Lists API keys. Requires secret:read or secret.read.
Request
GET /secret
Query Parameters
| Parameter | Type | Default | Description |
|---|---|---|---|
_start | integer | 0 | Pagination offset. |
_end | integer | 10 | End index (exclusive). Page size is _end - _start. |
active | boolean | — | When set, filters by isActive. |
Headers
| Header | Value |
|---|---|
Authorization | Bearer <token> (or HMAC headers, see Authentication) |
Response
JSON array of secret objects. X-Makaira-Total is the number of items in this page.
| Field | Type | Description |
|---|---|---|
id | integer | Key id. |
isActive | boolean | Inactive keys cannot authenticate. |
title | string | Title. |
description | string | Description (legacy secret for the original Shared Secret). |
createdBy | string | Creator email or Makaira. |
maskedSecret | string | Masked value. |
plainSecret | string or null | Full key if the caller has every permission on the key. |
expiry | string or null | Expiry datetime. |
permissions | array | API permission strings. |

