List website keys
GET https://datafa.st/api/v1/admin/websites/{websiteId}/apikeysList
df_ website API keys for one website. Returns masked keys only. Mobile app and WooCommerce integration keys are excluded.A
df_ key scoped to the same website can call this endpoint.Request
Path parameters
websiteIdstring
Response
Returns a JSON object with
status: "success" and endpoint-specific fields in data.Response fields
data[].idstring
Website API key ObjectId.
data[].userIdstring
User ObjectId that owns the key.
data[].namestring|null
Human-readable name for the resource or event. The exact meaning depends on the endpoint.
data[].displayKeystring
Masked key shown in the dashboard.
data[].websiteIdstring
Website ObjectId used by account tokens to choose which website to query or manage.
data[].keyPrefixstring
Indexed key prefix used for lookup.
data[].lastUsedAtstring|null
Last usage timestamp.
data[].usageCountnumber
Number of authenticated uses.
data[].isMobileboolean
Whether the key was created for the mobile app. Mobile keys are excluded from list responses.
data[].createdAtstring
Creation timestamp.
data[].updatedAtstring
Last update timestamp.
data[].keystring
Only returned when creating or rolling a key. Full raw key shown once.
Authentication
Use a
dft_ account token with api-keys:read.A
df_ website API key for the same website can also call this route when the path websiteId matches the key's website. Write access with a df_ key is capped at member level — owner-only actions such as team management require a dft_ token and owner role.Errors
See API errors for the standard error envelope, auth failures, validation errors, permission errors, and rate limits.