> ## Documentation Index
> Fetch the complete documentation index at: https://developers.authlete.com/llms.txt
> Use this file to discover all available pages before exploring further.

# List Issued Tokens

> Get the list of access tokens that are associated with the service.




## OpenAPI

````yaml https://spec.speakeasy.com/authlete/sdk-workspace/authlete-api-explorer-with-code-samples get /api/{serviceId}/auth/token/get/list
openapi: 3.0.3
info:
  title: Authlete API
  description: ''
  version: 3.0.16
  license:
    name: Apache 2.0
    url: https://www.apache.org/licenses/LICENSE-2.0.html
servers:
  - description: 🇺🇸 US Cluster
    url: https://us.authlete.com
  - description: 🇯🇵 Japan Cluster
    url: https://jp.authlete.com
  - description: 🇪🇺 Europe Cluster
    url: https://eu.authlete.com
  - description: 🇧🇷 Brazil Cluster
    url: https://br.authlete.com
security:
  - bearer: []
tags:
  - name: Service Management
    description: >-
      API endpoints for managing services, including creation, update, and
      deletion of services.
    x-tag-expanded: false
  - name: Client Management
    description: >-
      API endpoints for managing OAuth clients, including creation, update, and
      deletion of clients.
    x-tag-expanded: false
  - name: Authorization Endpoint
    description: API endpoints for implementing OAuth 2.0 Authorization Endpoint.
    x-tag-expanded: false
  - name: Pushed Authorization Endpoint
    description: >-
      API endpoints for implementing OAuth 2.0 Pushed Authorization Requests
      (PAR).
    x-tag-expanded: false
  - name: Token Endpoint
    description: API endpoints for implementing OAuth 2.0 Token Endpoint.
    x-tag-expanded: false
  - name: Token Operations
    description: >-
      API endpoints for various token related operations, including creating,
      revoking and deleting access_tokens with specified scopes.
    x-tag-expanded: false
  - name: Introspection Endpoint
    description: API endpoints for implementing OAuth 2.0 Introspection Endpoint.
    x-tag-expanded: false
  - name: Revocation Endpoint
    description: API endpoint for implementing OAuth 2.0 Revocation Endpoint.
    x-tag-expanded: false
  - name: UserInfo Endpoint
    description: API endpoints for implementing OpenID Connect UserInfo Endpoint.
    x-tag-expanded: false
  - name: JWK Set Endpoint
    description: API endpoints for to generate JSON Web Key Set (JWKS) for a service.
    x-tag-expanded: false
  - name: Discovery Endpoint
    description: API endpoints for implementing OpenID Connect Discovery.
    x-tag-expanded: false
  - name: Configuration Endpoint
    description: API endpoint for accessing configuration settings for a service.
    x-tag-expanded: false
  - name: Dynamic Client Registration
    description: API endpoints for implementing OAuth 2.0 Dynamic Client Registration.
    x-tag-expanded: false
  - name: CIBA
    description: >-
      API endpoints for implementing Client-Initiated Backchannel Authentication
      (CIBA).
    x-tag-expanded: false
  - name: Grant Management Endpoint
    description: >-
      API endpoint for implementing OAuth 2.0 grants, including grant management
      actions like updating and revoking grants.
    x-tag-expanded: false
  - name: Jose Object
    description: API endpoints for JOSE objects.
    x-tag-expanded: false
  - name: Device Flow
    description: API endpoints for implementing OAuth 2.0 Device Flow
    x-tag-expanded: false
  - name: Federation Endpoint
    description: API endpoints for implementing OpenID Federation using Authlete.
    x-tag-expanded: false
  - name: Verifiable Credential Issuer
    description: >-
      API endpoints for implementing and running a Verifiable Credential Issuer
      (VCI).
    x-tag-expanded: false
  - name: Hardware Security Key
    description: API endpoints for managing hardware security keys (HSK).
    x-tag-expanded: false
  - name: Utility Endpoints
    description: API endpoints for various utility operations.
