Skip to main content
GET
List every token under a gateway
Lists the phantom tokens issued under this gateway: the tokens of every agent it owns, and any token minted without an agent at all. That second category is why this endpoint exists. A token minted through the OIDC exchange with an RFC 8707 resource naming an MCP server has agent_id: null, so it is invisible to GET /v1/ai-gateway/agents/{agentId}/tokens — the only other place tokens are listed. Without this endpoint an agentless token could be neither inventoried nor found. Never returns plaintext; prefix is the first 12 characters, safe to display. Requires the read capability on ai_gateway. See the control-plane overview for authentication, the {data, meta} envelope, pagination and error types.

Authorizations

Authorization
string
header
required

OAuth 2.1 authentication — recommended for new integrations. Access tokens (kc_ prefix) are minted at the root-host token endpoint https://api.knoxcall.com/oauth/token and passed as Authorization: Bearer <access_token>. Public clients must use PKCE with the authorization_code grant; confidential clients may use client_credentials. The first-party SDKs and the knoxcall login CLI handle token minting, caching, refresh, and DPoP for you.

Path Parameters

gatewayId
string<uuid>
required

The AI gateway UUID.

Query Parameters

page
integer
default:1

Page number for pagination. Clamped server-side so the derived offset never exceeds 100,000 rows -- the effective maximum is floor(100000 / per_page) + 1, i.e. 1,001 at per_page=100. A larger value returns that last page, and meta.page reports it.

Required range: x >= 1
per_page
integer
default:20

Number of items per page (max 100).

Required range: 1 <= x <= 100

Response

A paginated list of tokens. agent_id is null for a gateway-level token.

data
object[]
meta
object

Pagination metadata for list endpoints.