Tool: apikeys_get_key
Gets the metadata for a specific API key. Does not return the key string itself.
The following code sample shows how to use curl to call the apikeys_get_key MCP tool.
| Curl Request |
|---|
curl --location 'https://apikeys.googleapis.com/mcp' \ --header 'content-type: application/json' \ --header 'accept: application/json, text/event-stream' \ --data '{ "method": "tools/call", "params": { "name": "apikeys_get_key", "arguments": { // Provide these details according to the MCP tool specification. } }, "jsonrpc": "2.0", "id": 1 }' |
Input Schema
Request message for GetKey method.
GetKeyRequest
| JSON representation |
|---|
{ "name": string } |
| Fields | |
|---|---|
name |
Required. The resource name of the API key to get. |
Output Schema
The representation of a key managed by the API Keys API.
Key
| JSON representation |
|---|
{
"name": string,
"uid": string,
"displayName": string,
"keyString": string,
"createTime": string,
"updateTime": string,
"deleteTime": string,
"annotations": {
string: string,
...
},
"restrictions": {
object ( |
| Fields | |
|---|---|
name |
Identifier. The resource name of the key. The NOTE: Key is a global resource; hence the only supported value for location is |
uid |
Output only. Unique id in UUID4 format. |
displayName |
Human-readable display name of this key that you can modify. The maximum length is 63 characters. |
keyString |
Output only. An encrypted and signed value held by this key. This field can be accessed only through the |
createTime |
Output only. A timestamp identifying the time this key was originally created. Uses RFC 3339, where generated output will always be Z-normalized and use 0, 3, 6 or 9 fractional digits. Offsets other than "Z" are also accepted. Examples: |
updateTime |
Output only. A timestamp identifying the time this key was last updated. Uses RFC 3339, where generated output will always be Z-normalized and use 0, 3, 6 or 9 fractional digits. Offsets other than "Z" are also accepted. Examples: |
deleteTime |
Output only. A timestamp when this key was deleted. If the resource is not deleted, this must be empty. Uses RFC 3339, where generated output will always be Z-normalized and use 0, 3, 6 or 9 fractional digits. Offsets other than "Z" are also accepted. Examples: |
annotations |
Annotations is an unstructured key-value map stored with a policy that may be set by external tools to store and retrieve arbitrary metadata. They are not queryable and should be preserved when modifying objects. An object containing a list of |
restrictions |
Key restrictions. |
etag |
A checksum computed by the server based on the current value of the Key resource. This may be sent on update and delete requests to ensure the client has an up-to-date value before proceeding. See https://google.aip.dev/154. |
serviceAccountEmail |
Optional. The email address of the service account the key is bound to. |
Timestamp
| JSON representation |
|---|
{ "seconds": string, "nanos": integer } |
| Fields | |
|---|---|
seconds |
Represents seconds of UTC time since Unix epoch 1970-01-01T00:00:00Z. Must be between -62135596800 and 253402300799 inclusive (which corresponds to 0001-01-01T00:00:00Z to 9999-12-31T23:59:59Z). |
nanos |
Non-negative fractions of a second at nanosecond resolution. This field is the nanosecond portion of the duration, not an alternative to seconds. Negative second values with fractions must still have non-negative nanos values that count forward in time. Must be between 0 and 999,999,999 inclusive. |
AnnotationsEntry
| JSON representation |
|---|
{ "key": string, "value": string } |
| Fields | |
|---|---|
key |
|
value |
|
Restrictions
| JSON representation |
|---|
{ "apiTargets": [ { object ( |
| Fields | |
|---|---|
apiTargets[] |
A restriction for a specific service and optionally one or more specific methods. Requests are allowed if they match any of these restrictions. If no restrictions are specified, all targets are allowed. |
Union field client_restrictions. The websites, IP addresses, Android apps, or iOS apps (the clients) that are allowed to use the key. You can specify only one type of client restrictions per key. client_restrictions can be only one of the following: |
|
browserKeyRestrictions |
The HTTP referrers (websites) that are allowed to use the key. |
serverKeyRestrictions |
The IP addresses of callers that are allowed to use the key. |
androidKeyRestrictions |
The Android apps that are allowed to use the key. |
iosKeyRestrictions |
The iOS apps that are allowed to use the key. |
BrowserKeyRestrictions
| JSON representation |
|---|
{ "allowedReferrers": [ string ] } |
| Fields | |
|---|---|
allowedReferrers[] |
A list of regular expressions for the referrer URLs that are allowed to make API calls with this key. |
ServerKeyRestrictions
| JSON representation |
|---|
{ "allowedIps": [ string ] } |
| Fields | |
|---|---|
allowedIps[] |
A list of the caller IP addresses that are allowed to make API calls with this key. |
AndroidKeyRestrictions
| JSON representation |
|---|
{
"allowedApplications": [
{
object ( |
| Fields | |
|---|---|
allowedApplications[] |
A list of Android applications that are allowed to make API calls with this key. |
AndroidApplication
| JSON representation |
|---|
{ "sha1Fingerprint": string, "packageName": string } |
| Fields | |
|---|---|
sha1Fingerprint |
The SHA1 fingerprint of the application. For example, both sha1 formats are acceptable : DA:39:A3:EE:5E:6B:4B:0D:32:55:BF:EF:95:60:18:90:AF:D8:07:09 or DA39A3EE5E6B4B0D3255BFEF95601890AFD80709. Output format is the latter. |
packageName |
The package name of the application. |
IosKeyRestrictions
| JSON representation |
|---|
{ "allowedBundleIds": [ string ] } |
| Fields | |
|---|---|
allowedBundleIds[] |
A list of bundle IDs that are allowed when making API calls with this key. |
ApiTarget
| JSON representation |
|---|
{ "service": string, "methods": [ string ] } |
| Fields | |
|---|---|
service |
The service for this restriction. It should be the canonical service name, for example: |
methods[] |
Optional. List of one or more methods that can be called. If empty, all methods for the service are allowed. A wildcard (*) can be used as the last symbol. Valid examples: |
Tool Annotations
Tool annotations are sent to MCP clients to describe the basic risk of a given tool. Most clients treat these hints as untrusted, but they can be used to decide when a confirmation prompt might be sent to a user.
Along with the title string, the following boolean hints are defined as follows:
readOnlyHint: If true, the tool doesn't modify its environment. Default: false.destructiveHint: If true, then the tool can perform destructive actions. If false, then the tool can only perform additive actions. Default: true.idempotentHint: If true, then calling the tool repeatedly with the same arguments will have no additional effect on its environment. Default: false.openWorldHint: If true, then the tool can interact with an 'open world' of external entities. If false, then the tool can only interact with internal entities. For example, a web search tool would be open world, while a memory tool would not be open world.
Destructive Hint: ❌ | Idempotent Hint: ✅ | Read Only Hint: ✅ | Open World Hint: ❌