client.keys()
Каждый метод этого пространства имён: его сигнатура, параметры, что он возвращает, и пример.
Методы
Every key in the workspace: list, create, change, rotate, switch off and revoke them, never wider than the calling key, and read their request log and activity.
keys().listkeys().listAllkeys().iteratekeys().getkeys().createkeys().updatekeys().deletekeys().rotatekeys().revokekeys().listRequestskeys().listAllRequestskeys().iterateRequestskeys().listActivitykeys().listAllActivitykeys().iterateActivitykeys().listWorkspaceRequestskeys().listAllWorkspaceRequestskeys().iterateWorkspaceRequestskeys().listWorkspaceActivitykeys().listAllWorkspaceActivitykeys().iterateWorkspaceActivitykeys().stats
keys().list
List one page of the workspace's API keys
Page list(RequestOptions options)Returns one page of the workspace's keys, newest first, with what the Settings, API keys page shows: status, scopes, role, send scope, when each was last used, how often, and who made and last changed it. Revoked and expired keys stay listed until somebody deletes them. No secret is ever returned; maskedKey is enough to tell two keys apart.
A key narrowed to some domains or addresses only sees the keys whose send scope sits inside its own, so any other is a 404 rather than a refusal. Over OAuth only the workspace owner reaches it, and a member's token is 403 owner_only.
Параметры
options.limitintRows per page, a whole number from 1 to 100. The server defaults to 25.
options.cursorStringThe
nextCursorfrom the previous page, passed back unchanged. Never build one yourself.options.apiKeyStringOverrides the client API key for this call only.
Возвращает
A Page of maps with items, hasMore and nextCursor. Each item has id, name, mode, maskedKey, keyLast4, status, scopes, roleId, roleName, addressAllowlist, domainAllowlist, expiresAt, lastUsedAt, totalUses, rotatedAt, rotationCount, deactivatedAt, revokedAt, revokedReason, createdAt, createdBy, updatedAt, updatedBy, lastChangeAt and lastChangeType. Never a secret.
Пример
Page page = client.keys().list(); for (Map<String, Object> key : page) { System.out.println(key.get("maskedKey") + " " + key.get("name") + " " + key.get("status"));} if (page.hasMore()) { System.out.println("Next page: " + page.nextCursor());}Примечания
It needs
keys:read, which no key holds unless somebody gave it one.The cursor is opaque: pass
nextCursorback as it came.
Также доступно в
- API
GET /keys- TypeScript
keys.list()- Python
keys.list()- Ruby
keys.list- PHP
keys->list- Go
Keys.List- C#
Keys.ListAsync- CLI
openemail keys list
keys().listAll
Collect every API key into one list
List<Map<String, Object>> listAll(RequestOptions options)Walks every page of list and returns every key the caller can see, newest first.
Параметры
options.limitintPage size for each request, 1 to 100. The server defaults to 25.
options.cursorStringStarts the walk from this cursor instead of the newest row.
options.apiKeyStringOverrides the client API key for every page of this walk.
Возвращает
A list of maps, one per key with the fields list returns, newest first.
Пример
List<Map<String, Object>> keys = client.keys().listAll(); for (Map<String, Object> all : keys) { System.out.println(all.get("id") + " " + all.get("name"));}Также доступно в
- API
GET /keys- TypeScript
keys.listAll()- Python
keys.list_all()- Ruby
keys.list_all- PHP
keys->listAll- Go
Keys.ListAll- C#
Keys.ListAllAsync
keys().iterate
Stream the workspace's API keys one at a time
PagedIterable iterate(RequestOptions options)A PagedIterable over list, fetching a page only when the one before is drained.
Параметры
options.limitintPage size per request, 1 to 100. The server defaults to 25.
options.cursorStringStarts the walk from this cursor instead of the newest row.
options.apiKeyStringOverrides the client API key for every page of this walk.
Возвращает
A PagedIterable that yields one key map per step.
Пример
for (Map<String, Object> key : client.keys().iterate()) { System.out.println(key.get("expiresAt") + " " + key.get("name"));}Также доступно в
- API
GET /keys- TypeScript
keys.iterate()- Python
keys.iterate()- Ruby
keys.iterate- PHP
keys->iterate- Go
Keys.Iterate- C#
Keys.IterateAsync
keys().get
Read one API key, without its secret
Map<String, Object> get(String id, RequestOptions options)Returns one key as list shows it. A key narrowed to some domains or addresses only sees the keys whose send scope sits inside its own, so any other is a 404 rather than a refusal. Over OAuth only the workspace owner reaches it, and a member's token is 403 owner_only.
client.me().get() describes the calling key itself and needs no scope; this reads any key the caller can see.
Параметры
idStringОбязательноKey id, the 24 hex characters after
oe_live_.options.apiKeyStringOverrides the client API key for this call only.