    x-tag-expanded: false
  - name: Native SSO
    description: API endpoints for Native SSO
    x-tag-expanded: false
paths:
  /api/{serviceId}/auth/token/get/list:
    get:
      tags:
        - Token Operations
      summary: List Issued Tokens
      description: |
        Get the list of access tokens that are associated with the service.
      operationId: auth_token_get_list_api
      parameters:
        - in: path
          name: serviceId
          description: A service ID.
          schema:
            type: string
          required: true
        - in: query
          name: clientIdentifier
          schema:
            type: string
          required: false
          description: |
            Client Identifier (client ID or client ID alias).
        - in: query
          name: subject
          schema:
            type: string
          required: false
          description: |
            Unique user ID.
        - in: query
          name: start
          schema:
            type: integer
            format: int32
          required: false
          description: Start index of search results (inclusive). The default value is 0.
        - in: query
          name: end
          schema:
            type: integer
            format: int32
          required: false
          description: |
            End index of search results (exclusive). The default value is 5.
      responses:
        '200':
          description: ''
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/token_get_list_response'
              example:
                accessTokens:
                  - accessTokenExpiresAt: 1642048149000
                    accessTokenHash: tC5hpjGylLiiw-vsd5_tqVHtYSUHblAGimEJ-5xqAco
                    clientId: 26888344961664
                    createdAt: 1642044549000
                    grantType: AUTHORIZATION_CODE
                    lastRefreshedAt: 0
                    refreshTokenExpiresAt: 1642048149000
                    refreshTokenHash: jv4B_7_kpY-Rez_E7bYIxGYnZk43w18uigkaeUe6tc4
                    scopes:
                      - history.read
                    subject: john
                  - accessTokenExpiresAt: 1642051604000
                    accessTokenHash: Bk1QneTxkoLKw_RRB8ToVL25Plt075RvPK68N9cWWtg
                    clientId: 26888344961664
                    createdAt: 1642048004000
                    grantType: AUTHORIZATION_CODE
                    lastRefreshedAt: 0
                    refreshTokenExpiresAt: 1642051604000
                    refreshTokenHash: YHmwk4xETvoIJ_maWCpJDlpvmcFLkxmaaSS-v9KPng4
                    scopes:
                      - history.read
                      - openid
                      - timeline.read
                    subject: john
                  - accessTokenExpiresAt: 1642052094000
                    accessTokenHash: UUatYXjkqYFbRQlnItjq03DtUYA2MRRtuL88GCbQpbw
                    clientId: 26888344961664
                    createdAt: 1642048494000
                    grantType: AUTHORIZATION_CODE
                    lastRefreshedAt: 0
                    refreshTokenExpiresAt: 1642052094000
                    refreshTokenHash: wjc-IXoScxDiVyBmRrB92I-B0zMXSSKw_qwP_WK1lFM
                    scopes:
                      - history.read
                    subject: john
                client:
                  clientId: 26888344961664
                  clientIdAliasEnabled: false
                  clientName: My Device Flow Client
                  clientType: CONFIDENTIAL
                  number: 6260
                end: 3
                start: 0
                subject: john
                totalCount: 3
        '400':
          $ref: '#/components/responses/400'
        '401':
          $ref: '#/components/responses/401'
        '403':
          $ref: '#/components/responses/403'
        '500':
          $ref: '#/components/responses/500'
      x-codeSamples:
        - lang: typescript
          label: Typescript (SDK)
          source: |-
            import { Authlete } from "@authlete/typescript-sdk";

            const authlete = new Authlete({
              bearer: process.env["AUTHLETE_BEARER"] ?? "",
            });

            async function run() {
              const result = await authlete.token.management.list({
                serviceId: "<id>",
              });

              console.log(result);
            }

            run();
        - lang: ruby
          label: Ruby (SDK)
          source: |-
            require 'authlete_ruby_sdk'

            Models = ::Authlete::Models
            s = ::Authlete::Client.new(
              bearer: '<YOUR_BEARER_TOKEN_HERE>'
            )

            req = Models::Operations::AuthTokenGetListApiRequest.new(
              service_id: '<id>'
            )
            res = s.token_management.list(request: req)

            unless res.token_get_list_response.nil?
