List access tokens
GET https://datafa.st/api/v1/admin/access-tokensList all
dft_ account tokens created by the authenticated user. Returns masked keys only — full tokens are shown once at creation.Requires a
dft_ account token. Website API keys cannot access this endpoint.Request
This endpoint does not require any path, query, or body parameters.
Response
Returns a JSON object with
status: "success" and endpoint-specific fields in data.Response fields
data[].idstring
Token ObjectId.
data[].userIdstring
User ObjectId that owns the token.
data[].namestring|null
Human-readable name for the resource or event. The exact meaning depends on the endpoint.
data[].displayKeystring
Masked token shown in the dashboard.
data[].scopestring
Token scope. Account tokens use
user.data[].websiteIdstring|null
Website ObjectId used by account tokens to choose which website to query or manage. Website ObjectId for legacy website-scoped tokens. Account tokens return
null.data[].permissionsstring[]
Granted permission strings.
['*'] means full access. See permission list. Example: ['analytics:read', 'websites:read'].data[].websiteIdsstring[]
Websites this token can access. Empty array
[] means all websites on the account. Example: ['665f0b3c4d2e1a0012345678'].data[].keyPrefixstring
Indexed token prefix used for lookup.
data[].lastUsedAtstring|null
Last usage timestamp.
data[].usageCountnumber
Number of authenticated uses.
data[].createdAtstring
Creation timestamp.
data[].updatedAtstring
Last update timestamp.
data[].keystring
Only returned when creating a token. Full raw token shown once.
Authentication
Requires a
dft_ account token with api-keys:read. Website API keys (df_) cannot call this endpoint because it manages account-level resources.Create tokens in Account settings → API.
Errors
403 — Called with a
df_ website key.See API errors for the standard error envelope, auth failures, validation errors, permission errors, and rate limits.