list_tokens
Generated automatically from the published contract sources.
Build metadata: Registered in this build. Registration describes the default dispatcher in this build. It does not guarantee that a caller has the required credential or grant, that a tool is listed for that connection, or that the required service is configured.
A script calls this action over HTTPS at POST https://turnzero.ai/api/v1/actions/list_tokens, with a bearer credential and the action's payload as the JSON body. It also accepts GET.
Contract description
List the account's API tokens: id, scope, grants, label, and stamps — never the values.
Access and action metadata
{
"name": "list_tokens",
"resource": "token",
"tier": "observe",
"admits": [
"synthetic_estate",
"issues"
],
"summary": "The account's minted tokens: identities, scopes, grants, labels, stamps, and a space grant's space and level, and, where the token code form is served, `authorized_computer`, never values.",
"annotations": {
"readOnlyHint": true,
"destructiveHint": false,
"openWorldHint": false,
"idempotentHint": true
}
}
MCP catalog entry
{
"name": "list_tokens",
"tier": "observe",
"summary": "List the account's API tokens: id, scope, grants, label, and stamps — never the values.",
"owners": [],
"scenario": "API-L0-05"
}
request
| JSON pointer | Description and constraints |
|---|---|
| "" (root) | Type: object |
response
| JSON pointer | Description and constraints |
|---|---|
| "" (root) | Type: object Required fields: ["contract_version","tokens"] Additional properties: false |
| / |
Required value: 1 |
| / |
Type: array |
| / |
Type: object Required fields: ["id","scope_kind","application","grants","label","created_at","expires_at","revoked_at","last_used_at"] Additional properties: false |
| / |
Type: string |
| / |
Allowed values: ["account","application"] |
| / |
Type: ["string","null"] |
| / |
Type: array |
| / |
Allowed values: ["destructive","super_admin","synthetic_seed_purge","synthetic_estate","publication","feedback_queue","issues"] |
| / |
Type: ["string","null"] |
| / |
Whether the token is an authorized computer's: true on a token the turnzero-cloud command keeps on a computer it authorized, false on every other. Answered only where the token code form is served. Type: boolean |
| / |
The space the issues grant names; present on a token that carries the grant alone. Type: string Pattern: ^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$ |
| / |
The level the issues grant reaches its space at: report, contribute, or owner; present on a token that carries the grant alone. Allowed values: ["report","contribute","owner"] |
| / |
Type: string |
| / |
Type: ["string","null"] |
| / |
Type: ["string","null"] |
| / |
Type: ["string","null"] |
Complete payload contract
{
"request": {
"type": "object",
"properties": {}
},
"response": {
"type": "object",
"required": [
"contract_version",
"tokens"
],
"properties": {
"contract_version": {
"const": 1
},
"tokens": {
"type": "array",
"items": {
"type": "object",
"required": [
"id",
"scope_kind",
"application",
"grants",
"label",
"created_at",
"expires_at",
"revoked_at",
"last_used_at"
],
"properties": {
"id": {
"type": "string"
},
"scope_kind": {
"enum": [
"account",
"application"
]
},
"application": {
"type": [
"string",
"null"
]
},
"grants": {
"type": "array",
"items": {
"enum": [
"destructive",
"super_admin",
"synthetic_seed_purge",
"synthetic_estate",
"publication",
"feedback_queue",
"issues"
]
}
},
"label": {
"type": [
"string",
"null"
]
},
"authorized_computer": {
"type": "boolean",
"description": "Whether the token is an authorized computer's: true on a token the turnzero-cloud command keeps on a computer it authorized, false on every other. Answered only where the token code form is served."
},
"space": {
"type": "string",
"pattern": "^[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}$",
"description": "The space the issues grant names; present on a token that carries the grant alone."
},
"level": {
"enum": [
"report",
"contribute",
"owner"
],
"description": "The level the issues grant reaches its space at: report, contribute, or owner; present on a token that carries the grant alone."
},
"created_at": {
"type": "string"
},
"expires_at": {
"type": [
"string",
"null"
]
},
"revoked_at": {
"type": [
"string",
"null"
]
},
"last_used_at": {
"type": [
"string",
"null"
]
}
},
"additionalProperties": false
}
}
},
"additionalProperties": false
}
}
Shared contracts
- Refusals: every refusal, by surface, with its cause and its remedy
- schemas/wire_error.schema.json
- schemas/wire_errors.json
- schemas/action_payloads.json (includes shared shapes)
- management_api_contract.md