Возвращает
A map with id, name, mode, maskedKey, keyLast4, status, scopes, roleId, roleName, addressAllowlist, domainAllowlist, expiresAt, lastUsedAt, totalUses, rotatedAt, rotationCount, deactivatedAt, revokedAt, revokedReason, createdAt, createdBy, updatedAt, updatedBy, lastChangeAt and lastChangeType. Never a secret.
Пример
Map<String, Object> key = client.keys().get("4c1b257a66287fd113bd89d0"); System.out.println(key.get("status") + " " + key.get("scopes") + " " + key.get("domainAllowlist"));Также доступно в
- API
GET /keys/{id}- TypeScript
keys.get()- Python
keys.get()- Ruby
keys.get- PHP
keys->get- Go
Keys.Get- C#
Keys.GetAsync- CLI
openemail keys get
keys().create
Mint a new API key and receive its secret once
Map<String, Object> create(Map<String, Object> body, RequestOptions options)Creates a live key and returns it plus token, the whole secret. That is the only time it appears, so store it before doing anything else.
Left out, scopes is List.of("emails:send"), the role is the caller's own or none, the send scope is the caller's own or none (none means every address the workspace owns), and the expiry is the caller's own or none. The workspace cap on live keys applies, as a 422 workspace_limit_reached.
A key never makes or reaches a key wider than itself. The target has to sit inside the caller on every axis: scopes the caller holds after its own role has narrowed them, the same role when the caller has one, an expiry no later than the caller's when the caller expires, the caller's mode, and a send scope inside the caller's own, where one address never covers its whole domain. Anything wider is 403 beyond_caller_authority, and param names the axis.
Step-up verification, which the app asks for before it mints a key, cannot apply to a call made with a key, so keys:manage is a credential that makes credentials. Give it only to automation that provisions keys, narrow that key to the role and send scope it needs, and give it an expiry.
Параметры
body.nameStringОбязательноA name, 1 to 60 characters.
body.scopesList<String>The scopes the key holds, at least one, each held by the caller, as in
uk.openemail.constants.ApiScopes. Defaults toList.of("emails:send").body.roleIdString or nullA role to cap the key. Left out, the caller's own role. A caller with a role can only give its own, and
nullis refused for it.body.addressAllowlistList<String>Single addresses the key may send as, at most 50, each owned by the workspace.
body.domainAllowlistList<String>Whole domains the key may send as, at most 25, including addresses added to them later. Leave both lists out to inherit the caller's own; send both empty for none.
body.expiresInMinutesintMinutes until the key expires, 5 to 5,256,000 (ten years). Left out, the caller's own expiry.
options.apiKeyStringOverrides the client API key for this call only.
Возвращает
A map with every field get returns: id, name, mode, maskedKey, keyLast4, status, scopes, roleId, roleName, addressAllowlist, domainAllowlist, expiresAt, lastUsedAt, totalUses, rotatedAt, rotationCount, deactivatedAt, revokedAt, revokedReason, createdAt, createdBy, updatedAt, updatedBy, lastChangeAt and lastChangeType, none of them a secret. Plus token, oe_live_ followed by the id, an underscore and the secret.
Пример
Map<String, Object> key = client.keys().create(Body.of( "name", "Billing sender", "scopes", List.of("emails:send", "emails:read"), "domainAllowlist", List.of("billing.acme.com"), "expiresInMinutes", 129600)); System.out.println(key.get("token"));Примечания
Not retried automatically: a retry after a lost response would mint a second key.
The new key is recorded in the activity log as made by the calling key, with
sourceset toapi.The success status is 201.
Также доступно в
- API
POST /keys- TypeScript
keys.create()- Python
keys.create()- Ruby
keys.create- PHP
keys->create- Go
Keys.Create- C#
Keys.CreateAsync- CLI
openemail keys create
keys().update
Rename a key, change its scopes or send scope, or switch it off and on
Map<String, Object> update(String id, Map<String, Object> patch, RequestOptions options)Applies a partial change and returns the key as it now stands. scopes, addressAllowlist and domainAllowlist REPLACE what the key had, and a field left out stays as it was. "enabled", false switches the key off: every call with it is refused with inactive_api_key and it keeps its secret, scopes, role and send scope, so "enabled", true restores it exactly. That is the reversible alternative to revoke. A revoked key cannot be changed, and answers 409 revoked.
A key never makes or reaches a key wider than itself. The target has to sit inside the caller on every axis: scopes the caller holds after its own role has narrowed them, the same role when the caller has one, an expiry no later than the caller's when the caller expires, the caller's mode, and a send scope inside the caller's own, where one address never covers its whole domain. Anything wider is 403 beyond_caller_authority, and param names the axis. A key changing itself may only narrow itself.
A key narrowed to some domains or addresses only sees the keys whose send scope sits inside its own, so any other is a 404 rather than a refusal. Over OAuth only the workspace owner reaches it, and a member's token is 403 owner_only.
