# Client API: Object Storage: Keys

> The 3 Client API operations for keys.

Source: https://www.coritan.com/docs/api/reference/client/object-storage/object-storage-keys/

Part of [Object Storage](/docs/api/reference/client/object-storage/).

## Operations

| Method | Path | Summary |
| --- | --- | --- |
| GET | [`/api/v1/client/object-storage/{service_id}/keys`](#op-get-api-v1-client-object-storage-service-id-keys) | List keys |
| POST | [`/api/v1/client/object-storage/{service_id}/keys`](#op-post-api-v1-client-object-storage-service-id-keys) | Issue a key |
| DELETE | [`/api/v1/client/object-storage/{service_id}/keys/{key_id}`](#op-delete-api-v1-client-object-storage-service-id-keys-key-id) | Revoke key |

### List keys {#op-get-api-v1-client-object-storage-service-id-keys}

`GET /api/v1/client/object-storage/{service_id}/keys`

Authentication: an access token, sent as `Authorization: Bearer <token>`.

#### Parameters

| Name | In | Type | Required |
| --- | --- | --- | --- |
| `service_id` | path | integer | yes |

#### Responses

| Status | Meaning |
| --- | --- |
| `200` | Success. |
| `422` | The request is not valid. `detail` lists each problem. |

Fields of a `200` response:

| Field | Type |
| --- | --- |
| `items` | array of KeyOut |
| `items[].id` | integer |
| `items[].access_key_id` | string |
| `items[].label` | string |
| `items[].bucket_id` | integer or null |
| `items[].bucket_name` | string or null |
| `items[].scope` | string, one of `bucket`, `all` |
| `items[].mode` | string, one of `read`, `read_write` |
| `items[].actions` | array of string |
| `items[].is_active` | boolean |
| `items[].last_used_at` | string or null |
| `items[].created_at` | string or null |
| `total` | integer |

### Issue a key {#op-post-api-v1-client-object-storage-service-id-keys}

`POST /api/v1/client/object-storage/{service_id}/keys`

Issue a key. The secret is in this response and nowhere else after.

Authentication: an access token, sent as `Authorization: Bearer <token>`.

#### Parameters

| Name | In | Type | Required |
| --- | --- | --- | --- |
| `service_id` | path | integer | yes |

#### Request body

`application/json` (required)

| Field | Type | Required |
| --- | --- | --- |
| `label` | string | yes |
| `bucket_id` | integer or null | no |
| `mode` | string, one of `read`, `read_write` | no |

#### Responses

| Status | Meaning |
| --- | --- |
| `201` | Success. |
| `422` | The request is not valid. `detail` lists each problem. |

Fields of a `201` response:

| Field | Type |
| --- | --- |
| `id` | integer |
| `access_key_id` | string |
| `label` | string |
| `bucket_id` | integer or null |
| `bucket_name` | string or null |
| `scope` | string, one of `bucket`, `all` |
| `mode` | string, one of `read`, `read_write` |
| `actions` | array of string |
| `is_active` | boolean |
| `last_used_at` | string or null |
| `created_at` | string or null |
| `secret_key` | string |
| `endpoint` | string or null |
| `region` | string or null |
| `activation_note` | string |

### Revoke key {#op-delete-api-v1-client-object-storage-service-id-keys-key-id}

`DELETE /api/v1/client/object-storage/{service_id}/keys/{key_id}`

Authentication: an access token, sent as `Authorization: Bearer <token>`.

#### Parameters

| Name | In | Type | Required |
| --- | --- | --- | --- |
| `service_id` | path | integer | yes |
| `key_id` | path | integer | yes |

#### Responses

| Status | Meaning |
| --- | --- |
| `200` | Success. |
| `422` | The request is not valid. `detail` lists each problem. |

Fields of a `200` response:

| Field | Type |
| --- | --- |
| `ok` | boolean |
| `access_key_id` | string |
