List Credentials

Beta
List every active credential in the caller's workspace, newest first. The vault is write-only: each `config` is the masked `CredentialConfigView` (non-secret fields plus `*_set` markers) — secret values are never returned. Soft-deleted credentials are omitted. Cursor-paginated: omit `cursor` for the first page; walk pages while `has_more` is true (default page size 50, max 200).

Authentication

AuthorizationBearer

Enter your API key with the Bearer prefix, e.g. ‘Bearer sk_…’.

Headers

Speechify-VersionstringOptional

Query parameters

cursorstringOptional
Opaque pagination cursor from a previous response.
limitintegerOptional1-200Defaults to 50

Max items per page (default 50, max 200).

project_idstringOptional
Filter credentials by project scope: omit for everything the caller may see, pass the literal `shared` for workspace-shared credentials only, or a `proj_...` id for credentials scoped to that project. Credentials have no Default project - a null `project_id` means workspace-shared, so the literal here is `shared`, never `default`. Returns 404 project_not_found for a malformed id and for any project outside your reach: a project-pinned API key or service-account key reaches only its pinned project, and a member holding project grants reaches only the granted projects. That 404 is the same in every case and does not reveal whether such a project exists - outside your reach a project is answered as nonexistent, never as forbidden. `shared` is always inside your reach. Inside it, a well-formed id that matches nothing yields an empty page.

Response headers

Speechify-Request-IdstringOptional
Unique identifier for this request, present on every response (2xx and non-2xx alike). If the caller sends a `Speechify-Request-Id` request header the server echoes it back (sanitized and length-capped) so one logical request can be traced end-to-end; otherwise the server generates a fresh value. Log it on every response and quote it in support requests - it is the stable handle that ties your observation to Speechify's server-side logs, and it matches the `request_id` field in the error envelope. The legacy alias `X-Request-ID` carries the same value and is still accepted on requests, until 2027-07-24. Prefer the un-prefixed name (RFC 6648).

Response

All active credentials in the workspace.
next_cursorstring or null

Opaque keyset cursor for the next page. Pass back as the cursor request parameter. null when the caller has reached the end of the list (has_more is also false in that case).

has_moreboolean
True when more rows exist beyond this page.
credentialslist of objects

Errors

400
Bad Request Error
401
Unauthorized Error
404
Not Found Error