Параметры
idStringОбязательноKey id, the 24 hex characters after
oe_live_.patch.nameStringA new name, 1 to 60 characters.
patch.scopesList<String>The whole new list of scopes, at least one.
patch.addressAllowlistList<String>The whole new list of single addresses.
patch.domainAllowlistList<String>The whole new list of whole domains.
patch.enabledbooleanFalse switches the key off, true switches it back on.
options.apiKeyStringOverrides the client API key for this call only.
Возвращает
A map with id, name, mode, maskedKey, keyLast4, status, scopes, roleId, roleName, addressAllowlist, domainAllowlist, expiresAt, lastUsedAt, totalUses, rotatedAt, rotationCount, deactivatedAt, revokedAt, revokedReason, createdAt, createdBy, updatedAt, updatedBy, lastChangeAt and lastChangeType. Never a secret.
Пример
Map<String, Object> key = client.keys().update("4c1b257a66287fd113bd89d0", Body.of("enabled", false)); System.out.println(key.get("status"));Примечания
An empty patch is a 422. A PATCH is retried on network failure because applying the same patch twice leaves the same key.
Также доступно в
- API
PATCH /keys/{id}- TypeScript
keys.update()- Python
keys.update()- Ruby
keys.update- PHP
keys->update- Go
Keys.Update- C#
Keys.UpdateAsync- CLI
openemail keys update
keys().delete
Remove a revoked key from the list
Map<String, Object> delete(String id, RequestOptions options)Deletes a key that has already been revoked. Its request log and activity stay, under Deleted key, so the history of what it did is not lost with it. A key that has not been revoked is refused with 409 not_revoked, so nothing still calling with it loses its credential without somebody deciding that first.
A key never makes or reaches a key wider than itself. The target has to sit inside the caller on every axis: scopes the caller holds after its own role has narrowed them, the same role when the caller has one, an expiry no later than the caller's when the caller expires, the caller's mode, and a send scope inside the caller's own, where one address never covers its whole domain. Anything wider is 403 beyond_caller_authority, and param names the axis.
Параметры
idStringОбязательноKey id, the 24 hex characters after
oe_live_.options.apiKeyStringOverrides the client API key for this call only.
Возвращает
A map with object set to api_key, the id, and deleted set to true.
Пример
Map<String, Object> result = client.keys().delete("4c1b257a66287fd113bd89d0"); System.out.println(result.get("id"));Также доступно в
- API
DELETE /keys/{id}- TypeScript
keys.delete()- Python
keys.delete()- Ruby
keys.delete- PHP
keys->delete- Go
Keys.Delete- C#
Keys.DeleteAsync- CLI
openemail keys delete
keys().rotate
Give a key a new secret and receive it once
Map<String, Object> rotate(String id, RequestOptions options)Mints a new secret for a key and returns the key plus token, rotationCount and rotatedAt. The id, name, scopes, role, send scope, expiry and request history all carry on; only the secret and keyLast4 change. There is no overlap window: the old secret stops working the instant this returns.
Rotating the calling key itself is what client.me().rotate() does, and here it is allowed with keys:write as well as keys:manage. A revoked or expired key cannot be rotated, and answers 409 revoked or expired.
A key never makes or reaches a key wider than itself. The target has to sit inside the caller on every axis: scopes the caller holds after its own role has narrowed them, the same role when the caller has one, an expiry no later than the caller's when the caller expires, the caller's mode, and a send scope inside the caller's own, where one address never covers its whole domain. Anything wider is 403 beyond_caller_authority, and param names the axis. Rotation hands the caller a working secret for the key, which is why the ceiling is checked against the key as it stands.
A key narrowed to some domains or addresses only sees the keys whose send scope sits inside its own, so any other is a 404 rather than a refusal. Over OAuth only the workspace owner reaches it, and a member's token is 403 owner_only.
Параметры
idStringОбязательноKey id, the 24 hex characters after
oe_live_.options.apiKeyStringOverrides the client API key for this call only.
Возвращает
A map with every field get returns: id, name, mode, maskedKey, keyLast4, status, scopes, roleId, roleName, addressAllowlist, domainAllowlist, expiresAt, lastUsedAt, totalUses, rotatedAt, rotationCount, deactivatedAt, revokedAt, revokedReason, createdAt, createdBy, updatedAt, updatedBy, lastChangeAt and lastChangeType, none of them a secret. Plus token, rotationCount and rotatedAt.
Пример
Map<String, Object> rotated = client.keys().rotate("4c1b257a66287fd113bd89d0"); System.out.println(rotated.get("token") + " " + rotated.get("rotationCount") + " " + rotated.get("rotatedAt"));Примечания
Not retried automatically. Repeating a rotation would invalidate the secret the first attempt returned.
