> ## Documentation Index
> Fetch the complete documentation index at: https://docs.xquik.com/llms.txt
> Use this file to discover all available pages before exploring further.

# X API key management: list active Xquik keys

> List Xquik API keys for X API authentication. Review each key ID, name, safe prefix, active state, creation time & last use before rotation or revocation.

<Panel>
  <Tabs defaultTabIndex={0} sync={false}>
    <Tab title="200" id="response-api-keys-list-200">
      ```json theme={null}
      {
        "keys": [],
        "hasMore": false
      }
      ```
    </Tab>

    <Tab title="400" id="response-api-keys-list-400">
      ```json theme={null}
      {
        "error": "invalid_input",
        "message": "Invalid input. Check the request body."
      }
      ```
    </Tab>

    <Tab title="401" id="response-api-keys-list-401">
      ```json theme={null}
      {
        "error": "unauthenticated",
        "message": "Authentication required. Provide a valid API key or bearer token."
      }
      ```
    </Tab>

    <Tab title="429" id="response-api-keys-list-429">
      ```json theme={null}
      {
        "error": "rate_limit_exceeded",
        "message": "Too many requests. Try again later.",
        "retryAfter": 60
      }
      ```
    </Tab>
  </Tabs>
</Panel>

<blockquote className="agent-llms-directive">
  For the complete documentation index, see <a href="/llms.txt">llms.txt</a>.
</blockquote>

## Audit Xquik API keys before X automation

List every Xquik key registered to the signed-in account. Review keys before
running tweet searches, follower exports, webhooks, monitors, or X writes.

This endpoint returns key inventory metadata. It never returns a complete API
key. Use `id` for revocation and `prefix` for safe identification.

The key list answers 5 operational questions:

* Which named Xquik keys exist on this account?
* Which keys are active or revoked?
* When was each key created?
* When did each key last authenticate a request?
* Which key ID should a rotation workflow revoke?

<Callout icon="circle-check" color="#16a34a">
  **Free.** This endpoint does not consume credits.
</Callout>

<CodeGroup>
  ```bash cURL theme={null}
  curl https://xquik.com/api/v1/api-keys \
    -H "Cookie: session_token=YOUR_SESSION_TOKEN" | jq
  ```

  ```javascript Node.js theme={null}
  const response = await fetch("https://xquik.com/api/v1/api-keys", {
    headers: { Cookie: "session_token=YOUR_SESSION_TOKEN" },
  });
  const result = await response.json();
  if (!response.ok) throw new Error(JSON.stringify(result));

  const keyInventory = result.keys.map((key) => ({
    id: key.id,
    name: key.name,
    safePrefix: key.prefix,
    active: key.isActive,
    createdAt: key.createdAt,
    lastUsedAt: key.lastUsedAt ?? null,
  }));
  ```

  ```python Python theme={null}
  import requests

  response = requests.get(
      "https://xquik.com/api/v1/api-keys",
      cookies={"session_token": "YOUR_SESSION_TOKEN"},
  )
  result = response.json()
  response.raise_for_status()

  key_inventory = [
      {
          "id": key["id"],
          "name": key["name"],
          "safe_prefix": key["prefix"],
          "active": key["isActive"],
          "created_at": key["createdAt"],
          "last_used_at": key.get("lastUsedAt"),
      }
      for key in result["keys"]
  ]
  ```

  ```go Go theme={null}
  package main

  import (
  	"fmt"
  	"io"
  	"log"
  	"net/http"
  )

  func main() {
  	req, err := http.NewRequest("GET", "https://xquik.com/api/v1/api-keys", nil)
  	if err != nil {
  		log.Fatal(err)
  	}
  	req.AddCookie(&http.Cookie{Name: "session_token", Value: "YOUR_SESSION_TOKEN"})

  	resp, err := http.DefaultClient.Do(req)
  	if err != nil {
  		log.Fatal(err)
  	}
  	defer resp.Body.Close()

  	body, err := io.ReadAll(resp.Body)
  	if err != nil {
  		log.Fatal(err)
  	}
  	fmt.Println(string(body))
  }
  ```
</CodeGroup>

## Read the API key inventory

Treat the response as an account credential inventory. Never treat it as a
secret recovery endpoint.

| Inventory check | Response field | Management decision |
| - | - | - |
| Stable key record | `id` | Pass this ID to the revoke endpoint. |
| Workload label | `name` | Match the key to its service or environment. |
| Safe identifier | `prefix` | Compare deployments without exposing the full key. |
| Current state | `isActive` | Accept requests only when this value is `true`. |
| Credential age | `createdAt` | Review old keys against your rotation policy. |
| Last authentication | `lastUsedAt` | Investigate stale keys and keys active without a known workload. |

`lastUsedAt` is optional. Its absence means Xquik recorded no authenticated use.
Xquik refreshes it at most once a minute, so it can trail the latest call by up
to 60 seconds.
It does not prove that a deployment no longer needs the key.

Check scheduled jobs before revoking a quiet key. A monthly follower export
can remain valid without recent requests. Confirm the owner and workload first.

