> ## Documentation Index
> Fetch the complete documentation index at: https://docs.xo.market/llms.txt
> Use this file to discover all available pages before exploring further.

# List API keys

> List the caller's API key UUIDs. Owner is derived from the
presented HMAC API key — there is no `?address=` query
parameter (closes a credential-enumeration hole).




## OpenAPI

````yaml /api-reference/openapi.yaml get /auth/api-keys
openapi: 3.0.3
info:
  title: XO Orderbook API
  description: |
    Public REST surface of the XO CLOB API.

    XO mainnet chain id is `3223`. The EIP-712 order domain is
    `XO Market CLOB` with `verifyingContract` set to the
    [CTF Exchange](/) address. See
    [Smart accounts](../guides/smart-accounts) for the smart-account
    identity model and ERC-1271 order signing.

    Wire conventions:
      * Prices are trimmed decimal strings (e.g. `"0.5"`, `"0.555"`).
      * Sizes are decimal-string integers in human shares.
      * Timestamps in trade and book responses are stringified Unix
        seconds / milliseconds (the SDK uses `TimestampSeconds<String>`
        / `TimestampMilliSeconds<String>`).
      * Token IDs are decimal U256 strings; condition IDs are
        `0x`-prefixed 32-byte hex.
  version: 1.0.0
  contact:
    name: XO Market
    url: https://beta.xo.market
servers:
  - url: https://orderbooks.xo.market
    description: Mainnet (XO chain id 3223)
security: []
tags:
  - name: Authentication
    description: >-
      Create and manage API keys. The L1 ClobAuth EIP-712 flow mints HMAC
      credentials that authenticate every other private request.
  - name: Market Data
    description: >-
      Public reads for books, prices, midpoints, spreads, last trades, and price
      history. Also includes server time and per-token configuration.
  - name: Markets
    description: >-
      Discovery for tradable markets, including pagination and SDK-compatible
      simplified shapes.
  - name: Trade
    description: Place, cancel, and inspect orders and trades for the authenticated maker.
  - name: Account
    description: Maker balance, allowance, positions, and claimable settled positions.
paths:
  /auth/api-keys:
    get:
      tags:
        - Authentication
      summary: List API keys
      description: |
        List the caller's API key UUIDs. Owner is derived from the
        presented HMAC API key — there is no `?address=` query
        parameter (closes a credential-enumeration hole).
      responses:
        '200':
          description: OK
          content:
            application/json:
              schema:
                type: object
                required:
                  - apiKeys
                properties:
                  apiKeys:
                    type: array
                    items:
                      type: string
                      format: uuid
              examples:
                one_key:
                  summary: caller has a single API key
                  value:
                    apiKeys:
                      - 7a3f9c1d-8b2e-4a5c-9d1e-2f3a4b5c6d7e
                multiple_keys:
                  summary: caller has rotated keys
                  value:
                    apiKeys:
                      - 7a3f9c1d-8b2e-4a5c-9d1e-2f3a4b5c6d7e
                      - 1b2c3d4e-5f6a-4b7c-8d9e-0f1a2b3c4d5e
        '401':
          $ref: '#/components/responses/Error401'
      security:
        - L2HMAC: []
      x-codeSamples:
        - lang: Rust
          label: xo-orderbook-client-rs
          source: |
            // Requires an authenticated client.
            let resp = client.api_keys().await?;
            for uuid in &resp.api_keys {
                println!("key: {uuid}");
            }
components:
  responses:
    Error401:
      description: |
        Authentication failure. L1 ClobAuth (wallet) or L2 HMAC (API key)
        headers were missing, malformed, expired, or did not match the
        requested resource.
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorResponse'
          examples:
            l1_required:
              summary: L1 ClobAuth headers missing
              value:
                error: L1 ClobAuth headers required
            l2_required:
              summary: HMAC credentials missing
              value:
                error: HMAC L2 credentials required
            address_mismatch:
              summary: L1-recovered address does not match request
              value:
                error: L1 auth address does not match request address
  schemas:
    ErrorResponse:
      type: object
      required:
        - error
      properties:
        error:
          type: string
  securitySchemes:
    L2HMAC:
      type: apiKey
      in: header
      name: XO_API_KEY
      description: >-
        L2 HMAC request signature. See
        [Authentication](/api-reference/authentication).

````