Также доступно в
- API
POST /keys/{id}/rotate- TypeScript
keys.rotate()- Python
keys.rotate()- Ruby
keys.rotate- PHP
keys->rotate- Go
Keys.Rotate- C#
Keys.RotateAsync- CLI
openemail keys rotate
keys().revoke
Revoke a key for good
Map<String, Object> revoke(String id, Map<String, Object> body, RequestOptions options)Revokes a key: every later call with it is refused with revoked_api_key, and it can never be switched back on, rotated or changed. reason is kept on the key and in the activity log. Revoking a key that is already revoked changes nothing and returns it as it is. A key may revoke itself, which is how an integration that believes its secret leaked retires it at once.
A key never makes or reaches a key wider than itself. The target has to sit inside the caller on every axis: scopes the caller holds after its own role has narrowed them, the same role when the caller has one, an expiry no later than the caller's when the caller expires, the caller's mode, and a send scope inside the caller's own, where one address never covers its whole domain. Anything wider is 403 beyond_caller_authority, and param names the axis.
A key narrowed to some domains or addresses only sees the keys whose send scope sits inside its own, so any other is a 404 rather than a refusal. Over OAuth only the workspace owner reaches it, and a member's token is 403 owner_only.
Параметры
idStringОбязательноKey id, the 24 hex characters after
oe_live_.body.reasonStringWhy, at most 200 characters.
options.apiKeyStringOverrides the client API key for this call only.
Возвращает
A map with id, name, mode, maskedKey, keyLast4, status, scopes, roleId, roleName, addressAllowlist, domainAllowlist, expiresAt, lastUsedAt, totalUses, rotatedAt, rotationCount, deactivatedAt, revokedAt, revokedReason, createdAt, createdBy, updatedAt, updatedBy, lastChangeAt and lastChangeType. Never a secret. status is revoked.
Пример
Map<String, Object> key = client.keys().revoke("4c1b257a66287fd113bd89d0", Body.of("reason", "Contractor offboarded")); System.out.println(key.get("status") + " " + key.get("revokedAt"));Примечания
Retried on network failure, because revoking twice leaves the same key. Prefer
update(id, Body.of("enabled", false))while you find out whether anything still depends on a key.
Также доступно в
- API
POST /keys/{id}/revoke- TypeScript
keys.revoke()- Python
keys.revoke()- Ruby
keys.revoke- PHP
keys->revoke- Go
Keys.Revoke- C#
Keys.RevokeAsync- CLI
openemail keys revoke
keys().listRequests
List one page of one key's request log
Page listRequests(String id, RequestOptions options)Returns one page of the calls one key made, newest first, the Requests tab of the key in the app. The request log records every authenticated call a key made: method, path, status, error code, duration, IP and user agent, and never a body or a query string. A call refused before a key could be identified is not in it, and neither is a call made with an OAuth access token. Nothing is pruned, so the log reaches back to a key's first call. failedOnly, statuses, path, since and until narrow it, and they combine.
A deleted key's log stays readable to a key that is not narrowed. A key narrowed to some domains or addresses only sees the keys whose send scope sits inside its own, so any other is a 404 rather than a refusal. Over OAuth only the workspace owner reaches it, and a member's token is 403 owner_only.
Параметры
idStringОбязательноKey id, the 24 hex characters after
oe_live_.options.failedOnlybooleanOnly calls answered with a status of 400 or more.
options.statusesString or List<Integer>Only calls answered with one of these HTTP status codes, such as
List.of(401, 403), as a list or one comma-separated string. At most 20, each from 100 to 599, sent comma-separated asstatus.options.pathStringOnly calls to this route, whatever the method, such as
/emailsor/emails/:id. It matches the route, not the exact path: an id counts as:idand an email address as:address. End it with*to read every route that starts with it, such as/emails/*.options.sinceInstant or StringOnly rows at or after this instant. An
Instantis sent as ISO 8601 in UTC, and a string must already be ISO 8601.options.untilInstant or StringOnly rows before this instant. It has to be later than
since, or the server answers 400invalid_parameter.options.limitintRows per page, a whole number from 1 to 100. The server defaults to 25.
options.cursorStringThe
nextCursorfrom the previous page, passed back unchanged. Never build one yourself.options.apiKeyStringOverrides the client API key for this call only.
Возвращает
A Page of maps with items, hasMore and nextCursor. Each item has id, keyId, keyName, requestId, method, path, status, errorCode, durationMs, ip, userAgent and createdAt.
Пример
Page page = client.keys().listRequests("4c1b257a66287fd113bd89d0", RequestOptions.create().set("failedOnly", true).limit(50)); for (Map<String, Object> call : page) { System.out.println(call.get("createdAt") + " " + call.get("method") + " " + call.get("path"));} if (page.hasMore()) { System.out.println("Next page: " + page.nextCursor());}Примечания
The cursor is opaque and stays valid under the same filters. One this log did not hand out is a 400
invalid_cursor.pathmatches the route rather than the exact path, because the log folds ids and addresses: every call to/emails/<id>is the one route/emails/:id, and passing a real id reads that whole route. Each row still carries the exactpath, so filter the page yourself to follow one id.The key making the call reads its own log with no scope through
me().listRequests.
