# List device tokens

> Every token minted for the device, active and revoked, newest first. Each carries its prefix, name, status and last use — what you need to tell tokens apart and decide which to revoke. The secret itself is never returned after the token is minted.

Source: https://docs.xplantpro.com/docs/api/devices/list-device-tokens

`GET https://app.xplantpro.com/api/v1/devices/{deviceId}/tokens`

- Required scope: `read:devices`
- Credentials: workspace API key (`xpk_`)
- Idempotency-Key: ignored on this endpoint

Pages hold up to 200 tokens by default; follow `meta.next_cursor` until it comes back `null` to be sure you have them all.

## Path parameters

| Name | Type | Required | Description |
| --- | --- | --- | --- |
| `deviceId` | string (uuid) | Yes | The device's id. |

## Query parameters

| Name | Type | Required | Description |
| --- | --- | --- | --- |
| `limit` | integer | No | Page size. Values above 200 are capped at 200. Default `200`. From 1 to 200. |
| `offset` | integer | No | Number of records to skip. Prefer `cursor` where a list offers it: an offset shifts when records are added ahead of it. Default `0`. At least 0. |
| `cursor` | string | No | Continue from the previous page: pass its `meta.next_cursor` unchanged, with the same filters. Treat it as opaque. Not combinable with `offset`. Up to 2048 characters. |

## Example

**curl**

```bash
curl https://app.xplantpro.com/api/v1/devices/5f7a9c1e-3b5d-4f7a-9c1e-3b5d7f9a1c3e/tokens \
  -H "Authorization: Bearer $XPLANT_API_KEY"
```

**JavaScript**

```js
import { XPlantClient } from "@shmaplex/xplant-sdk";

const client = new XPlantClient({ apiKey: process.env.XPLANT_API_KEY });

const tokens = await client.devices.listTokens("5f7a9c1e-3b5d-4f7a-9c1e-3b5d7f9a1c3e");
```

**Python**

```python
import os
import requests

resp = requests.get(
    "https://app.xplantpro.com/api/v1/devices/5f7a9c1e-3b5d-4f7a-9c1e-3b5d7f9a1c3e/tokens",
    headers={"Authorization": f"Bearer {os.environ['XPLANT_API_KEY']}"},
    timeout=10,
)
body = resp.json()
if not body["ok"]:
    raise RuntimeError(f"{resp.status_code} {body['code']}: {body['error']}")
tokens = body["data"]
```

## Response

`200` with `{ "ok": true, "data": … }`. `data` is an array. To get the next page, pass `meta.next_cursor` back as `cursor`; it is `null` on the last page. See [Pagination](https://docs.xplantpro.com/docs/pagination.md).

| Field | Type | Required | Description |
| --- | --- | --- | --- |
| `id` | string (uuid) | Yes | — |
| `deviceId` | string (uuid) | Yes | The device the token belongs to. |
| `name` | string \| null | Yes | The label it was given when it was minted. |
| `prefix` | string | Yes | The first characters of the token — enough to recognise it, never enough to use it. |
| `status` | string | Yes | `active`, or `revoked` once it can no longer be used. |
| `lastUsedAt` | string \| null | Yes | When the token last authenticated a request, as an ISO 8601 timestamp. Null if never. |
| `revokedAt` | string \| null | Yes | When the token was revoked, as an ISO 8601 timestamp. Null while it is active. |
| `createdAt` | string | Yes | When the token was minted. |

```json title="Response"
{
  "ok": true,
  "data": [
    {
      "id": "4f8a2c6e-9d1b-4e7a-b3c5-6a0d8f2e4b19",
      "deviceId": "8e3b1f52-6c0d-4a7e-9b21-5f4d8c2a7e13",
      "name": "Grow room Pi",
      "prefix": "xpd_live_0123456789a",
      "status": "active",
      "lastUsedAt": "2026-09-25T14:05:00.000Z",
      "revokedAt": null,
      "createdAt": "2026-09-01T09:40:00.000Z"
    }
  ]
}
```

The envelope can also carry `meta`:

| Field | Type | Required | Description |
| --- | --- | --- | --- |
| `next_cursor` | string \| null | Yes | Pass as `cursor` to fetch the next page. `null` means this is the last page. |

| Response header | Meaning |
| --- | --- |
| `X-Request-Id` | Identifies this request. Include it when you contact support. |

## Errors

| Status | Code | When |
| --- | --- | --- |
| `401` | `UNAUTHORIZED` | The key is missing, malformed or revoked, or its owner is no longer a member of the workspace. |
| `402` | `PAID_PLAN_REQUIRED` | The workspace has no paid plan. Connecting devices is included with every paid plan. |
| `403` | `FORBIDDEN` | The key lacks a scope this operation requires, or its owner's current role in the workspace cannot use it — a key never does more than its owner can in xPlant. `error` names the scope, and for a role, the role it needs. |
| `403` | `DEVICE_TOKEN_NOT_ACCEPTED` | A device token was sent; this operation needs a workspace API key. |
| `404` | `NOT_FOUND` | No device with this id is registered in the key's workspace. |
| `422` | `VALIDATION_ERROR` | Both `cursor` and `offset` were sent; use one. |
| `422` | `INVALID_CURSOR` | The cursor is malformed, or came from a different list or different filters. Start again without it. |
| `429` | `RATE_LIMIT_EXCEEDED` | Too many requests for this key, device token or workspace. Wait `Retry-After` seconds. |
| `500` | `DEVICE_TOKEN_QUERY_FAILED` | The tokens could not be read. Retry later. |

Branch on `code`, never on the `error` text. See [Errors](https://docs.xplantpro.com/docs/errors.md).
