---
title: List Tokens
---

[Skip to content](#_top)

[API Reference](https://developers.cloudflare.com/api/go)

[User](https://developers.cloudflare.com/api/go/resources/user)

[Tokens](https://developers.cloudflare.com/api/go/resources/user/subresources/tokens)

Copy Markdown

Open in **Claude**Open in **ChatGPT**Open in **Cursor**

---

**Copy Markdown****View as Markdown**

# List Tokens

client.User.Tokens.List(ctx, query) (\*V4PagePaginationArray\[[Token](<https://developers.cloudflare.com/api/go/resources/$shared#(resource)%20%24shared%20%3E%20(model)%20token%20%3E%20(schema)>)], error)

GET/user/tokens

List all access tokens you created. Results include active, disabled, and recently-expired tokens when include\_expired is set to true.

##### Security

API Token

The preferred authorization scheme for interacting with the Cloudflare API. [Create a token](https://developers.cloudflare.com/fundamentals/api/get-started/create-token/).

**Example:**`Authorization: Bearer Sn3lZJTBX6kkg7OdcBUAxOO963GEIyGQqnFTOFYY`

##### Accepted Permissions (at least one required)

`API Tokens Write``API Tokens Read`

##### ParametersExpand Collapse

<details>

<summary>

query TokenListParams

</summary>

<details>

<summary>

Direction param.Field\[<a href="https://developers.cloudflare.com/api/go/resources/user/subresources/tokens/methods/list#(resource)%20user.tokens%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20direction%20%3E%20(schema)">TokenListParamsDirection</a>]Optional

Direction to order results.

</summary>

const TokenListParamsDirectionAsc <a href="https://developers.cloudflare.com/api/go/resources/user/subresources/tokens/methods/list#(resource)%20user.tokens%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20direction%20%3E%20(schema)">TokenListParamsDirection</a> = "asc"

<a href="#(resource)%20user.tokens%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20direction%20%3E%20(schema)%20%3E%20(member)%200">Link to this property</a>

const TokenListParamsDirectionDesc <a href="https://developers.cloudflare.com/api/go/resources/user/subresources/tokens/methods/list#(resource)%20user.tokens%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20direction%20%3E%20(schema)">TokenListParamsDirection</a> = "desc"

<a href="#(resource)%20user.tokens%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20direction%20%3E%20(schema)%20%3E%20(member)%201">Link to this property</a>

</details>

<a href="#(resource)%20user.tokens%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20direction">Link to this property</a>

IncludeExpired param.Field\[bool]Optional

When true, includes recently-expired tokens in the response.

<a href="#(resource)%20user.tokens%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20include_expired">Link to this property</a>

Page param.Field\[float64]Optional

Page number of paginated results.

minimum1

<a href="#(resource)%20user.tokens%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20page">Link to this property</a>

PerPage param.Field\[float64]Optional

Maximum number of results per page.

maximum50

minimum5

<a href="#(resource)%20user.tokens%20%3E%20(method)%20list%20%3E%20(params)%20default%20%3E%20(param)%20per_page">Link to this property</a>

</details>

[Link to this property](<#(resource)%20user.tokens%20%3E%20(method)%20list%20%3E%20(params)%20default>)

##### ReturnsExpand Collapse

<details>

<summary>

type Token struct{…}

</summary>

ID stringOptional

Token identifier tag.

maxLength32

<a href="#(resource)%20%24shared%20%3E%20(model)%20token%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

<details>

<summary>

Condition TokenConditionOptional

</summary>

<details>

<summary>

RequestIP TokenConditionRequestIPOptional

Client IP restrictions.

</summary>

In \[]<a href="https://developers.cloudflare.com/api/go/resources/$shared#(resource)%20%24shared%20%3E%20(model)%20token_condition_cidr_list%20%3E%20(schema)">TokenConditionCIDRList</a>Optional

List of IPv4/IPv6 CIDR addresses.

<a href="#(resource)%20%24shared%20%3E%20(model)%20token%20%3E%20(schema)%20%3E%20(property)%20condition%20%3E%20(property)%20request_ip%20%3E%20(property)%20in">Link to this property</a>

NotIn \[]<a href="https://developers.cloudflare.com/api/go/resources/$shared#(resource)%20%24shared%20%3E%20(model)%20token_condition_cidr_list%20%3E%20(schema)">TokenConditionCIDRList</a>Optional

List of IPv4/IPv6 CIDR addresses.

