List the tenant's config entries
const url = 'https://example.com/v1/tenant/config?limit=25&kind=env';const options = {method: 'GET', headers: {Authorization: 'Bearer <token>'}};
try { const response = await fetch(url, options); const data = await response.json(); console.log(data);} catch (error) { console.error(error);}curl --request GET \ --url 'https://example.com/v1/tenant/config?limit=25&kind=env' \ --header 'Authorization: Bearer <token>'Cursor-paginated: the env entries (in the env binding order), then the secret entries (in the secrets binding order); a page holds at most limit entries and nextCursor resumes where it ended. Optional ?kind= narrows to one slot (env / config / secret); ?keyPrefix= matches on entry key. Secret values are ALWAYS redacted on this admin surface — the dispatch path is the only reader that receives raw material.
Authorizations
Section titled “Authorizations”Parameters
Section titled “Parameters”Query Parameters
Section titled “Query Parameters”1..100. Default 25.
Opaque cursor from a prior response. Absent → first page.
Slot for a tenant config entry (tenant-scoped). env and config both address EnvBinding; secret addresses SecretBinding. Prefer /v1/env/* + /v1/secrets/* for new callers.
Restrict to one slot: env, config, or secret.
Prefix match on entry key.
Responses
Section titled “Responses”Page of tenant-config entries.
object
object
Slot for a tenant config entry (tenant-scoped). env and config both address EnvBinding; secret addresses SecretBinding. Prefer /v1/env/* + /v1/secrets/* for new callers.
Entry value. For kind: "secret" this is ALWAYS [redacted] on this admin surface; use the /v1/secrets/* routes and SecretBinding.resolve on the dispatch path to read plaintext.
Example
{ "data": [ { "kind": "env" } ]}Malformed query parameter.
object
object
Stable machine-readable discriminant. Values match domain error codes (see docs/API-ROUTE-CONVENTIONS.md §4.3).
Optional, kind-specific.
object
Server-assigned request id; also echoed via X-Request-Id header.
Examplegenerated
{ "error": { "code": "example", "message": "example", "details": {}, "requestId": "example" }}Missing / malformed / expired / revoked bearer token.
object
object
Stable machine-readable discriminant. Values match domain error codes (see docs/API-ROUTE-CONVENTIONS.md §4.3).
Optional, kind-specific.
object
Server-assigned request id; also echoed via X-Request-Id header.
Examplegenerated
{ "error": { "code": "example", "message": "example", "details": {}, "requestId": "example" }}