## Distinguish Xquik keys from official X credentials

An Xquik API key starts with `xq_`. It authenticates requests to Xquik routes.
It is not an official Twitter API key or X developer bearer token.

| Credential | Purpose | Where to manage it |
| - | - | - |
| Xquik API key | Authenticate Xquik tweet, follower, monitor, webhook, and write routes. | Xquik API key pages. |
| Official X API key | Identify an application on the X developer platform. | X developer console. |
| Xquik dashboard session | Authorize Xquik API key management. | Signed-in Xquik dashboard. |

Official X documentation separates application keys from bearer tokens. Read
its [authentication overview](https://docs.x.com/fundamentals/authentication/oauth-1-0a/api-key-and-secret)
when integrating directly with the X developer platform.

Use [Xquik authentication](/api-reference/authentication) for Xquik request
headers. Use this list endpoint only for Xquik credential inventory.

## Rotate an Xquik API key

Create the replacement before revoking the current key. This overlap prevents
failed tweet, follower, webhook, and monitor requests.

1. List keys and record the current `id`, `name`, and `prefix`.
2. [Create a replacement key](/api-reference/api-keys/create) with a clear name.
3. Store the returned `fullKey` in an approved secret manager.
4. Update one deployment without logging the replacement value.
5. Send a planned Xquik request from that deployment.
6. List keys and verify the replacement `lastUsedAt` value.
7. [Revoke the old key](/api-reference/api-keys/revoke) by its exact `id`.
8. List keys again and confirm the old key is inactive.

OWASP treats creation, rotation, revocation, and expiration as a secret
lifecycle. Review its [secrets management guidance](https://cheatsheetseries.owasp.org/cheatsheets/Secrets_Management_Cheat_Sheet.html)
when defining your organization policy.

The Xquik list response does not expose scopes or expiration fields. Do not
invent those controls from names or prefixes. Use `isActive` as the documented
key state.

## Common X API key questions

### Can I recover my full Xquik API key?

No. `GET /api-keys` returns only a safe prefix. The creation response returns
`fullKey` once. Create a replacement when the stored secret is unavailable.

### Can an API key list other Xquik keys?

No. This management endpoint requires a same-origin dashboard session. An
`x-api-key` header or OAuth bearer token cannot authorize the request.

### How do I check which Xquik key is active?

Match the deployed key prefix with `prefix`. Then check `isActive`. Never print
the complete deployed key during this comparison.

### What does a missing last-used time mean?

The key has no recorded authenticated request. It may be new or unused. Check
the intended workload before revocation.

### Does this endpoint list official Twitter API keys?

No. It lists Xquik keys for Xquik endpoints. Manage official X developer
credentials in the X developer console.

## Headers

<ParamField header="Cookie" type="string">
  Dashboard session cookie. Format: `session_token=YOUR_SESSION_TOKEN`.
</ParamField>

## Query parameters

<ParamField query="limit" type="integer">
  Maximum items per page: 1 to 200, default 200.
</ParamField>

<ParamField query="cursor" type="string">
  `nextCursor` from the previous page. The `after` alias also works. Offset pagination is not
  supported.
</ParamField>

## Response

### 200 OK

<ResponseField name="keys" type="array">
  Array of API key objects.
  **Key object fields.**

  <ResponseField name="id" type="string">
    Unique identifier for the API key.
  </ResponseField>

  <ResponseField name="name" type="string">
    Display name of the key.
  </ResponseField>

  <ResponseField name="prefix" type="string">
    First 8 characters of the key including the `xq_` prefix (for example `"xq_a1b2"`).
  </ResponseField>

  <ResponseField name="isActive" type="boolean">
    Whether the key is active.
  </ResponseField>

  <ResponseField name="createdAt" type="string">
    ISO 8601 creation timestamp.
  </ResponseField>

  <ResponseField name="lastUsedAt" type="string">
    ISO 8601 timestamp of the last API call made with this key, refreshed at most once a minute. Omitted if never used.
  </ResponseField>
</ResponseField>

<ResponseField name="hasMore" type="boolean">
  Whether more rows follow this page.
</ResponseField>

<ResponseField name="nextCursor" type="string">
  Pass it as `cursor` for the next page. Present when `hasMore` is `true`.
</ResponseField>

```json theme={null}
{
  "keys": [
    {
      "id": "42",
      "name": "Production",
      "prefix": "xq_a1b2",
      "isActive": true,
      "createdAt": "2026-02-24T10:30:00.000Z",
      "lastUsedAt": "2026-02-24T18:45:12.000Z"
    },
    {
      "id": "43",
      "name": "Staging",
      "prefix": "xq_c3d4",
      "isActive": true,
      "createdAt": "2026-02-20T09:00:00.000Z"
    }
  ],
  "hasMore": false
}
```

### 400 Invalid cursor

```json theme={null}
{
  "error": "invalid_input",
  "message": "Cursor invalid. Use nextCursor from the previous page, or omit it to start over."
}
```

The `cursor` is not one this list returned. Send the `nextCursor` of the previous page, or omit it.

### 401 Unauthenticated

```json theme={null}
{ "error": "unauthenticated" }
```

Missing, expired, or invalid dashboard session cookie.

### 429 Rate limited

```json theme={null}
{
  "error": "rate_limit_exceeded",
  "message": "Too many requests. Try again later.",
  "retryAfter": 1
}
```

Too many requests. Wait for the `Retry-After` header before retrying.

<Note>
  API key listing requires a same-origin dashboard session. API keys and OAuth
  bearer tokens cannot list account keys.

  **Related.** [Create API Key](/api-reference/api-keys/create) · [Revoke API Key](/api-reference/api-keys/revoke)
</Note>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.