Skip to main content
GET
Get Project Key

Authorizations

Authorization
string
header
required

Bearer authentication header of the form Bearer <token>, where <token> is your auth token.

Path Parameters

project_key_id
string
required

Response

Successful Response

Detail response for GET /project-keys/{id} - includes Kafka ACLs, whitelist IPs, and proxy endpoints.

id
string
required
name
string
required
service_id
string
required
status
string
required
description
string | null
created_at
string<date-time> | null
created_by_user
User · object | null
api_client_id
string | null
api_client_id_masked_secret
string | null
kafka_username
string | null
roles
Role · object[]
last_used_at
string<date-time> | null
tool_profile
enum<string> | null
Available options:
full,
read-only,
agent-operator,
infra-admin
allowed_tools
string[] | null
blocked_tools
string[] | null
agentic_enabled
boolean
default:false

Whether this Project Key is wired up as the auth blob behind the Streamkap MCP. Toggled via POST /project-keys/{id}/enable-agentic and disable-agentic. When true, the encrypted credential lives on the PK row (server-side only); the agent picker on the FE filters to PKs where this is true.

agentic_secret_blob
string | null

Always masked to '********' on responses when agentic_enabled is true; null otherwise. Server-derived only - PUT/PATCH bodies that include this field are rejected with 422.

kafka_acls
Kafka Acls · object[]
whitelist_ips
string | null
kafka_proxy_endpoint
string | null

Kafka proxy endpoint (e.g. host:32400)

schema_proxy_endpoint
string | null

Schema Registry proxy endpoint

token_ttl_seconds
integer

Frontegg JWT token TTL in seconds (dynamic - reflects the current tenant-level authentication token expiration setting in Frontegg). Frontend uses this to display 'role changes take effect within X hours' on role updates.