              # handle response
            end
        - lang: go
          label: Go (SDK)
          source: "package main\n\nimport(\n\t\"context\"\n\t\"os\"\n\tauthlete \"github.com/authlete/authlete-go-sdk\"\n\t\"github.com/authlete/authlete-go-sdk/models/operations\"\n\t\"log\"\n)\n\nfunc main() {\n    ctx := context.Background()\n\n    s := authlete.New(\n        authlete.WithSecurity(os.Getenv(\"AUTHLETE_BEARER\")),\n    )\n\n    res, err := s.Token.Management.List(ctx, operations.AuthTokenGetListAPIRequest{\n        ServiceID: \"<id>\",\n    })\n    if err != nil {\n        log.Fatal(err)\n    }\n    if res.TokenGetListResponse != nil {\n        // handle response\n    }\n}"
      x-code-samples:
        - lang: shell
          label: curl
          source: >
            curl -v
            https://us.authlete.com/api/21653835348762/auth/token/get/list/?clientIdentifier=26888344961664\&subject=john\&start=0\&end=3
            \

            -H 'Authorization: Bearer
            V5a40R6dWvw2gMkCOBFdZcM95q4HC0Z-T0YKD9-nR6F'
        - lang: java
          label: java
          source: |
            AuthleteConfiguration conf = ...;
            AuthleteApi api = AuthleteApiFactory.create(conf);

            String clientIdentifier = "26888344961664";
            String subject = "john";
            int start = 0;
            int end = 3;

            api.getTokenList(clientIdentifier, subject, start, end);
        - lang: python
          source: |
            conf = ...
            api = AuthleteApiImpl(conf)

            clientIdentifier = '26888344961664'
            subject = 'john'
            start = 0
            end = 3

            api.getTokenList(clientIdentifier, subject, start, end)
components:
  schemas:
    token_get_list_response:
      type: object
      properties:
        start:
          type: integer
          format: int32
          description: |
            Start index of search results (inclusive).
        end:
          type: integer
          format: int32
          description: |
            End index of search results (exclusive).
        totalCount:
          type: integer
          format: int32
          description: |
            Unique ID of a client developer.
        client:
          $ref: '#/components/schemas/client_limited'
        subject:
          type: string
          description: |
            Unique user ID of an end-user.
        accessTokens:
          type: array
          items:
            $ref: '#/components/schemas/access_token'
          description: |
            An array of access tokens.
    client_limited:
      type: object
      properties:
        number:
          type: integer
          format: int32
          readOnly: true
          description: >
            The sequential number of the client. The value of this property is
            assigned by Authlete.
        clientName:
          type: string
          description: >
            The name of the client application. This property corresponds to
            `client_name` in

            [OpenID Connect Dynamic Client Registration 1.0, 2. Client
            Metadata](https://openid.net/specs/openid-connect-registration-1_0.html#ClientMetadata).
        clientNames:
          type: array
          items:
            $ref: '#/components/schemas/tagged_value'
          description: >
            Client names with language tags. If the client application has
            different names for different

            languages, this property can be used to register the names.
        description:
          type: string
          description: The description about the client application.
        descriptions:
          type: array
          items:
            $ref: '#/components/schemas/tagged_value'
          description: >
            Descriptions about the client application with language tags. If the
            client application has different

            descriptions for different languages, this property can be used to
            register the descriptions.
        clientId:
          type: integer
          format: int64
          readOnly: true
          description: >-
            The client identifier used in Authlete API calls. The value of this
            property is assigned by Authlete.
        clientIdAlias:
          type: string
          description: >
            The value of the client's `client_id` property used in OAuth and
            OpenID Connect calls. By

            default, this is a string version of the `clientId` property.
        clientIdAliasEnabled:
          type: boolean
          description: Deprecated. Always set to `true`.
