Skip to content

List a repository's deploy keys, oldest first: SSH keys that reach this one repository, for a server or a pipeline.

GET/repos/{owner}/{name}/keys

Each has its id (dk_…), title, public key, fingerprint (SHA256:…), read_only (false when it may push), created_at, created_by (who added it) and last_used_at (null when it never signed in). Needs the Admin role on the repository; agents’ tokens are refused.

Oldest first. read_only false means the key may push, workflow files included. last_used_at is when it last signed in over SSH, to within 5 minutes, and null when it never has. Refused with 403 without the Admin role, and for an agent’s token or a workspace token without Admin; 404 for a private repository you cannot see. See Deploy keys.

  • Authentication: Required. Send an access token as Authorization: Bearer.
  • MCP tool: access with action list_deploy_keys, and the same inputs
  • Scope: An access token needs access:read.
Name Type Required Description
owner string Yes The workspace that owns the repository.
name string Yes The repository’s name.
curl https://api.g1t.sh/repos/flagon-io/hello/keys \
-H "Authorization: Bearer $G1T_TOKEN"

A successful request answers 200 with:

[
{
"id": "dk_01kp3f2g3h4j5k6m7n8p9q0r1s",
"title": "Docs build",
"key": "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIGb9ECWmEzf6FQbrBZ9w7lshQhqowtrbLDFw4rXAxZuE",
"fingerprint": "SHA256:ubxEl41fJDnUoEPKSZE0y6R0ZjjAQf/wV5vZgeBV8qk",
"read_only": true,
"created_at": "2026-10-06T09:12:00.000Z",
"created_by": "syntaqx",
"last_used_at": "2026-10-08T07:40:00.000Z"
},
{
"id": "dk_01kp3g4h5j6k7m8n9p0q1r2s3t",
"title": "Release bot",
"key": "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIJ8Vq2nLr5Xw0sT3yK7mP1cH4dF6gB9aE2uZ5oN8iR0j",
"fingerprint": "SHA256:2h7VyLkcqBHwKVtfFUchGsE5pDwpgBPV/VvJgYiS27M",
"read_only": false,
"created_at": "2026-10-07T15:30:00.000Z",
"created_by": "syntaqx",
"last_used_at": null
}
]

A failed request answers with one of these statuses and a body like {"error": {"code": "not_found", "message": "Repository not found."}}. See errors.

Status Code When
401 unauthenticated A token is required, or the one sent is not valid.
403 forbidden The token is valid but not allowed to do this, such as a member-only change or an agent token outside its repository.
404 not_found It does not exist, or you cannot see it.
422 invalid The input is not valid. message says which field and why.