<a href="#(resource)%20%24shared%20%3E%20(model)%20token%20%3E%20(schema)%20%3E%20(property)%20condition%20%3E%20(property)%20request_ip%20%3E%20(property)%20not_in">Link to this property</a>

</details>

<a href="#(resource)%20%24shared%20%3E%20(model)%20token%20%3E%20(schema)%20%3E%20(property)%20condition%20%3E%20(property)%20request_ip">Link to this property</a>

</details>

<a href="#(resource)%20%24shared%20%3E%20(model)%20token%20%3E%20(schema)%20%3E%20(property)%20condition">Link to this property</a>

CreatorEmailAtCreation stringOptional

The email address of the user who created the token at the time of creation. Only present for Account Owned API Tokens when a creator email was available.

maxLength90

<a href="#(resource)%20%24shared%20%3E%20(model)%20token%20%3E%20(schema)%20%3E%20(property)%20creator_email_at_creation">Link to this property</a>

ExpiresOn TimeOptional

The expiration time on or after which the JWT MUST NOT be accepted for processing.

formatdate-time

<a href="#(resource)%20%24shared%20%3E%20(model)%20token%20%3E%20(schema)%20%3E%20(property)%20expires_on">Link to this property</a>

IssuedOn TimeOptional

The time on which the token was created.

formatdate-time

<a href="#(resource)%20%24shared%20%3E%20(model)%20token%20%3E%20(schema)%20%3E%20(property)%20issued_on">Link to this property</a>

LastUsedOn TimeOptional

Last time the token was used.

formatdate-time

<a href="#(resource)%20%24shared%20%3E%20(model)%20token%20%3E%20(schema)%20%3E%20(property)%20last_used_on">Link to this property</a>

ModifiedOn TimeOptional

Last time the token was modified.

formatdate-time

<a href="#(resource)%20%24shared%20%3E%20(model)%20token%20%3E%20(schema)%20%3E%20(property)%20modified_on">Link to this property</a>

Name stringOptional

Token name.

maxLength120

<a href="#(resource)%20%24shared%20%3E%20(model)%20token%20%3E%20(schema)%20%3E%20(property)%20name">Link to this property</a>

NotBefore TimeOptional

The time before which the token MUST NOT be accepted for processing.

formatdate-time

<a href="#(resource)%20%24shared%20%3E%20(model)%20token%20%3E%20(schema)%20%3E%20(property)%20not_before">Link to this property</a>

<details>

<summary>

Policies \[]<a href="https://developers.cloudflare.com/api/go/resources/$shared#(resource)%20%24shared%20%3E%20(model)%20token_policy%20%3E%20(schema)">TokenPolicy</a>Optional

List of access policies assigned to the token.

</summary>

ID string

Policy identifier.

<a href="#(resource)%20%24shared%20%3E%20(model)%20token_policy%20%3E%20(schema)%20%3E%20(property)%20id">Link to this property</a>

<details>

<summary>

Effect TokenPolicyEffect

Allow or deny operations against the resources.

</summary>

One of the following:

const TokenPolicyEffectAllow TokenPolicyEffect = "allow"

<a href="#(resource)%20%24shared%20%3E%20(model)%20token_policy%20%3E%20(schema)%20%3E%20(property)%20effect%20%3E%20(member)%200">Link to this property</a>

const TokenPolicyEffectDeny TokenPolicyEffect = "deny"

<a href="#(resource)%20%24shared%20%3E%20(model)%20token_policy%20%3E%20(schema)%20%3E%20(property)%20effect%20%3E%20(member)%201">Link to this property</a>

</details>

<a href="#(resource)%20%24shared%20%3E%20(model)%20token_policy%20%3E%20(schema)%20%3E%20(property)%20effect">Link to this property</a>

<details>

<summary>

PermissionGroups \[]TokenPolicyPermissionGroup

A set of permission groups that are specified to the policy.

</summary>

ID string

Identifier of the permission group.