Также доступно в
keys().listAllRequests
Collect one key's whole request log into one list
List<Map<String, Object>> listAllRequests(String id, RequestOptions options)Walks every page of listRequests under the same filters. The log is never pruned, so give it a window unless you mean to read a busy key's whole history, or use iterateRequests to stop early.
Параметры
idStringОбязательноKey id, the 24 hex characters after
oe_live_.options.failedOnlybooleanOnly calls answered with a status of 400 or more.
options.statusesString or List<Integer>Only calls answered with one of these HTTP status codes, such as
List.of(401, 403), as a list or one comma-separated string. At most 20, each from 100 to 599, sent comma-separated asstatus.options.pathStringOnly calls to this route, whatever the method, such as
/emailsor/emails/:id. It matches the route, not the exact path: an id counts as:idand an email address as:address. End it with*to read every route that starts with it, such as/emails/*.options.sinceInstant or StringOnly rows at or after this instant. An
Instantis sent as ISO 8601 in UTC, and a string must already be ISO 8601.options.untilInstant or StringOnly rows before this instant. It has to be later than
since, or the server answers 400invalid_parameter.options.limitintPage size for each request, 1 to 100. The server defaults to 25.
options.cursorStringStarts the walk from this cursor instead of the newest row.
options.apiKeyStringOverrides the client API key for every page of this walk.
Возвращает
A list of maps, one per call with the fields listRequests returns, newest first.
Пример
List<Map<String, Object>> today = client.keys().listAllRequests("4c1b257a66287fd113bd89d0", RequestOptions.create().set("since", "2026-10-09T22:34:28.552Z").limit(100)); for (Map<String, Object> request : today) { System.out.println(request.get("id") + " " + request.get("status"));}Примечания
If any page fails the call throws and the rows already fetched are discarded.
Также доступно в
keys().iterateRequests
Stream one key's request log one call at a time
PagedIterable iterateRequests(String id, RequestOptions options)A PagedIterable over listRequests under the same filters, fetching a page only when the one before is drained.
Параметры
idStringОбязательноKey id, the 24 hex characters after
oe_live_.options.failedOnlybooleanOnly calls answered with a status of 400 or more.
options.statusesString or List<Integer>Only calls answered with one of these HTTP status codes, such as
List.of(401, 403), as a list or one comma-separated string. At most 20, each from 100 to 599, sent comma-separated asstatus.options.pathStringOnly calls to this route, whatever the method, such as
/emailsor/emails/:id. It matches the route, not the exact path: an id counts as:idand an email address as:address. End it with*to read every route that starts with it, such as/emails/*.options.sinceInstant or StringOnly rows at or after this instant. An
Instantis sent as ISO 8601 in UTC, and a string must already be ISO 8601.options.untilInstant or StringOnly rows before this instant. It has to be later than
since, or the server answers 400invalid_parameter.options.limitintPage size per request, 1 to 100. The server defaults to 25.
options.cursorStringStarts the walk from this cursor instead of the newest row.
options.apiKeyStringOverrides the client API key for every page of this walk.
Возвращает
A PagedIterable that yields one call map per step.
Пример
for (Map<String, Object> call : client.keys().iterateRequests("4c1b257a66287fd113bd89d0", RequestOptions.of("failedOnly", true))) { System.out.println(call.get("errorCode") + " " + call.get("createdAt"));}Также доступно в
keys().listActivity
List one page of what happened to one key
Page listActivity(String id, RequestOptions options)Returns one page of one key's audit log, newest first, the Activity tab of the key in the app. Every change to a key is a row: created, updated, rotated, deactivated, reactivated, revoked and deleted, plus auth_failed for every call that presented the key and was refused. actor names who made the change, a person as @username or a key as API key <name> in label, and detail.source says where it came from: console, api, mcp or documentation.
A deleted key keeps its history, readable to a key that is not narrowed. A key narrowed to some domains or addresses only sees the keys whose send scope sits inside its own, so any other is a 404 rather than a refusal. Over OAuth only the workspace owner reaches it, and a member's token is 403 owner_only.
Параметры
idStringОбязательноKey id, the 24 hex characters after
oe_live_.options.sinceInstant or StringOnly rows at or after this instant. An
Instantis sent as ISO 8601 in UTC, and a string must already be ISO 8601.options.untilInstant or StringOnly rows before this instant. It has to be later than
since, or the server answers 400invalid_parameter.options.limitintRows per page, a whole number from 1 to 100. The server defaults to 25.
options.cursorStringThe
nextCursorfrom the previous page, passed back unchanged. Never build one yourself.options.apiKeyStringOverrides the client API key for this call only.
