> ## Documentation Index
> Fetch the complete documentation index at: https://docs.hookmyapp.com/llms.txt
> Use this file to discover all available pages before exploring further.

# List agent credentials



## OpenAPI

````yaml api-reference/openapi.yaml GET /agent/credentials
openapi: 3.1.0
info:
  title: HookMyApp API
  version: 1.0.0
  description: >
    The HookMyApp REST API. Everything the dashboard and the CLI can do, your

    code and your AI agents can do too.


    ## Authentication


    Two kinds of Bearer credentials exist. Do not mix them up:


    - **API key (`hmok_...`)** authenticates *you* (or your agent) to
      `https://api.hookmyapp.com`.
      Create one in the dashboard under **Org → API keys → Create API Key**
      (full org access, optional expiration date, reveal or
      revoke it any time from that page), or without a
      browser via the [agent auth flow](#tag/agent-auth) described in
      [`GET /auth.md`](https://api.hookmyapp.com/auth.md). That flow can mint a
      scope-limited key. Send it as `Authorization: Bearer hmok_...`, or on
      `/mcp` as `X-API-Key: hmok_...`. Use it for org, workspace, customer,
      channel and webhook management.
    - **Channel token (`hmat_...`)** sends messages from one connected channel.
      Mint it with `GET /meta/channels/{id}/token`. It is not valid on
      `https://api.hookmyapp.com`.

    Browser sessions from the dashboard use the same endpoints with a session

    cookie or WorkOS JWT instead of `hmok_`.


    ## IDs


    Every ID on the wire is a typed public ID, never an internal UUID:

    `ws_` workspace/customer, `ch_` channel, `org_` organization,

    `cred_` connection credential, `ac_` agent credential.


    ## Workspace context


    Workspace-scoped routes (channels, webhook config, and deliveries) resolve
    the

    workspace from the `X-Workspace-Id: ws_XXXXXXXX` header.


    ## Errors


    Errors return a stable machine-readable `code` plus a human `message`.

    Agent tokens that exceed their granted scopes get `403
    AGENT_SCOPE_INSUFFICIENT`.


    ## Webhook signatures


    Deliveries to your webhook are signed with `X-HookMyApp-Signature-256`,

    an HMAC-SHA256 of the raw body keyed on the channel `WEBHOOK_HMAC_SECRET`.

    The Verify Token is a separate value used only for the GET ownership probe.
servers:
  - url: https://api.hookmyapp.com
    description: Production
security:
  - bearerAuth: []
tags:
  - name: Agent auth
    description: Register an agent credential (`hmok_`) with email OTP, no browser needed
  - name: Organizations
    description: Your organization and its summary
  - name: Customers
    description: Customer workspaces you run messaging for (SaaS Mode)
  - name: Onboarding links
    description: Links your customers open to connect their own channels
  - name: Workspaces
    description: Team workspaces
  - name: Channels
    description: Connected WhatsApp and Instagram channels, and their channel tokens
  - name: Webhook config
    description: Where inbound messages are delivered for a channel
  - name: Deliveries
    description: Inspect inbound delivery logs and app responses
paths:
  /agent/credentials:
    get:
      tags:
        - Agent auth
      summary: List agent credentials
      operationId: listAgentCredentials
      responses:
        '200':
          description: Credentials owned by the authenticated user
          content:
            application/json:
              schema:
                type: array
                items:
                  type: object
                  properties:
                    publicId:
                      type: string
                    name:
                      type:
                        - string
                        - 'null'
                      description: >-
                        Display name given at creation. Null for keys minted
                        before names existed.
                    scopes:
                      type: array
                      items:
                        $ref: '#/components/schemas/AgentScope'
                    createdAt:
                      type: string
                      format: date-time
                    lastUsedAt:
                      type:
                        - string
                        - 'null'
                      format: date-time
                    revokedAt:
                      type:
                        - string
                        - 'null'
                      format: date-time
                    expiresAt:
                      type:
                        - string
                        - 'null'
                      format: date-time
                      description: When the key stops working. Null means no expiration.
                    retrievable:
                      type: boolean
                      description: >-
                        Whether the key can be revealed again from the
                        dashboard. Headless-minted keys are not retrievable.
components:
  schemas:
    AgentScope:
      type: string
      enum:
        - workspace.create
        - workspace.read
        - workspace.delete
        - workspace.reclassify
        - channel.connect
        - channel.read
        - channel.manage
        - messages.read
        - billing.read
        - billing.manage
        - member.invite
        - member.manage
        - team.read
        - team.manage
        - support.read
        - support.write
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      description: '`Authorization: Bearer hmok_...` API key or a dashboard session token'

````