> ## Documentation Index
> Fetch the complete documentation index at: https://docs.suprsend.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Get Workspace Key

> Retrieve a single workspace key/secret pair by its `id`.

The response returns the full `key` and `secret` in plain text.




## OpenAPI

````yaml GET /v1/{workspace}/ws_key/{workspace_key_id}/
openapi: 3.1.1
info:
  title: SuprSend API
  description: APIs supported on suprsend platform
  version: 1.2.2
servers:
  - url: https://hub.suprsend.com
security:
  - sec0: []
  - BearerAuth: []
paths:
  /v1/{workspace}/ws_key/{workspace_key_id}/:
    get:
      summary: Get Workspace Key
      description: |
        Retrieve a single workspace key/secret pair by its `id`.

        The response returns the full `key` and `secret` in plain text.
      operationId: get-workspace-key
      parameters:
        - in: path
          name: workspace
          required: true
          schema:
            type: string
          description: Workspace slug (e.g. `staging`, `production`).
        - in: path
          name: workspace_key_id
          required: true
          schema:
            type: string
          description: Workspace key identifier (e.g. `ws_key_...`).
      responses:
        '200':
          description: >-
            Successfully retrieved the workspace key. Full `key` and `secret`
            are included.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ManagementWorkspaceKey'
              example:
                id: ws_key_01ABCDEFGHJKMNPQRSTVWXYZ1
                name: ops-cli
                key: SS.WSK.YYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYY
                secret: SS.WSS.YYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYYY
                is_default: false
                is_active: true
                is_deleted: false
                allowed_domains: []
                created_at: '2026-09-28T11:12:23.557360Z'
                created_by:
                  name: System User
                  email: org_XXXXXXXXXXXXXXXXXXXXXX@systemuser.suprsend.com
                rotated_at: null
                rotated_by: null
                deleted_at: null
                deleted_by: null
        '401':
          $ref: '#/components/responses/AuthenticationError'
        '404':
          $ref: '#/components/responses/NotFoundError'
      security:
        - ServiceTokenAuth: []
      servers:
        - url: https://management-api.suprsend.com
      x-codeSamples:
        - lang: cURL
          label: Get Workspace Key
          source: >
            curl -X GET
            "https://management-api.suprsend.com/v1/{workspace}/ws_key/{workspace_key_id}/"
            \
              --header 'Authorization: ServiceToken <SERVICE_TOKEN>'
components:
  schemas:
    ManagementWorkspaceKey:
      type: object
      description: >
        A workspace key/secret pair used to authenticate backend SDKs
        (`Suprsend(workspace_key, workspace_secret)`).


        Unlike `ws_api_key`, both `key` and `secret` are returned in full plain
        text on every response - list, detail, create and rotate. Treat every
        response as sensitive: do not log it, do not surface it to browsers, and
        store the secret only in an environment variable or secrets manager.
      properties:
        id:
          type: string
          description: >-
            Unique identifier of the workspace key. Format is `ws_key_` followed
            by a 26-character ULID.
          example: ws_key_01ABCDEFGHJKMNPQRSTVWXYZ0
        name:
          type: string
          description: >-
            Label for the workspace key. Unique across the workspace's ws_key
            records.
          example: ops-cli
        key:
          type: string
          description: >
            Full workspace key value. This is the `workspace_key` passed to
            backend SDKs when authenticating (`Suprsend(workspace_key,
            workspace_secret)`). Returned in plain text on every response.


            Rotation does not change `key` - only `secret` is regenerated.
          example: SS.WSK.XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
        secret:
          type: string
          description: >
            Full workspace secret. This is the `workspace_secret` passed to
            backend SDKs when authenticating (`Suprsend(workspace_key,
            workspace_secret)`). Returned in plain text on every response, not
            masked and not "returned once".


            Anyone with read access to this response can authenticate as this
            workspace. Handle every list, detail, create and rotate response as
            sensitive data.
          example: SS.WSS.XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
        is_default:
          type: boolean
          description: >-
            Whether this is the workspace's default key/secret pair. The default
            record cannot be deleted; it can be rotated.
        is_active:
          type: boolean
          description: Whether this workspace key can authenticate requests.
        is_deleted:
          type: boolean
          description: Whether this workspace key has been deleted.
        allowed_domains:
          type: array
          items:
            type: string
          description: Array of domain strings associated with the workspace key.
        created_at:
          type: string
          format: date-time
          description: Timestamp when the workspace key was created.
        created_by:
          $ref: '#/components/schemas/ManagementActor'
        rotated_at:
          type: string
          format: date-time
          nullable: true
          description: Timestamp when the workspace secret was last rotated.
        rotated_by:
          $ref: '#/components/schemas/ManagementActor'
        deleted_at:
          type: string
          format: date-time
          nullable: true
          description: Timestamp when the workspace key was deleted, if applicable.
        deleted_by:
          $ref: '#/components/schemas/ManagementActor'
    ManagementActor:
      type: object
      description: >-
        Identity that performed an action (created, updated, rolled, deleted,
        rotated).
      nullable: true
      properties:
        name:
          type: string
          description: Display name of the actor.
          example: System User
        email:
          type: string
          description: Email address of the actor.
          example: user@example.com
    ErrorResponse:
      type: object
      properties:
        code:
          type: integer
          description: HTTP status code
        error_code:
          type: string
          description: Specific error code identifier
        type:
          type: string
          description: Error type classification
        message:
          type: string
          description: Human-readable error message
        detail:
          type: string
          description: Additional error details
  responses:
    AuthenticationError:
      description: Authentication failed
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorResponse'
          example:
            code: 401
            error_code: authentication_failed
            type: AuthenticationFailed
            message: Invalid service token.
            detail: Invalid service token.
    NotFoundError:
      description: Resource not found
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/ErrorResponse'
          example:
            code: 404
            error_code: not_found
            type: NotFound
            message: workspace 'demo' not found
            detail: workspace 'demo' not found
  securitySchemes:
    sec0:
      type: apiKey
      in: header
      name: Authorization
      x-bearer-format: bearer
      description: >-
        Bearer authentication header of the form `Bearer <token>`, where <token>
        is your auth token.
    BearerAuth:
      type: http
      scheme: bearer
      bearerFormat: API_Key
      description: >-
        Pass as `Bearer <API_KEY>`. Get API Key from SuprSend dashboard
        Developers -> API Keys section.
    ServiceTokenAuth:
      type: apiKey
      in: header
      name: ServiceToken <token>
      description: >-
        You can get Service Token from [SuprSend dashboard -> Account Settings
        -> Service
        Tokens](https://app.suprsend.com/en/account-settings/service-tokens)
        section.

````