List API keys
List a sub-account's API keys, newest first. Keys are masked — the full key is never returned here.
GET
https://api.centerfy.ai/webhooks/inbound/agency/sub-accounts/:id/api-keys Headers
| Header | Required | Value | Description |
|---|---|---|---|
x-api-key | Yes | your agency API key (cfy_…) | Agency (organization-wide) API key, created in the agency workspace under Settings → API Keys (“Agency API Keys”; the tab only appears on White Label or SaaS Mode plans). Or send Authorization: Bearer <key>; x-api-key wins if both are present. Keys must start with cfy_. A sub-account key is rejected with 401. |
Path parameters
| Name | Type | Required | Description |
|---|---|---|---|
id | string (uuid) | Yes | The sub-account id. Must belong to the key’s agency and not be deleted. |
Example
curl -X GET "https://api.centerfy.ai/webhooks/inbound/agency/sub-accounts/{id}/api-keys" \
-H "x-api-key: $CENTERFY_AGENCY_API_KEY" import { CenterfyAgencyClient } from "@centerfy/sdk";
const agency = new CenterfyAgencyClient({ apiKey: process.env.CENTERFY_AGENCY_API_KEY! });
const result = await agency.subAccountApiKeys.list("<subAccountId>");
console.log(result); centerfy --agency subAccountApiKeys list <subAccountId> MCP tool: centerfy_agency_sub_account_api_keys_list (see MCP server)
Response
{
"status": "success",
"api_keys": [
{
"id": "b07f9284-e1a3-44c5-b061-7c8d9eafb007",
"name": "Zapier",
"key_prefix": "cfy_Q3vX",
"last_four": "k9Tz",
"created_at": "2026-10-02T11:00:00.000Z",
"last_used_at": "2026-10-05T18:42:00.000Z"
}
]
}Errors
404— when the sub-account id is not a uuid, does not exist, is deleted, or belongs to another agency.401— when the key is missing, not cfy_-prefixed or unknown (including sub-account keys); 403 when the agency is not on a White Label or SaaS Mode plan; 429 above 50 requests per minute per agency (Retry-After header set); 500 ‘database error’ on an internal failure.
Notes
key_prefix is the first 8 characters of the key and last_four the last 4. Not paginated.