Skip to content

List access tokens

GET
/tokens
curl --request GET \
--url 'https://api.flotera.com/api/v1/tokens?limit=50&kind=pat' \
--cookie __Host-erm_session=<__Host-erm_session>

PATs, one-time init tokens and agent credentials of the tenant. Only masked prefixes are ever returned; plaintext exists once at mint time.

cursor
string
>= 1 characters <= 512 characters

Opaque pagination cursor from a previous next_cursor.

limit
integer
default: 50 >= 1 <= 200

Page size.

kind
string
Allowed values: pat init agent

Page of tokens.

Media typeapplication/json
object
items
required
Array<object>
<= 200 items
object
id
required

UUID (v7 for new entities; v4 accepted during migration).

string format: uuid
tenant_id
required

UUID (v7 for new entities; v4 accepted during migration).

string format: uuid
kind
required
string
Allowed values: pat init agent
name
string | null
<= 80 characters
token_prefix
required

Masked prefix for display (erm_pat_xxxx····xxxx); plaintext is never stored.

string
<= 64 characters
scopes
required

Granted scopes; agent tokens carry fixed server-assigned scopes.

Array<string>
<= 32 items
server_id
Any of:

UUID (v7 for new entities; v4 accepted during migration).

string format: uuid
server_allowlist

PAT caveat; null means the caveat is unset (all tenant servers).

Array<string> | null
<= 200 items
activated_at

For init tokens — when the one-time claim happened.

string | null format: date-time
expires_at

RFC 3339 UTC with microsecond precision, or null.

string | null format: date-time
revoked_at

RFC 3339 UTC with microsecond precision, or null.

string | null format: date-time
last_used_at

Updated at most once per 5 minutes.

string | null format: date-time
created_at
required

RFC 3339 UTC with microsecond precision.

string format: date-time
next_cursor
required

Opaque cursor for the next page; null when there are no more rows.

string | null
>= 1 characters <= 512 characters
Example
{
"items": [
{
"kind": "pat",
"created_at": "2026-07-25T10:15:30.123456Z"
}
]
}

Missing/invalid credentials (code=unauthorized).

Media typeapplication/problem+json

RFC 9457 problem document with a stable machine code.

object
type
required
string format: uri
title
required
string
<= 256 characters
status
required
integer
>= 100 <= 599
code
required

Stable machine-readable error code (03 §2.4).

string
Allowed values: unauthorized forbidden csrf_rejected not_found conflict idempotency_conflict validation_failed rate_limited payload_too_large unsupported_agent_version temporarily_unavailable offline_queue_full online_queue_full plan_required server_limit_reached feature_not_entitled account_in_grace account_frozen payment_pending payment_expired payment_amount_mismatch change_already_pending change_already_applied change_effective reserve_not_covered direction_changed
detail
string
<= 2048 characters
instance
string
<= 512 characters
request_id

UUID (v7 for new entities; v4 accepted during migration).

string format: uuid
errors
Array<object>
<= 100 items
object
path
required

JSON Pointer to the offending field.

string
<= 512 characters
code
required
string
<= 64 characters
Example
{
"type": "https://ermeon.com/problems/validation",
"code": "unauthorized"
}

Authenticated but not permitted. code=forbidden — role/scope mismatch; code=feature_not_entitled — the plan does not include the capability; code=account_frozen — the account is frozen and this operation is declared x-ermeon-frozen: deny. The three are deliberately distinct: only the last one is fixed by a top-up (13 §5.6).

Media typeapplication/problem+json

RFC 9457 problem document with a stable machine code.

object
type
required
string format: uri
title
required
string
<= 256 characters
status
required
integer
>= 100 <= 599
code
required

Stable machine-readable error code (03 §2.4).

string
Allowed values: unauthorized forbidden csrf_rejected not_found conflict idempotency_conflict validation_failed rate_limited payload_too_large unsupported_agent_version temporarily_unavailable offline_queue_full online_queue_full plan_required server_limit_reached feature_not_entitled account_in_grace account_frozen payment_pending payment_expired payment_amount_mismatch change_already_pending change_already_applied change_effective reserve_not_covered direction_changed
detail
string
<= 2048 characters
instance
string
<= 512 characters
request_id

UUID (v7 for new entities; v4 accepted during migration).

string format: uuid
errors
Array<object>
<= 100 items
object
path
required

JSON Pointer to the offending field.

string
<= 512 characters
code
required
string
<= 64 characters
Example
{
"type": "https://ermeon.com/problems/validation",
"code": "unauthorized"
}

The tenant has no plan assignment, so the capability cannot be evaluated (code=plan_required).

Media typeapplication/problem+json

RFC 9457 problem document with a stable machine code.

object
type
required
string format: uri
title
required
string
<= 256 characters
status
required
integer
>= 100 <= 599
code
required

Stable machine-readable error code (03 §2.4).

string
Allowed values: unauthorized forbidden csrf_rejected not_found conflict idempotency_conflict validation_failed rate_limited payload_too_large unsupported_agent_version temporarily_unavailable offline_queue_full online_queue_full plan_required server_limit_reached feature_not_entitled account_in_grace account_frozen payment_pending payment_expired payment_amount_mismatch change_already_pending change_already_applied change_effective reserve_not_covered direction_changed
detail
string
<= 2048 characters
instance
string
<= 512 characters
request_id

UUID (v7 for new entities; v4 accepted during migration).

string format: uuid
errors
Array<object>
<= 100 items
object
path
required

JSON Pointer to the offending field.

string
<= 512 characters
code
required
string
<= 64 characters
Example
{
"type": "https://ermeon.com/problems/validation",
"code": "unauthorized"
}