# List your API access tokens {#top}

**Read** · `GET /v1/access-tokens` · MCP tool `list-access-tokens`

Shows every access token created from your login: its ID, its label, when it was created, when it expires and whether it was revoked. The tokens themselves are never shown. You need to be signed in with a session to list them.

Roles that can call it: `viewer`, `builder`, `deployer`.

## Parameters

This operation takes no parameters.

## Returns

A JSON object with these keys: `access_tokens`, `login`, `guarantee`, `caller_authenticated`.

## Example request

```sh
curl https://api.tarsana.io/v1/access-tokens \
  -H "X-Tarsana-Session: $SESSION"
```

## Example response

```json
{
  "access_tokens": [
    {
      "id": "67e94a06c977c24c",
      "token_label": "laptop-mcp",
      "login": "you@example.com",
      "issued_at": "2026-10-05T02:15:39Z",
      "expires_at": "2027-01-03T02:15:39Z",
      "revoked": false,
      "revoked_at": null
    }
  ],
  "login": "you@example.com",
  "guarantee": "namespaces are separated, callers are not authenticated",
  "caller_authenticated": false
}
```

## Errors

| Code | HTTP | What it means |
|---|---|---|
| [`unauthenticated`](/api/errors#unauthenticated) | 401 | Your request has no credential, or one that Tarsana does not recognise. Sign in with `login`, or send a valid access token. |
| [`forbidden`](/api/errors#forbidden) | 403 | Your role does not allow this operation. The response names the roles that do; ask for a credential with one of them. |
| [`rate_limited`](/api/errors#rate_limited) | 429 | You sent too many requests in a short time. Wait for the number of seconds in `retry_after_seconds`, then try again. |
| [`surface_fault`](/api/errors#surface_fault) | 500 | Something went wrong on our side. Try again later, and contact Tarsana support if it keeps happening. |
