List MCP API keys
Keys belonging to your agency. Narrowed to one client when a location is bound to the request. The key hash is never returned, and the raw key is unrecoverable — only key_prefix identifies a key after creation.
curl -X GET "https://mythic-analytics.gulp.workers.dev/builder/mcp/api-keys?location_id=loc_abc123" \
-H "Content-Type: application/json" \
-H "Authorization: Bearer YOUR_API_TOKEN"
import requests
import json
url = "https://mythic-analytics.gulp.workers.dev/builder/mcp/api-keys?location_id=loc_abc123"
headers = {
"Content-Type": "application/json",
"Authorization": "Bearer YOUR_API_TOKEN"
}
response = requests.get(url, headers=headers)
print(response.json())
const response = await fetch("https://mythic-analytics.gulp.workers.dev/builder/mcp/api-keys?location_id=loc_abc123", {
method: "GET",
headers: {
"Content-Type": "application/json",
"Authorization": "Bearer YOUR_API_TOKEN"
}
});
const data = await response.json();
console.log(data);
package main
import (
"fmt"
"net/http"
)
func main() {
req, err := http.NewRequest("GET", "https://mythic-analytics.gulp.workers.dev/builder/mcp/api-keys?location_id=loc_abc123", nil)
if err != nil {
panic(err)
}
req.Header.Set("Content-Type", "application/json")
req.Header.Set("Authorization", "Bearer YOUR_API_TOKEN")
client := &http.Client{}
resp, err := client.Do(req)
if err != nil {
panic(err)
}
defer resp.Body.Close()
fmt.Println("Response Status:", resp.Status)
}
require 'net/http'
require 'json'
uri = URI('https://mythic-analytics.gulp.workers.dev/builder/mcp/api-keys?location_id=loc_abc123')
http = Net::HTTP.new(uri.host, uri.port)
http.use_ssl = true
request = Net::HTTP::Get.new(uri)
request['Content-Type'] = 'application/json'
request['Authorization'] = 'Bearer YOUR_API_TOKEN'
response = http.request(request)
puts response.body
{
"data": [
{
"id": "123e4567-e89b-12d3-a456-426614174000",
"agency_id": "123e4567-e89b-12d3-a456-426614174000",
"location_id": "loc_abc123",
"name": "Reporting agent",
"key_prefix": "mcp_3f9a1c0b",
"scopes": [
"people:read",
"insights:read"
],
"is_active": true,
"rate_limit_per_minute": 60,
"last_used_at": "2024-12-25T10:00:00Z",
"created_at": "2024-12-25T10:00:00Z",
"updated_at": "2024-12-25T10:00:00Z"
}
]
}
{
"error": "Forbidden",
"message": "You don't have permission to access this resource",
"code": 403
}
GET
/builder/mcp/api-keys
GET
Base URLstring
Target server for requests. Edit to use your own host.
Bearer Token
Bearer Tokenstring
RequiredAn agency key (ak_). Location secret keys are rejected. Scoped keys (mcp_) are not accepted here (403 not_available_to_scoped_keys).
An agency key (
ak_). Location secret keys are rejected. Scoped keys (mcp_) are not accepted here (403 not_available_to_scoped_keys).query
location_idstring
Bind the request to one client. The X-Location-Id header does the same.
Request Preview
Response
Response will appear here after sending the request
Authentication
header
Authorizationstring
RequiredBearer token. An agency key (ak_). Location secret keys are rejected. Scoped keys (mcp_) are not accepted here (403 not_available_to_scoped_keys).
Query Parameters
location_idstring
Bind the request to one client. The X-Location-Id header does the same.
Example:
loc_abc123Responses
dataarray
Was this page helpful?