---
id: pat-list
title: List personal access tokens
description: >-
  Lists your own personal access tokens. You only ever see the tokens you
  created.
sidebar_label: List personal access tokens
hide_title: true
hide_table_of_contents: true
api: >-
  eJztWe9u28gRf5XBfmkS0ArlP3EgIAXUJNem6OWMxEGutQ1pRI7IPZO7zO7Sss7Qt37v67Sv0xfoKxSzS+qPJdk6x5cDivqDLJG7M7/5P7tzI1KyiZGVk1qJnviLtM7CVNcG9ERBRcZqhQVgkpC14PQlKduBv+oatCqmQFdkwBKBy6l5y7shMYSO0s65Ole/h3///V//+ec/4Nmz99pR79kzONlIF9AQlKgwoxQm0uULIIXOpAJL1kqtOtAHQ19qsg6wdjkpJxNmFzahgv7JO7ikaQS4WQSQKinqlNIIpAVDP1Gy2A7Dw/hg2DlXIhIOMyt6Z2IzYHERCV2RQdbeu1T0RIWuV0jrRCQsJbWRbip6ZzdiRGjI9GuXi97ZxewiEhUaLMmRsX6BZO1/qclMRSQUliR6whKaJBfRLRt9jy7JyQIGFL+zwOsj0MZb4ZKm/PUKi5pAj0Er/086CyxNB16jpT2pLCkrnbyiCOoKnIb9oyNIcjSYMKoOi5DkVKLo3Qg3rTwiZ6TKxCwSrH9pKBW9MRaWIkHXWFYFLyqTSsyiLSI5dLVdE+kHxmig1IYgLCEbgSVWEhtmNIVElyXaHgwxYdDDCIZ0XUnGM7BaqyE88b/JejNK5ZWh6NrBMaQ4tU8jQJU2uyhtDPwwEQOGaAXAVpkbWAN0PYMqozXpT4P3uxwdhMUwIjchUuAmGlJ0rA3vstbbCy0Mx0aXkdNDDgZe4aXWtWO3kCVBoq/IWK+ESa4Lgk+nr1kPD7frfrz/Yq8b78XdKHzd3zvo7iJ15naSWSv2ARw7YkeW1ov1GHB3wVj8EowjGrOnPhrIOxVptXHr0HIOmJQMhzbb2JCtC2c70IBWPjPXllJgAlCgdTDJSfmfUmUcU0N+OuBFA3TDu6SIBKm65EzIqHpokwZgj3GJSCxT4tcDVReFHfDj2295x/Lri7tVNGe4TUGFLOW6hr7Ha1nWJai6HDVqCpqpyECFGUXAIQRdTn3dOO7AGxoj65AfHMQbtSGVo4zM3UY9iLch1eOxpc3GXIPpNNhLWa3C+gpUMRcdQ7bSypLl3ftxzP82OFZb0mCCFmztS964Lph5opUj5XgjVlXBdVdq9fwny7tv1rHpEddWsYzsTFSYBadqvJbraGWYrZMBW7PiHjpzfQYXWKPSvF/X1CYLWIfGteEU+MNEqlRPWO4lPbbs7id7rw+uUGa/EU47LHZEvO4znKlKbg+8EGNZtJV8zuRoNpst9L7gg8Yge6p0VNr79C7T1qcjERqitlWKRGZQOetZtsmV3Sb0g+FHXaXtjzWTyXQH4T8p+aUmePcGxk3T4xWwImh3/+Bw1kbeejpb1+b8yRX5hgoyecUVWG9hIAqdYLEXNlkOvhLtJYtVycElTXfj6ulGELau0u/3+/1r/js5ta+YfqPqO5LzXPkWSxqg5ZxrWMmrjD/n5HJa0hyMdVHoSdP5Nz3uk+EyleFTrny5LlLre0nuygM7eDIMX4ZPVwVYATFrm+k1l7ulFMwsoLU6kYuWfmEBeFtWbhoqmXSQowWllQ+knVyXDRMJ3xyvO99uVsOMe+xVUR1hySIGwjvR8EtXqVQFurE2pZj5KG2seZ/GPnPUL0yZoIJUd+A7bqZg1Yatu7mcLPnj1vyE1diy6Zu1yVDJn0MVaMiXuiTlFg2HP4Bx+xn4+uSjNBRaZWRgos2ljWBECdaW2FZN481u5LkyIj5+SdW002Co0sY1FvXt+VabPiBrcLi9e9Pi9/KupsYXxy85Yxi1W+i+//B+qfvStUloQRl8dSSu2qs2Xtbsq24Pk0TXyr3a99VbFzR4gCy8L7C9lUOO4/ige3x89KIlbos62006XnkvfZHSFRVsiZCfeP8OIZ4ThLU+0dolrbEiiyuvtggqQ5Y9rg127kaaQhJ6t2HDccg+NZQqJyOdHW5KBotufA7+bLmD6RnC1COtCj1lR+8FVuIiBGN7j7BEc6R1QajW5OsXE5xaGDpT09CXqC3XECu65NWzSOiJIvMQJ/DhNMn1XEWby9bhfmMplfmc8GBWi4yDieOU3eOwXue13Ptvcj1OePxGcFOwx2dXbi7qosBRq5aNaD7+sPfyRdz151reZR2WFSP07rJAx17jTz90neR8/k6DSdR2UyzOji9Pu/u9OO7FcSeO478F/5n3NbtK8xXordOV9clUqmwN5PFe3N2LX5x6hOsg0x2cdb0X4Jra7F9h6E8Us5Ve7hsoYCnot9poTfylDvMbQfQe1rDdFSe3RNKFyo/uQ3M2E7NbL074LMJ0l1fMInH444/r57fXheSUScZoA/PjHqQ1gwWprrCQKUhV1c7fuElr+aCzuI18tENeuMd7rVPWrscjIlGStZhtaL2WVt+fjf50enrS3BNColOuv02tYFnYMLaiRI5lAsmyPp5QJ+tEcBjH/NHljwP+OFxtXA9jPoklq1i2lMo+lJjkUtEeFxBOWQ0vj8v3RHw1nWkjf24qnSXDdzNjlEVtbnWAI0wHTWflw9irbQcQIyNpHEFel6gWSJZWtak7gGNyrTbOxR8whQ+B6bngB58UX6t7yOm5uNXVL632h57GoveDTFPJX7GAlBzKwgKO+MJyDmuVz+miyfQRVmLBgRsaSPZQlIrSuUsve/BsFiLkaFOEfAzqvx0hUqXez1XGpUFaW/vbPgbH0wQrU/ofCw27rIjGGY44NI7iff44WDX80W8XFSysUVgMwqJBUNk3i493DXtoXOctrwmRwk9kQvBJ4RVK37KsBczG7b9q6PQV1IquqzDVCiLpJKkNl3Q4KQgtgTNTwAylggIdmTZqPC6Xa55mZf5yrUKeWonnFYaxFgsRhla1KURP5M5Vtvf8OVayw31be4rtJLoUfOvYTsI+cnAEn16eh82lZ0Lt/aZPhn6RiJov37Vl+8+fT33xlGqseTvjCYrqduJOLBbVs9+kMR+krPJKW1eiD9XmTpYnnlvmnLftcLOI/v8PSm8PSoMJHV2751WB0mvb+8dN40B87esv/HJtHf+8uRmhpU+mmM34cbgrZ7dKpeVAWlxib7XCtxuFbpTP3xctxrTN5Y/wk4rdhfjthp93CdUOah8o1Defad4hy4YB7ONJtXVquRugMBt9bDibBpS74Sm+Cs+vNJW8y0/DdPSBgB9jSHgHuHYy+RXq/AVzwTuAzAdlCyQX/MPIcMlyxjPYnDAl4zNw2NVPEqqWd611vExl3i388e0pz4NWa/qtGu6pt5eDarpE++YmrPCeMpuJFroXW8z4Fu6/fqydZw==
sidebar_class_name: get api-method
info_path: docs/api/authorization
custom_edit_url: null
canonical: 'https://docs.nullplatform.com/docs/api/pat-list'
---
<Heading
  as={"h1"}
  className={"openapi__heading"}
  children={"List personal access tokens"}
>
</Heading>

