> For the complete documentation index, see [llms.txt](https://docs.defguard.net/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.defguard.net/2.1/for-developers/rest-api/core/api-token/list-api-tokens-of-a-user.md).

# List API tokens of a user

Token values are never returned, only their metadata.

```json
{"openapi":"3.1.0","info":{"title":"defguard Core API","version":"2.1.0"},"tags":[{"name":"API token","description":"API tokens used for `Authorization: Bearer` authentication."}],"security":[{"cookie":[]},{"api_token":[]}],"components":{"securitySchemes":{"cookie":{"type":"apiKey","in":"cookie","name":"defguard_session"},"api_token":{"type":"http","scheme":"bearer"}},"schemas":{"ApiTokenInfo":{"type":"object","required":["id","name","created_at"],"properties":{"created_at":{"type":"string","format":"date-time"},"id":{"$ref":"#/components/schemas/i64"},"name":{"type":"string"}}},"i64":{"type":"integer","format":"int64"},"ApiErrorResponse":{"type":"object","description":"Body returned with error responses.","required":["msg"],"properties":{"code":{"type":["string","null"],"description":"Machine-readable error code, returned for selected errors."},"msg":{"type":"string","description":"Human-readable error message."}}}}},"paths":{"/api/v1/user/{username}/api_token":{"get":{"tags":["API token"],"summary":"List API tokens of a user","description":"Token values are never returned, only their metadata.","operationId":"fetch_api_tokens","parameters":[{"name":"username","in":"path","description":"Name of the user.","required":true,"schema":{"type":"string"}}],"responses":{"200":{"description":"All API tokens of the user.","content":{"application/json":{"schema":{"type":"array","items":{"$ref":"#/components/schemas/ApiTokenInfo"}}}}},"401":{"description":"Session is missing or invalid.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/ApiErrorResponse"}}}},"403":{"description":"Requires admin privileges and an active enterprise license.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/ApiErrorResponse"}}}},"404":{"description":"User not found.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/ApiErrorResponse"}}}},"500":{"description":"Unable to list API tokens.","content":{"application/json":{"schema":{"$ref":"#/components/schemas/ApiErrorResponse"}}}}}}}}}
```
