List personal access tokens
List the calling user’s personal access tokens. Each entry carries its id, label, scopes, derived status (active, revoked, or expired), and timestamps. Token plaintext is never returned. Only the account owner may list their tokens — from the Sumvin app or the CLI. Anything acting on their behalf is refused.
Authorizations
JWT issued by Dynamic Labs or Privy. Sent in the x-juno-jwt header on every authenticated request.
Headers
Tenant org ID for multi-tenant auth
Controls how timestamp fields are serialized in JSON response bodies.
Default (header omitted or any other value): epoch milliseconds as integers.
iso8601: UTC ISO 8601 strings of the form YYYY-MM-DDTHH:MM:SSZ.
Example: with X-Timestamp-Format: iso8601, the field value 1704067200000 becomes "2024-01-01T00:00:00Z".
Affected fields (recursively, in dicts and arrays): any field whose name ends in _at, plus the literal field names timestamp, period_start, and period_end. All other fields are passed through unchanged.
Only iso8601 is recognized. Any other value (or omitting the header) yields the default epoch-ms representation; the server does not reject unknown values, so this is documented as an example rather than an enum to keep generated clients permissive.
"iso8601"
Query Parameters
Pagination offset
x >= 0Pagination limit
1 <= x <= 100Response
Tokens retrieved
Paginated list of the caller's personal access tokens.
HAL-style hypermedia links for navigation and available actions.
Page of personal access tokens.
Number of items skipped from the beginning of the result set.
Maximum number of items returned per page (1-100).
Total number of items across all pages.