Возвращает
A Page of maps with items, hasMore and nextCursor. Each item has id, keyId, keyName, type, createdAt, actor and detail.
Пример
Page page = client.keys().listActivity("4c1b257a66287fd113bd89d0"); for (Map<String, Object> change : page) { System.out.println(change.get("createdAt") + " " + change.get("type") + " " + change.get("actor"));} if (page.hasMore()) { System.out.println("Next page: " + page.nextCursor());}Также доступно в
keys().listAllActivity
Collect one key's whole audit log into one list
List<Map<String, Object>> listAllActivity(String id, RequestOptions options)Walks every page of listActivity under the same window and returns every change, newest first.
Параметры
idStringОбязательноKey id, the 24 hex characters after
oe_live_.options.sinceInstant or StringOnly rows at or after this instant. An
Instantis sent as ISO 8601 in UTC, and a string must already be ISO 8601.options.untilInstant or StringOnly rows before this instant. It has to be later than
since, or the server answers 400invalid_parameter.options.limitintPage size for each request, 1 to 100. The server defaults to 25.
options.cursorStringStarts the walk from this cursor instead of the newest row.
options.apiKeyStringOverrides the client API key for every page of this walk.
Возвращает
A list of maps, one per change with the fields listActivity returns, newest first.
Пример
List<Map<String, Object>> history = client.keys().listAllActivity("4c1b257a66287fd113bd89d0"); for (Map<String, Object> activity : history) { System.out.println(activity.get("id") + " " + activity.get("type"));}Примечания
If any page fails the call throws and the rows already fetched are discarded.
Также доступно в
keys().iterateActivity
Stream one key's audit log one change at a time
PagedIterable iterateActivity(String id, RequestOptions options)A PagedIterable over listActivity under the same window, fetching a page only when the one before is drained.
Параметры
idStringОбязательноKey id, the 24 hex characters after
oe_live_.options.sinceInstant or StringOnly rows at or after this instant. An
Instantis sent as ISO 8601 in UTC, and a string must already be ISO 8601.options.untilInstant or StringOnly rows before this instant. It has to be later than
since, or the server answers 400invalid_parameter.options.limitintPage size per request, 1 to 100. The server defaults to 25.
options.cursorStringStarts the walk from this cursor instead of the newest row.
options.apiKeyStringOverrides the client API key for every page of this walk.
Возвращает
A PagedIterable that yields one change map per step.
Пример
for (Map<String, Object> change : client.keys().iterateActivity("4c1b257a66287fd113bd89d0")) { System.out.println(change.get("type") + " " + change.get("actor") + " " + change.get("createdAt"));}Также доступно в
keys().listWorkspaceRequests
List one page of the request log of every key
Page listWorkspaceRequests(RequestOptions options)Returns one page of every call the workspace's keys made, newest first, the Requests tab of Settings, API keys. The request log records every authenticated call a key made: method, path, status, error code, duration, IP and user agent, and never a body or a query string. A call refused before a key could be identified is not in it, and neither is a call made with an OAuth access token. Nothing is pruned, so the log reaches back to a key's first call. keyIds, failedOnly, statuses, path, since and until narrow it, and they combine. keyIds may name a deleted key.
A narrowed key reads only the log of the keys it can see, so naming another key in keyIds matches nothing.
Параметры
options.keyIdsString or List<String>Key ids to read, at most 50, as a list or one comma-separated string, sent comma-separated. Left out, every key the caller can see.
options.failedOnlybooleanOnly calls answered with a status of 400 or more.
options.statusesString or List<Integer>Only calls answered with one of these HTTP status codes, such as
List.of(401, 403), as a list or one comma-separated string. At most 20, each from 100 to 599, sent comma-separated asstatus.options.pathStringOnly calls to this route, whatever the method, such as
/emailsor/emails/:id. It matches the route, not the exact path: an id counts as:idand an email address as:address. End it with*to read every route that starts with it, such as/emails/*.options.sinceInstant or StringOnly rows at or after this instant. An
Instantis sent as ISO 8601 in UTC, and a string must already be ISO 8601.options.untilInstant or StringOnly rows before this instant. It has to be later than
since, or the server answers 400invalid_parameter.options.limitintRows per page, a whole number from 1 to 100. The server defaults to 25.
options.cursorStringThe
nextCursorfrom the previous page, passed back unchanged. Never build one yourself.options.apiKeyStringOverrides the client API key for this call only.
Возвращает
A Page of maps with items, hasMore and nextCursor. Each item has id, keyId, keyName, requestId, method, path, status, errorCode, durationMs, ip, userAgent and createdAt.
