# List API tokens

> Source: https://elaichi.ai/docs/api-reference/api-tokens/api-token/listapitokens/

`GET /api-token`

Resource: **Api Token** · API: **API tokens**

## Query parameters

- **`q`** _(string)_
  Case-insensitive substring match on the token's name. LIKE wildcards are matched literally. Max 200 characters.

## Response body

- **`result`** _(array<object>)_
  - **`id`** _(string)_
    API token id (`atok_…`).
  - **`organization_id`** _(string)_
    The single organization this token can address (`org_…`).
  - **`user_id`** _(string)_
    Member (`usr_…`) the token acts as. It carries that member's permissions, live.
  - **`name`** _(string)_
  - **`last_used_at`** _(string,null)_
  - **`impersonated_by_user_id`** _(string,null)_
    Set when Elaichi support created this token while signed in as `user_id` (a support session). The token keeps working after the support session ends, but is refused with `403 staff_impersonation_blocked` once the organization turns `allow_staff_impersonation` off, and its actions are audited with `metadata.impersonated_by_user_id`. `null` for a token the member created themselves.
  - **`created_at`** _(string)_
  - **`updated_at`** _(string)_
- **`next_cursor`** _(string,null)_
- **`prev_cursor`** _(string,null)_

## Code examples

### curl

```bash
curl -X GET 'https://api.elaichi.ai/api-token' \
  -H 'Authorization: Bearer $ELAICHI_API_TOKEN' \
  -H 'Content-Type: application/json'
```

### JavaScript

```javascript
const response = await fetch('https://api.elaichi.ai/api-token', {
  method: 'GET',
  headers: {
    'Authorization': 'Bearer ' + process.env.ELAICHI_API_TOKEN,
    'Content-Type': 'application/json',
  },
});

const data = await response.json();
console.log(data);
```

### Python

```python
import os
import requests

url = "https://api.elaichi.ai/api-token"
headers = {
    "Authorization": f"Bearer {os.environ['ELAICHI_API_TOKEN']}",
    "Content-Type": "application/json",
}

response = requests.get(url, headers=headers)
print(response.json())
```
