# List IAM credentials

> **GET** `https://api.us.nylas.com/v3/iam/principals/{principal_id}/credentials`

Source: https://developer.nylas.com/docs/reference/api/iam-credentials/list-iam-credentials/

Requires `iam.credentials.read` on an active principal bound to the authenticated organization. Authenticate with an active, unexpired IAM credential of type `api_key`. Application API keys (including legacy API keys) and provider OAuth tokens cannot authorize IAM management endpoints. Use an existing IAM credential with these permissions, or [create your first management credential in the Dashboard](/docs/v3/auth/nylas-iam/manage-principals-with-api/#create-a-management-credential-in-the-dashboard).

Never returns the credential secret.

Use next_cursor from the response as page_token on the next request. When next_cursor is absent, there are no more results.

**Authentication:** IAM_API_KEY

## Parameters

### Query parameters

| Name | Type | Required | Description |
|------|------|----------|-------------|
| `limit` | integer, min: 1, max: 200, default: `50` | No | Maximum results per page. |
| `page_token` | string, maxLength: 2048 | No | Opaque next_cursor from the previous response. |

### Path parameters

| Name | Type | Required | Description |
|------|------|----------|-------------|
| `principal_id` | string | Yes | ID of the principal in the authenticated organization. |

## Responses

### 200 - OK

- `request_id` (string) - Request ID for troubleshooting.
- `data` (array)
  - `id` (string) **(required)** - Opaque credential ID.
  - `principal_id` (string) **(required)** - ID of the principal that owns this credential.
  - `type` (string, one of: `api_key`) **(required)** - Supported IAM credential type.
  - `name` (string, minLength: 1, maxLength: 128) **(required)** - Descriptive workload name. Surrounding whitespace is removed.
  - `status` (string, one of: `active`, `disabled`) **(required)** - Whether the principal or credential can authenticate.
  - `expires_at` (integer, nullable, format: int64) **(required)** - Expiration as an integer number of seconds since the Unix epoch (January 1, 1970 at 00:00:00 UTC). For example, `1799193600` represents January 6, 2027 at 00:00:00 UTC. Newly created credentials always have an expiration.
  - `created_at` (integer, format: int64) **(required)** - Unix timestamp in seconds.
  - `updated_at` (integer, format: int64) **(required)** - Unix timestamp in seconds.
- `next_cursor` (string) - Opaque cursor. Absent on the final page. Pass as page_token.

### 400 - Invalid request or object quota exceeded

- `request_id` (string) - Request ID for troubleshooting.
- `error` (object)
  - `code` (string) - Error code.
  - `type` (string) **(required)** - Error category.
  - `message` (string) **(required)** - Description of the failure.
  - `details` (object) - Additional error context. Quota errors include resource_type, limit, and current.
    - `resource_type` (string)
    - `limit` (integer)
    - `current` (integer)

### 401 - Invalid, disabled, deleted, or expired authentication credential

- `request_id` (string) - Request ID for troubleshooting.
- `error` (object)
  - `code` (string) - Error code.
  - `type` (string) **(required)** - Error category.
  - `message` (string) **(required)** - Description of the failure.
  - `details` (object) - Additional error context. Quota errors include resource_type, limit, and current.
    - `resource_type` (string)
    - `limit` (integer)
    - `current` (integer)

### 403 - Missing management permission or organization binding

- `request_id` (string) - Request ID for troubleshooting.
- `error` (object)
  - `code` (string) - Error code.
  - `type` (string) **(required)** - Error category.
  - `message` (string) **(required)** - Description of the failure.
  - `details` (object) - Additional error context. Quota errors include resource_type, limit, and current.
    - `resource_type` (string)
    - `limit` (integer)
    - `current` (integer)

### 404 - Principal or credential not found in this organization

- `request_id` (string) - Request ID for troubleshooting.
- `error` (object)
  - `code` (string) - Error code.
  - `type` (string) **(required)** - Error category.
  - `message` (string) **(required)** - Description of the failure.
  - `details` (object) - Additional error context. Quota errors include resource_type, limit, and current.
    - `resource_type` (string)
    - `limit` (integer)
    - `current` (integer)

### 409 - Conflicting principal or credential state

- `request_id` (string) - Request ID for troubleshooting.
- `error` (object)
  - `code` (string) - Error code.
  - `type` (string) **(required)** - Error category.
  - `message` (string) **(required)** - Description of the failure.
  - `details` (object) - Additional error context. Quota errors include resource_type, limit, and current.
    - `resource_type` (string)
    - `limit` (integer)
    - `current` (integer)

### 429 - Too many requests

- `request_id` (string) - Request ID for troubleshooting.
- `error` (object)
  - `code` (string) - Error code.
  - `type` (string) **(required)** - Error category.
  - `message` (string) **(required)** - Description of the failure.
  - `details` (object) - Additional error context. Quota errors include resource_type, limit, and current.
    - `resource_type` (string)
    - `limit` (integer)
    - `current` (integer)

## Code samples

### cURL

```bash
curl --request GET \
  --url "https://api.us.nylas.com/v3/iam/principals/${NYLAS_PRINCIPAL_ID}/credentials" \
  --header "Authorization: Bearer $NYLAS_IAM_ADMIN_KEY"

```
