Skip to main content
GET
List an agent's capability tokens
Returns the agent’s tokens, newest first, paginated. KnoxCall stores only a hash, so no response ever contains a token’s plaintextprefix is the first 12 characters, enough to identify a token in a list and safe to store. This endpoint lists tokens belonging to this agent. A token minted without an agent — the OIDC exchange produces these — is invisible here; find those with List gateway tokens. expires_at can be null on a token minted before 2026-08-30, when an omitted expiry meant “never”. Those are worth auditing: nothing will retire them for you. Requires the read capability on ai_gateway. See the control-plane overview for authentication, the {data, meta} envelope, pagination and error types.

Authorizations

Authorization
string
header
required

OAuth 2.1 authentication — recommended for new integrations. Access tokens (kc_ prefix) are minted at the root-host token endpoint https://api.knoxcall.com/oauth/token and passed as Authorization: Bearer <access_token>. Public clients must use PKCE with the authorization_code grant; confidential clients may use client_credentials. The first-party SDKs and the knoxcall login CLI handle token minting, caching, refresh, and DPoP for you.

Path Parameters

agentId
string<uuid>
required

The AI agent UUID.

Query Parameters

page
integer
default:1

Page number for pagination. Clamped server-side so the derived offset never exceeds 100,000 rows -- the effective maximum is floor(100000 / per_page) + 1, i.e. 1,001 at per_page=100. A larger value returns that last page, and meta.page reports it.

Required range: x >= 1
per_page
integer
default:20

Number of items per page (max 100).

Required range: 1 <= x <= 100

Response

A paginated list of capability tokens.

data
object[]
meta
object

Pagination metadata for list endpoints.