<a href="#(resource)%20%24shared%20%3E%20(model)%20token_policy%20%3E%20(schema)%20%3E%20(property)%20permission_groups%20%3E%20(items)%20%3E%20(property)%20id">Link to this property</a>

<details>

<summary>

Meta TokenPolicyPermissionGroupsMetaOptional

Attributes associated to the permission group.

</summary>

Category stringOptional

A category used to group permission groups.

<a href="#(resource)%20%24shared%20%3E%20(model)%20token_policy%20%3E%20(schema)%20%3E%20(property)%20permission_groups%20%3E%20(items)%20%3E%20(property)%20meta%20%3E%20(property)%20category">Link to this property</a>

Deprecated stringOptional

Indicates whether the permission group is deprecated.

<a href="#(resource)%20%24shared%20%3E%20(model)%20token_policy%20%3E%20(schema)%20%3E%20(property)%20permission_groups%20%3E%20(items)%20%3E%20(property)%20meta%20%3E%20(property)%20deprecated">Link to this property</a>

Description stringOptional

Additional information about the permission group.

<a href="#(resource)%20%24shared%20%3E%20(model)%20token_policy%20%3E%20(schema)%20%3E%20(property)%20permission_groups%20%3E%20(items)%20%3E%20(property)%20meta%20%3E%20(property)%20description">Link to this property</a>

Editable stringOptional

Indicates whether the permission group can be edited.

<a href="#(resource)%20%24shared%20%3E%20(model)%20token_policy%20%3E%20(schema)%20%3E%20(property)%20permission_groups%20%3E%20(items)%20%3E%20(property)%20meta%20%3E%20(property)%20editable">Link to this property</a>

EolAt TimeOptional

The planned end-of-life date and time, when provided.

formatdate-time

<a href="#(resource)%20%24shared%20%3E%20(model)%20token_policy%20%3E%20(schema)%20%3E%20(property)%20permission_groups%20%3E%20(items)%20%3E%20(property)%20meta%20%3E%20(property)%20eol_at">Link to this property</a>

Label stringOptional

A label identifying the permission group.

<a href="#(resource)%20%24shared%20%3E%20(model)%20token_policy%20%3E%20(schema)%20%3E%20(property)%20permission_groups%20%3E%20(items)%20%3E%20(property)%20meta%20%3E%20(property)%20label">Link to this property</a>

Scopes stringOptional

The scope associated with the permission group.

<a href="#(resource)%20%24shared%20%3E%20(model)%20token_policy%20%3E%20(schema)%20%3E%20(property)%20permission_groups%20%3E%20(items)%20%3E%20(property)%20meta%20%3E%20(property)%20scopes">Link to this property</a>

Visibility stringOptional

Indicates the permission group’s availability or visibility.

<a href="#(resource)%20%24shared%20%3E%20(model)%20token_policy%20%3E%20(schema)%20%3E%20(property)%20permission_groups%20%3E%20(items)%20%3E%20(property)%20meta%20%3E%20(property)%20visibility">Link to this property</a>

</details>

<a href="#(resource)%20%24shared%20%3E%20(model)%20token_policy%20%3E%20(schema)%20%3E%20(property)%20permission_groups%20%3E%20(items)%20%3E%20(property)%20meta">Link to this property</a>

Name stringOptional

Name of the permission group.

<a href="#(resource)%20%24shared%20%3E%20(model)%20token_policy%20%3E%20(schema)%20%3E%20(property)%20permission_groups%20%3E%20(items)%20%3E%20(property)%20name">Link to this property</a>

</details>

<a href="#(resource)%20%24shared%20%3E%20(model)%20token_policy%20%3E%20(schema)%20%3E%20(property)%20permission_groups">Link to this property</a>

<details>

<summary>

Resources TokenPolicyResourcesUnion

A list of resource names that the policy applies to.

