## List all API keys

Retrieve a list of all API keys associated with your merchant account. This endpoint returns an array of
key objects containing details about each key, including:

- Key name and ID
- Creation time
- Current status (enabled or disabled)

See `generate-key` or `find-key` for the complete list of response attributes.

Common use cases for this endpoint:

- Auditing active API keys
- Identifying unused or outdated keys that should be rotated

Note: For security reasons, this endpoint only returns metadata about your keys - it never returns the
actual key values. Make sure to securely store your key values when they are first generated, as they
cannot be retrieved later.

## Endpoint signature

```http
POST https://api.reservepay.com/merchants/list-keys HTTP/1.1
Content-Type: application/json
Accept: application/json
Authorization: Bearer <token>

{}
```

Returns: array

## Response attributes

### `key_id` (string)

**Always present**. The ID of the key. This can be used as an argument to `find-key`.

### `key` (string)

**Always present**. The secret key. It will only be shown once as a response to `generate-key`. Subsequent calls using `find-key` will display `MASKED` instead.

### `name` (string)

**Always present**. The name of the key that you provided when creating it.

### `revoked` (boolean)

**Always present**. Whether the key is revoked. If it is revoked, it cannot be used to make API requests.

### `created_at` (number)

**Always present**. The timestamp of the key creation as a Unix timestamp.

### `permissions` (array)

**Always present**. Permission tokens granted to this key.

Possible values:

- `manage_contacts`
- `manage_developer_settings`
- `manage_disputes`
- `manage_payouts`
- `manage_settings`
- `manage_team`
- `manage_terminals`
- `manage_transactions`
- `view_contacts`
- `view_disputes`
- `view_payouts`
- `view_settings`
- `view_statements`
- `view_team`
- `view_transactions`

## Errors common to all endpoints

### `UNHANDLED_ERROR`

This error occurs when the server encounters an unexpected internal error that
it cannot handle gracefully. This typically happens due to bugs, infrastructure
issues, or edge cases that weren't anticipated during development.

### `INVALID_ARGUMENTS`

This error occurs when the request contains invalid or missing parameters.
Common cases include missing required fields, or values that don't match the
expected format or type.

### `BAD_VERSION`

This error occurs when making requests to an API version that does not exist.
This commonly happens when using an outdated SDK or when the API version
specified in the request URL is incorrect.
