> For clean Markdown of any page, append .md to the page URL. > For a complete documentation index, see https://docs.withpersona.com/2025-10-27/api-reference/client-tokens/list-all-client-tokens/llms.txt. > For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://docs.withpersona.com/_mcp/server. # List all Client Tokens GET https://api.withpersona.com/api/v1/client-tokens Returns a list of client tokens for your organization. Results are returned in reverse chronological order, with the most recently created objects first. Reference: https://docs.withpersona.com/api-reference/client-tokens/list-all-client-tokens ## Authentication - `Authorization` header (bearer token, required) — Bearer authentication of the form `Bearer `, where token is your auth token. ## Request ### Query parameters - `page` (ClientTokensGetParametersPage, optional) - `fields` (map from string to string, optional) — Comma-separated list(s) of attributes to include in the response. This can be used to customize which attributes will be serialized in the response. See [Serialization](https://docs.withpersona.com/serialization#sparse-fieldsets) for more details. ### Headers - `Key-Inflection` (enum, optional) — Determines casing for the API response. - Allowed values: `camel`, `kebab`, `snake` - `Idempotency-Key` (string, optional) — Ensures the request is idempotent. - `Persona-Version` (enum, optional) — Server API version. More info on versioning can be found [here](https://docs.withpersona.com/versioning). - Allowed values: `2025-12-08`, `2025-10-27`, `2023-01-05`, `2022-09-01`, `2021-08-18`, `2021-07-05`, `2021-02-21`, `2020-05-18` ## Response ### 200 This endpoint returns a collection of Client Tokens. - `data` (list of client-token-list-item, required) - `links` (ClientTokensGetResponsesContentApplicationJsonSchemaLinks, required) ## Errors ### 400 Bad Request Error The request was unacceptable, often due to invalid parameters. - `errors` (list of ClientTokensGetResponsesContentApplicationJsonSchemaErrorsItems, optional) ### 401 Unauthorized Error An invalid API key was provided. - `errors` (list of ClientTokensGetResponsesContentApplicationJsonSchemaErrorsItems, optional) ### 403 Forbidden Error The given API key doesn’t have permissions to perform the request or a quota has been exceeded. - `errors` (list of ClientTokensGetResponsesContentApplicationJsonSchemaErrorsItems, optional) ### 429 Too Many Requests Error Your organization’s rate limit has been exceeded. We recommend an exponential backoff on requests. - `errors` (list of ClientTokensGetResponsesContentApplicationJsonSchemaErrorsItems, optional) ## Types ### ClientTokensGetParametersPage - `after` (string, optional) — Object ID for pagination cursor - `before` (string, optional) — Object ID for pagination cursor - `size` (double, optional) — Limit on the number of objects returned ### client-token-list-item A Client Token resource in a collection response - `type` ("client-token", optional) - `id` (string, optional) - `attributes` (ClientTokenListItemAttributes, optional) ### ClientTokensGetResponsesContentApplicationJsonSchemaLinks - `next` (string, required, nullable) - `prev` (string, required, nullable) ### ClientTokensGetResponsesContentApplicationJsonSchemaErrorsItems - `title` (string, optional) - `details` (string, optional) ### ClientTokenListItemAttributes - `name` (string, optional) — The name of the client token - `api-version` (date, optional) — The API version used by this client token - `api-key-inflection` (string, optional) — The key inflection used by this client token - `permissions` (list of string, optional) — List of permissions granted to this client token - `domain-allowlist` (list of string, optional) — List of domains allowed to use this client token - `allowed-resources` (list of string, optional) — List of resources that this client token is authorized to manipulate - `version-expires-in-seconds` (integer, optional, nullable) — How long newly minted client token versions live before expiring, in seconds (max 10 years). Null means new versions do not expire by default. - `disabled-at` (datetime, optional, nullable) — When this client token was disabled - `disabled` (boolean, optional) — Whether this client token is disabled - `created-at` (datetime, optional) — When this client token was created ## Examples **Response** ```json { "data": [ { "type": "client-token", "id": "ctk_ABC123", "attributes": { "name": "Default Client Token", "api-version": "2023-01-05", "api-key-inflection": "kebab", "permissions": [ "sentinel.collect", "txn.write" ], "domain-allowlist": [ "*.example.com", "api.example.com" ], "allowed-resources": [ "txntp_ABC123", "txntp_DEF456" ], "version-expires-in-seconds": 31536000, "disabled-at": null, "disabled": false, "created-at": "2023-08-17T23:18:13.000Z" } }, { "type": "client-token", "id": "ctk_DEF456", "attributes": { "name": "Secondary Client Token", "api-version": "2023-01-05", "api-key-inflection": "kebab", "permissions": [ "sentinel.collect" ], "domain-allowlist": [ "api.example.com" ], "allowed-resources": [ "txntp_GHI789" ], "version-expires-in-seconds": null, "disabled-at": "2023-08-18T23:20:00.000Z", "disabled": true, "created-at": "2023-08-17T23:20:00.000Z" } } ], "links": { "next": "/api/v1/client-tokens?page%5Bafter%5D=ctk_DEF456", "prev": null } } ``` **SDK Code** ```python Success import requests url = "https://api.withpersona.com/api/v1/client-tokens" headers = {"Authorization": "Bearer "} response = requests.get(url, headers=headers) print(response.json()) ``` ```javascript Success const url = 'https://api.withpersona.com/api/v1/client-tokens'; const options = {method: 'GET', headers: {Authorization: 'Bearer '}}; try { const response = await fetch(url, options); const data = await response.json(); console.log(data); } catch (error) { console.error(error); } ``` ```go Success package main import ( "fmt" "net/http" "io" ) func main() { url := "https://api.withpersona.com/api/v1/client-tokens" req, _ := http.NewRequest("GET", url, nil) req.Header.Add("Authorization", "Bearer ") res, _ := http.DefaultClient.Do(req) defer res.Body.Close() body, _ := io.ReadAll(res.Body) fmt.Println(res) fmt.Println(string(body)) } ``` ```ruby Success require 'uri' require 'net/http' url = URI("https://api.withpersona.com/api/v1/client-tokens") http = Net::HTTP.new(url.host, url.port) http.use_ssl = true request = Net::HTTP::Get.new(url) request["Authorization"] = 'Bearer ' response = http.request(request) puts response.read_body ``` ```java Success import com.mashape.unirest.http.HttpResponse; import com.mashape.unirest.http.Unirest; HttpResponse response = Unirest.get("https://api.withpersona.com/api/v1/client-tokens") .header("Authorization", "Bearer ") .asString(); ``` ```php Success request('GET', 'https://api.withpersona.com/api/v1/client-tokens', [ 'headers' => [ 'Authorization' => 'Bearer ', ], ]); echo $response->getBody(); ``` ```csharp Success using RestSharp; var client = new RestClient("https://api.withpersona.com/api/v1/client-tokens"); var request = new RestRequest(Method.GET); request.AddHeader("Authorization", "Bearer "); IRestResponse response = client.Execute(request); ``` ```swift Success import Foundation let headers = ["Authorization": "Bearer "] let request = NSMutableURLRequest(url: NSURL(string: "https://api.withpersona.com/api/v1/client-tokens")! as URL, cachePolicy: .useProtocolCachePolicy, timeoutInterval: 10.0) request.httpMethod = "GET" request.allHTTPHeaderFields = headers let session = URLSession.shared let dataTask = session.dataTask(with: request as URLRequest, completionHandler: { (data, response, error) -> Void in if (error != nil) { print(error as Any) } else { let httpResponse = response as? HTTPURLResponse print(httpResponse) } }) dataTask.resume() ```