</summary>

One of the following:

type TokenPolicyResourcesIAMResourcesTypeObjectString map\[string, string]

Map of simple string resource permissions

<a href="#(resource)%20%24shared%20%3E%20(model)%20token_policy%20%3E%20(schema)%20%3E%20(property)%20resources%20%3E%20(variant)%200">Link to this property</a>

type TokenPolicyResourcesIAMResourcesTypeObjectNested map\[string, map\[string, string]]

Map of nested resource permissions

<a href="#(resource)%20%24shared%20%3E%20(model)%20token_policy%20%3E%20(schema)%20%3E%20(property)%20resources%20%3E%20(variant)%201">Link to this property</a>

</details>

<a href="#(resource)%20%24shared%20%3E%20(model)%20token_policy%20%3E%20(schema)%20%3E%20(property)%20resources">Link to this property</a>

</details>

<a href="#(resource)%20%24shared%20%3E%20(model)%20token%20%3E%20(schema)%20%3E%20(property)%20policies">Link to this property</a>

ProvisionerID stringOptional

The identifier of the service that provisioned the token. For an OAuth-provisioned token, this is the OAuth client identifier. Present when <code>provisioner_type</code> is present and null when the identifier is unavailable.

<a href="#(resource)%20%24shared%20%3E%20(model)%20token%20%3E%20(schema)%20%3E%20(property)%20provisioner_id">Link to this property</a>

ProvisionerType stringOptional

The type of service that provisioned the token. Only present for provisioned Account Owned API Tokens.

<a href="#(resource)%20%24shared%20%3E%20(model)%20token%20%3E%20(schema)%20%3E%20(property)%20provisioner_type">Link to this property</a>

<details>

<summary>

Status TokenStatusOptional

Status of the token.

</summary>

One of the following:

const TokenStatusActive TokenStatus = "active"

<a href="#(resource)%20%24shared%20%3E%20(model)%20token%20%3E%20(schema)%20%3E%20(property)%20status%20%3E%20(member)%200">Link to this property</a>

const TokenStatusDisabled TokenStatus = "disabled"

<a href="#(resource)%20%24shared%20%3E%20(model)%20token%20%3E%20(schema)%20%3E%20(property)%20status%20%3E%20(member)%201">Link to this property</a>

const TokenStatusExpired TokenStatus = "expired"

<a href="#(resource)%20%24shared%20%3E%20(model)%20token%20%3E%20(schema)%20%3E%20(property)%20status%20%3E%20(member)%202">Link to this property</a>

</details>

<a href="#(resource)%20%24shared%20%3E%20(model)%20token%20%3E%20(schema)%20%3E%20(property)%20status">Link to this property</a>

</details>

[Link to this property](<#(resource)%20%24shared%20%3E%20(model)%20token%20%3E%20(schema)>)

### List Tokens

Go

HTTPTypeScriptPythonGoTerraform

```
package main

import (
  "context"
  "fmt"

  "github.com/cloudflare/cloudflare-go"
  "github.com/cloudflare/cloudflare-go/option"
  "github.com/cloudflare/cloudflare-go/user"
)

func main() {
  client := cloudflare.NewClient(
    option.WithAPIToken("Sn3lZJTBX6kkg7OdcBUAxOO963GEIyGQqnFTOFYY"),
  )
  page, err := client.User.Tokens.List(context.TODO(), user.TokenListParams{

  })
  if err != nil {
    panic(err.Error())
  }
  fmt.Printf("%+v\n", page)
}
```