Пример
Page page = client.keys().listWorkspaceRequests(RequestOptions.create().set("failedOnly", true).set("since", "2026-09-22T00:00:00Z")); for (Map<String, Object> call : page) { System.out.println(call.get("keyName") + " " + call.get("method") + " " + call.get("path"));} if (page.hasMore()) { System.out.println("Next page: " + page.nextCursor());}Также доступно в
keys().listAllWorkspaceRequests
Collect the request log of every key into one list
List<Map<String, Object>> listAllWorkspaceRequests(RequestOptions options)Walks every page of listWorkspaceRequests under the same filters. The log is never pruned, so give it a window, or use iterateWorkspaceRequests to stop early.
Параметры
options.keyIdsString or List<String>Key ids to read, at most 50, as a list or one comma-separated string, sent comma-separated. Left out, every key the caller can see.
options.failedOnlybooleanOnly calls answered with a status of 400 or more.
options.statusesString or List<Integer>Only calls answered with one of these HTTP status codes, such as
List.of(401, 403), as a list or one comma-separated string. At most 20, each from 100 to 599, sent comma-separated asstatus.options.pathStringOnly calls to this route, whatever the method, such as
/emailsor/emails/:id. It matches the route, not the exact path: an id counts as:idand an email address as:address. End it with*to read every route that starts with it, such as/emails/*.options.sinceInstant or StringOnly rows at or after this instant. An
Instantis sent as ISO 8601 in UTC, and a string must already be ISO 8601.options.untilInstant or StringOnly rows before this instant. It has to be later than
since, or the server answers 400invalid_parameter.options.limitintPage size for each request, 1 to 100. The server defaults to 25.
options.cursorStringStarts the walk from this cursor instead of the newest row.
options.apiKeyStringOverrides the client API key for every page of this walk.
Возвращает
A list of maps, one per call with the fields listWorkspaceRequests returns, newest first.
Пример
List<Map<String, Object>> failures = client.keys().listAllWorkspaceRequests(RequestOptions.create() .set("failedOnly", true) .set("since", "2026-10-10T21:34:28.554Z") .limit(100)); for (Map<String, Object> workspaceRequest : failures) { System.out.println(workspaceRequest.get("id") + " " + workspaceRequest.get("status"));}Примечания
If any page fails the call throws and the rows already fetched are discarded.
Также доступно в
keys().iterateWorkspaceRequests
Stream the request log of every key one call at a time
PagedIterable iterateWorkspaceRequests(RequestOptions options)A PagedIterable over listWorkspaceRequests under the same filters, fetching a page only when the one before is drained.
Параметры
options.keyIdsString or List<String>Key ids to read, at most 50, as a list or one comma-separated string, sent comma-separated. Left out, every key the caller can see.
options.failedOnlybooleanOnly calls answered with a status of 400 or more.
options.statusesString or List<Integer>Only calls answered with one of these HTTP status codes, such as
List.of(401, 403), as a list or one comma-separated string. At most 20, each from 100 to 599, sent comma-separated asstatus.options.pathStringOnly calls to this route, whatever the method, such as
/emailsor/emails/:id. It matches the route, not the exact path: an id counts as:idand an email address as:address. End it with*to read every route that starts with it, such as/emails/*.options.sinceInstant or StringOnly rows at or after this instant. An
Instantis sent as ISO 8601 in UTC, and a string must already be ISO 8601.options.untilInstant or StringOnly rows before this instant. It has to be later than
since, or the server answers 400invalid_parameter.options.limitintPage size per request, 1 to 100. The server defaults to 25.
options.cursorStringStarts the walk from this cursor instead of the newest row.
options.apiKeyStringOverrides the client API key for every page of this walk.
Возвращает
A PagedIterable that yields one call map per step.
Пример
for (Map<String, Object> call : client.keys().iterateWorkspaceRequests(RequestOptions.of("failedOnly", true))) { System.out.println(call.get("status") + " " + call.get("requestId") + " " + call.get("path"));}Также доступно в
keys().listWorkspaceActivity
List one page of what happened to every key
Page listWorkspaceActivity(RequestOptions options)Returns one page of the audit log of every key in the workspace, newest first, the Activity tab of Settings, API keys. Every change to a key is a row: created, updated, rotated, deactivated, reactivated, revoked and deleted, plus auth_failed for every call that presented the key and was refused. actor names who made the change, a person as @username or a key as API key <name> in label, and detail.source says where it came from: console, api, mcp or documentation.
keyIds narrows it, deleted keys included, and since and until keep a window. A narrowed key reads only the activity of the keys it can see.
Параметры
options.keyIdsString or List<String>Key ids to read, at most 50, as a list or one comma-separated string, sent comma-separated. Left out, every key the caller can see.
options.sinceInstant or StringOnly rows at or after this instant. An
Instantis sent as ISO 8601 in UTC, and a string must already be ISO 8601.options.untilInstant or StringOnly rows before this instant. It has to be later than
since, or the server answers 400invalid_parameter.options.limitintRows per page, a whole number from 1 to 100. The server defaults to 25.
options.cursorStringThe
nextCursorfrom the previous page, passed back unchanged. Never build one yourself.options.apiKeyStringOverrides the client API key for this call only.