        clientType:
          $ref: '#/components/schemas/client_type'
    access_token:
      type: object
      properties:
        accessTokenHash:
          type: string
          description: The hash of the access token.
        accessTokenExpiresAt:
          type: integer
          format: int64
          description: The timestamp at which the access token will expire.
        refreshTokenHash:
          type: string
          description: The hash of the refresh token.
        refreshTokenExpiresAt:
          type: integer
          format: int64
          description: The timestamp at which the refresh token will expire.
        createdAt:
          type: integer
          format: int64
          description: |
            The timestamp at which the access token was first created.
        lastRefreshedAt:
          type: integer
          format: int64
          description: >
            The timestamp at which the access token was last refreshed using the
            refresh token.
        clientId:
          type: integer
          format: int64
          description: |
            The ID of the client associated with the access token.
        subject:
          type: string
          description: |
            The subject (= unique user ID) associated with the access token.
        grantType:
          $ref: '#/components/schemas/grant_type'
        scopes:
          type: array
          items:
            type: string
          description: |
            The scopes associated with the access token.
        properties:
          type: array
          items:
            $ref: '#/components/schemas/property'
          description: |
            The properties associated with the access token.
        refreshTokenScopes:
          type: array
          items:
            type: string
          description: |
            The scopes associated with the refresh token.
    result:
      type: object
      properties:
        resultCode:
          type: string
          description: The code which represents the result of the API call.
        resultMessage:
          type: string
          description: A short message which explains the result of the API call.
    tagged_value:
      type: object
      properties:
        tag:
          type: string
          description: The language tag part.
        value:
          type: string
          description: The value part.
    client_type:
      type: string
      description: >
        The client type, either `CONFIDENTIAL` or `PUBLIC`. See [RFC 6749, 2.1.
        Client Types](https://datatracker.ietf.org/doc/html/rfc6749#section-2.1)

        for details.
      enum:
        - PUBLIC
        - CONFIDENTIAL
    grant_type:
      type: string
      description: |
        The grant type of the access token when the access token was created.
      enum:
        - AUTHORIZATION_CODE
        - IMPLICIT
        - PASSWORD
        - CLIENT_CREDENTIALS
        - REFRESH_TOKEN
        - CIBA
        - DEVICE_CODE
        - TOKEN_EXCHANGE
        - JWT_BEARER
        - PRE_AUTHORIZED_CODE
    property:
      type: object
      properties:
        key:
          type: string
          description: The key part.
        value:
          type: string
          description: The value part.
        hidden:
          type: boolean
          description: >
            The flag to indicate whether this property hidden from or visible to
            client applications.

            If `true`, this property is hidden from client applications.
            Otherwise, this property is visible to client applications.
  responses:
    '400':
      description: ''
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/result'
          example:
            resultCode: A001201
            resultMessage: '[A001201] /auth/authorization, TLS must be used.'
    '401':
      description: ''
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/result'
          example:
            resultCode: A001202
            resultMessage: '[A001202] /auth/authorization, Authorization header is missing.'
    '403':
      description: ''
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/result'
          example:
            resultCode: A001215
            resultMessage: >-
              [A001215] /auth/authorization, The client (ID = 26837717140341) is
              locked.
    '500':
      description: ''
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/result'
          example:
            resultCode: A001101
            resultMessage: '[A001101] /auth/authorization, Authlete Server error.'
  securitySchemes:
    bearer:
      type: http
      scheme: bearer
      bearerFormat: JWT
      description: >
        Authenticate every request with a **Service Access Token** or
        **Organization Token**.

        Set the token value in the `Authorization: Bearer <token>` header.


        **Service Access Token**: Scoped to a single service. Use when
        automating service-level configuration or runtime flows.


        **Organization Token**: Scoped to the organization; inherits permissions
        across services. Use for org-wide automation or when managing multiple
        services programmatically.


        Both token types are issued by the Authlete console or provisioning
        APIs.

````