200 example

```
{
  "errors": [
    {
      "code": 1000,
      "message": "message",
      "documentation_url": "documentation_url",
      "source": {
        "pointer": "pointer"
      }
    }
  ],
  "messages": [
    {
      "code": 1000,
      "message": "message",
      "documentation_url": "documentation_url",
      "source": {
        "pointer": "pointer"
      }
    }
  ],
  "success": true,
  "result": [
    {
      "id": "ed17574386854bf78a67040be0a770b0",
      "condition": {
        "request_ip": {
          "in": [
            "123.123.123.0/24",
            "2606:4700::/32"
          ],
          "not_in": [
            "123.123.123.100/24",
            "2606:4700:4700::/48"
          ]
        }
      },
      "creator_email_at_creation": "user@example.com",
      "expires_on": "2020-01-01T00:00:00Z",
      "issued_on": "2018-07-01T05:20:00Z",
      "last_used_on": "2020-01-02T12:34:00Z",
      "modified_on": "2018-07-02T05:20:00Z",
      "name": "readonly token",
      "not_before": "2018-07-01T05:20:00Z",
      "policies": [
        {
          "id": "f267e341f3dd4697bd3b9f71dd96247f",
          "effect": "allow",
          "permission_groups": [
            {
              "id": "c8fed203ed3043cba015a93ad1616f1f",
              "meta": {
                "category": "category",
                "deprecated": "deprecated",
                "description": "description",
                "editable": "editable",
                "eol_at": "2019-12-27T18:11:19.117Z",
                "label": "load_balancer_admin",
                "scopes": "com.cloudflare.api.account",
                "visibility": "visibility"
              },
              "name": "Zone Read"
            },
            {
              "id": "82e64a83756745bbbb1c9c2701bf816b",
              "meta": {
                "category": "category",
                "deprecated": "deprecated",
                "description": "description",
                "editable": "editable",
                "eol_at": "2019-12-27T18:11:19.117Z",
                "label": "fbm_user",
                "scopes": "com.cloudflare.api.account",
                "visibility": "visibility"
              },
              "name": "Magic Network Monitoring"
            }
          ],
          "resources": {
            "com.cloudflare.api.account.zone.22b1de5f1c0e4b3ea97bb1e963b06a43": "*"
          }
        }
      ],
      "provisioner_id": "a1b2c3d4e5f6a1b2c3d4e5f6a1b2c3d4",
      "provisioner_type": "com.cloudflare.api.oauthtoken",
      "status": "active"
    }
  ],
  "result_info": {
    "count": 1,
    "page": 1,
    "per_page": 20,
    "total_count": 2000
  }
}
```

##### Returns Examples

200 example

```
{
  "errors": [
    {
      "code": 1000,
      "message": "message",
      "documentation_url": "documentation_url",
      "source": {
        "pointer": "pointer"
      }
    }
  ],
  "messages": [
    {
      "code": 1000,
      "message": "message",
      "documentation_url": "documentation_url",
      "source": {
        "pointer": "pointer"
      }
    }
  ],
  "success": true,
  "result": [
    {
      "id": "ed17574386854bf78a67040be0a770b0",
      "condition": {
        "request_ip": {
          "in": [
            "123.123.123.0/24",
            "2606:4700::/32"
          ],
          "not_in": [
            "123.123.123.100/24",
            "2606:4700:4700::/48"
          ]
        }
      },
      "creator_email_at_creation": "user@example.com",
      "expires_on": "2020-01-01T00:00:00Z",
      "issued_on": "2018-07-01T05:20:00Z",
      "last_used_on": "2020-01-02T12:34:00Z",
      "modified_on": "2018-07-02T05:20:00Z",
      "name": "readonly token",
      "not_before": "2018-07-01T05:20:00Z",
      "policies": [
        {
          "id": "f267e341f3dd4697bd3b9f71dd96247f",
          "effect": "allow",
          "permission_groups": [
            {
              "id": "c8fed203ed3043cba015a93ad1616f1f",
              "meta": {
                "category": "category",
                "deprecated": "deprecated",
                "description": "description",
                "editable": "editable",
                "eol_at": "2019-12-27T18:11:19.117Z",
                "label": "load_balancer_admin",
                "scopes": "com.cloudflare.api.account",
                "visibility": "visibility"
              },
              "name": "Zone Read"
            },
            {
              "id": "82e64a83756745bbbb1c9c2701bf816b",
              "meta": {
                "category": "category",
                "deprecated": "deprecated",
                "description": "description",
                "editable": "editable",
                "eol_at": "2019-12-27T18:11:19.117Z",
                "label": "fbm_user",
                "scopes": "com.cloudflare.api.account",
                "visibility": "visibility"
              },
              "name": "Magic Network Monitoring"
            }
          ],
          "resources": {
            "com.cloudflare.api.account.zone.22b1de5f1c0e4b3ea97bb1e963b06a43": "*"
          }
        }
      ],
      "provisioner_id": "a1b2c3d4e5f6a1b2c3d4e5f6a1b2c3d4",
      "provisioner_type": "com.cloudflare.api.oauthtoken",
      "status": "active"
    }
  ],
  "result_info": {
    "count": 1,
    "page": 1,
    "per_page": 20,
    "total_count": 2000
  }
}
```