Возвращает
A Page of maps with items, hasMore and nextCursor. Each item has id, keyId, keyName, type, createdAt, actor and detail.
Пример
Page page = client.keys().listWorkspaceActivity(RequestOptions.of("since", "2026-09-01T00:00:00Z")); for (Map<String, Object> change : page) { System.out.println(change.get("keyName") + " " + change.get("type") + " " + change.get("actor"));} if (page.hasMore()) { System.out.println("Next page: " + page.nextCursor());}Также доступно в
keys().listAllWorkspaceActivity
Collect the audit log of every key into one list
List<Map<String, Object>> listAllWorkspaceActivity(RequestOptions options)Walks every page of listWorkspaceActivity under the same filters and returns every change, newest first.
Параметры
options.keyIdsString or List<String>Key ids to read, at most 50, as a list or one comma-separated string, sent comma-separated. Left out, every key the caller can see.
options.sinceInstant or StringOnly rows at or after this instant. An
Instantis sent as ISO 8601 in UTC, and a string must already be ISO 8601.options.untilInstant or StringOnly rows before this instant. It has to be later than
since, or the server answers 400invalid_parameter.options.limitintPage size for each request, 1 to 100. The server defaults to 25.
options.cursorStringStarts the walk from this cursor instead of the newest row.
options.apiKeyStringOverrides the client API key for every page of this walk.
Возвращает
A list of maps, one per change with the fields listWorkspaceActivity returns, newest first.
Пример
List<Map<String, Object>> changes = client.keys().listAllWorkspaceActivity(RequestOptions.of("since", "2026-09-01T00:00:00.000Z")); for (Map<String, Object> workspaceActivity : changes) { System.out.println(workspaceActivity.get("id") + " " + workspaceActivity.get("type"));}Примечания
If any page fails the call throws and the rows already fetched are discarded.
Также доступно в
keys().iterateWorkspaceActivity
Stream the audit log of every key one change at a time
PagedIterable iterateWorkspaceActivity(RequestOptions options)A PagedIterable over listWorkspaceActivity under the same filters, fetching a page only when the one before is drained.
Параметры
options.keyIdsString or List<String>Key ids to read, at most 50, as a list or one comma-separated string, sent comma-separated. Left out, every key the caller can see.
options.sinceInstant or StringOnly rows at or after this instant. An
Instantis sent as ISO 8601 in UTC, and a string must already be ISO 8601.options.untilInstant or StringOnly rows before this instant. It has to be later than
since, or the server answers 400invalid_parameter.options.limitintPage size per request, 1 to 100. The server defaults to 25.
options.cursorStringStarts the walk from this cursor instead of the newest row.
options.apiKeyStringOverrides the client API key for every page of this walk.
Возвращает
A PagedIterable that yields one change map per step.
Пример
for (Map<String, Object> change : client.keys().iterateWorkspaceActivity()) { System.out.println(change.get("type") + " " + change.get("keyName") + " " + change.get("detail"));}Также доступно в
keys().stats
Read what the keys did inside a window
Map<String, Object> stats(RequestOptions options)Returns the numbers behind the Analytics tab of the API keys page: the mail the keys sent and what became of it, the calls refused because a secret was wrong, revoked or expired, the requests they made and how many failed, the routes they called most with the median time each took, and the status codes they got back.
It covers every key you can see, or the ones keyIds names. The window runs from since to until, and left out it is the 30 days before now. grain sets the bucket width of the series and offsetMinutes shifts the boundaries so days break where the reader's day does.
Параметры
options.keyIdsString or List<String>Only these keys, at most 50, as a list or one comma-separated string. Left out, every key you can see.
options.sinceInstant or StringThe start of the window, an
Instantor an ISO 8601 instant. Defaults to 30 days beforeuntil.options.untilInstant or StringThe end of the window, not included. Defaults to now.
options.grainStringBucket width:
minute,hourorday, defaulting today.options.offsetMinutesintMinutes east of UTC to bucket in, from -840 to 840, defaulting to 0.
options.apiKeyStringOverrides the client API key for this call only.
Возвращает
A map with the window it covered, sends, rejected, requests, routes and codes.
Пример
Map<String, Object> stats = client.keys().stats(RequestOptions.of("grain", "day")); System.out.println(stats.get("sends") + " " + stats.get("routes"));Примечания
A key narrowed to some domains or addresses only counts the keys whose send scope sits inside its own, and an access token is refused with 403
owner_onlyunless it acts for the owner of the workspace.The series are sparse: a bucket with nothing in it has no entry, so a chart must fill the gaps.
Retried automatically on network failure, since it only reads.
Также доступно в
- API
GET /keys/stats- TypeScript
keys.stats()- Python
keys.stats()- Ruby
keys.stats- PHP
keys->stats- Go
Keys.Stats- C#
Keys.StatsAsync- CLI
openemail keys stats