projects, API
        keys). Create one in Settings > API Keys or via POST /api/api-keys.
        Format: sk-lw-{id}_{secret}.

````