<MethodEndpoint
  method={"get"}
  path={"/pat"}
  context={"endpoint"}
>

</MethodEndpoint>

Lists your own personal access tokens. You only ever see the tokens you created.

> ℹ️ **Note:** Personal access tokens are managed with your own login session. A request authenticated with an API key, a personal access token included, is rejected with a `403`.

<Heading
  id={"request"}
  as={"h2"}
  className={"openapi-tabs__heading"}
  children={"Request"}
>
</Heading>

<ParamsDetails
  parameters={[{"in":"query","name":"search","description":"Matches a token's name, or the key or value of one of its tags. Case-insensitive, up to 255 characters.","schema":{"type":"string"},"required":false,"example":"mcp"},{"in":"query","name":"status","description":"One or more statuses, separated by commas: `active`, `expiring_soon` (expires within the next 7 days), and `expired`.\n","schema":{"type":"string"},"required":false,"example":"active,expiring_soon"},{"in":"query","name":"expires_at:range","description":"Tokens that expire between two dates, inclusive, as `from,to`. A date without a time covers the whole UTC day.","schema":{"type":"string"},"required":false,"example":"2026-10-01,2026-12-31"},{"in":"query","name":"expires_at:gte","description":"Tokens that expire on or after this date.","schema":{"type":"string"},"required":false,"example":"2026-10-01"},{"in":"query","name":"expires_at:lte","description":"Tokens that expire on or before this date.","schema":{"type":"string"},"required":false,"example":"2026-12-31"},{"in":"query","name":"sort","description":"The order of the results. Tokens never used sort last when sorting by `last_used_at`.","schema":{"type":"string","enum":["name:asc","name:desc","last_used_at:asc_nulls_last","last_used_at:desc_nulls_last"]},"required":false,"example":"name:asc"},{"in":"query","name":"limit","description":"Maximum number of tokens per page, from 1 to 100. Defaults to 30.","schema":{"type":"integer"},"required":false,"example":30},{"in":"query","name":"offset","description":"The number of tokens to skip. Defaults to 0.","schema":{"type":"integer"},"required":false,"example":0}]}
>

</ParamsDetails>

<RequestSchema
  title={"Body"}
  body={undefined}
>

</RequestSchema>

<StatusCodes
  id={undefined}
  label={undefined}
  responses={{"200":{"description":"The operation was successful.","content":{"application/json":{"schema":{"type":"object","required":["paging","results"],"properties":{"paging":{"type":"object","required":["offset","limit"],"properties":{"offset":{"type":"integer","description":"The start of the paging window.","example":0},"limit":{"type":"integer","description":"Maximum number of tokens per page.","example":30},"total":{"type":"integer","description":"The number of tokens that match the filters.","example":5}}},"results":{"type":"array","items":{"type":"object","required":["id","name","access","tags","grants","expires_at","created_at","updated_at"],"properties":{"id":{"type":"integer","description":"Unique ID for the token.","example":1234},"name":{"type":"string","description":"The descriptive name given to the token.","example":"local-scripts"},"masked_api_key":{"type":"string","description":"The token, masked.","example":"AAAAxxxxxPTs="},"access":{"type":"string","enum":["grants","same_as_user"],"description":"Whether the token follows your access (`same_as_user`) or holds its own grants (`grants`).","example":"same_as_user"},"tags":{"type":"array","description":"Tags associated with the token. Empty when it has none.","items":{"type":"object","required":["key","value"],"properties":{"key":{"type":"string","description":"Tag key.","example":"team"},"value":{"type":"string","description":"Tag value.","example":"platform"}}}},"grants":{"type":"array","description":"What the token can do. For a `same_as_user` token, these are your own grants in the organization at the moment of the request. A token that no longer works, because it expired or your user is inactive, reports none.\n","items":{"type":"object","properties":{"id":{"type":"integer","description":"The ID of the grant.","example":5678},"nrn":{"type":"string","description":"The NRN of the resource the grant applies to.","example":"organization=1:account=2"},"role_id":{"type":"integer","description":"The ID of the role granted.","example":700317756},"role_slug":{"type":"string","description":"The slug of the role granted.","example":"developer"},"actions":{"type":"array","description":"The action names the grant resolves to, present when it was created from `actions` or `inherits`.","items":{"type":"string"},"example":["application:read","deployment:create"]}}}},"personal":{"type":"boolean","description":"Always `true` for a personal access token.","example":true},"owner_id":{"type":"integer","description":"The ID of the user who created the token.","example":42},"acting_user_id":{"type":"integer","description":"The ID of the user the token acts as: you.","example":42},"last_used_at":{"type":"string","format":"date-time","nullable":true,"description":"The ISO-8601 UTC timestamp of when the token was last exchanged for an access token.","example":"2026-10-08T12:00:00.000Z"},"expires_at":{"type":"string","format":"date-time","description":"The ISO-8601 UTC timestamp of when the token stops working.","example":"2027-01-06T00:00:00.000Z"},"expired":{"type":"boolean","description":"Whether the token has expired.","example":false},"created_at":{"type":"string","format":"date-time","description":"The ISO-8601 UTC timestamp of when the token was created.","example":"2026-10-08T00:00:00.000Z"},"updated_at":{"type":"string","format":"date-time","description":"The ISO-8601 UTC timestamp of when the token was last updated.","example":"2026-10-08T00:00:00.000Z"}},"title":"patResponse"}}},"title":"patPaginatedResponse"}}}},"4XX":{"description":"Client error responses due to invalid input or missing parameters.","content":{"application/json":{"schema":{"type":"object","required":["statusCode","error","message"],"properties":{"statusCode":{"type":"integer","description":"HTTP status code representing the specific client error (e.g., 400, 401, 403, 404).","example":400},"code":{"type":"string","description":"A machine-readable error code that categorizes the server failure.","example":"bad_request"},"error":{"type":"string","description":"A brief, human-readable description of the error type (e.g., \"Bad Request\", \"Unauthorized\").","example":"Bad Request"},"message":{"type":"string","description":"Additional details about the error.","example":"The request was malformed or contained invalid parameters."}}}}}},"5XX":{"description":"Server error responses indicating an issue on the API side.","content":{"application/json":{"schema":{"type":"object","required":["statusCode","error","message"],"properties":{"statusCode":{"type":"integer","description":"HTTP status code representing the specific server error (e.g., 500, 502, 503).","example":500},"code":{"type":"string","description":"A machine-readable error code that categorizes the server failure.","example":"internal_server_error"},"error":{"type":"string","description":"A brief, human-readable description of the error type (e.g., \"Internal Server Error\", \"Service Unavailable\").","example":"Internal Server Error"},"message":{"type":"string","description":"Additional details about the error.","example":"An unexpected error occurred. Please try again later."}}}}}}}}
>

</StatusCodes>

