# Retrieve authentication tokens

Retrieves a list of customer authentication tokens.

Endpoint: GET /authentication-tokens
Version: latest
Security: SecretApiKey, JWT

## Security:

  - `SecretApiKey` (unknown)
    apiKey in header REB-APIKEY

  - `JWT` (unknown)
    http bearer JWT

## Query parameters:

  - `limit` (integer)
    Limit the number of collection items to be returned.
Use `0` to return an empty collection and still receive the count of matching items in `Pagination-Total`.

  - `offset` (integer)
    Specifies the starting point within the collection of items to be returned.

## Response 200:

  - `200` (unknown)
    List of auth tokens retrieved.

## Response 200 fields (application/json):

  - `username` (string, required)
    Username of the customer who is associated with the authentication token.

  - `customerId` (string)
    ID of the customer resource.
    Example: cus_0YV7DDSDD1C8DA64KHH2W33CPF

  - `token` (string)
    ID of the authentication token.

  - `otpRequired` (boolean)
    Specifies if a One-Time Password (OTP) is required to exchange the authentication token.

  - `credentialId` (string)
    Unique resource ID.
    Example: 4f6cf35x-2c4y-483z-a0a9-158621f77a21

  - `expiredTime` (string | null)
    Date and time when the token expired.

  - `_links` (array)
    Related links.

  - `_links.href` (string)
    Link URL.

  - `_links.rel` (string)
    Type of link.
    Enum: "self"

## Response 200 headers (application/json):

  - `Pagination-Total` (integer)
    Total number of items that match the request.
The value is independent of `limit`, including when `limit` is `0`.
    Example: 332

  - `Pagination-Limit` (integer)
    Maximum number of items per page.
    Example: 100

  - `Pagination-Offset` (integer)
    Specifies the starting point within the
collection of resource results. For example, a request with
`limit=20` retrieves and displays the first 20 results on a page. A
following request with `limit=20` and `offset=20`, retrieves the next
page of 20 results.
    Example: 2

## Response 401:

  - `401` (unknown)
    Unauthorized access.
Invalid credentials used.

## Response 401 fields (application/json):

  - `status` (integer)
    HTTP status code.

  - `type` (string)
    Problem type in the form of a [URI](https://tools.ietf.org/html/rfc3986) reference.
It should provide human-readable documentation for the problem type.
When this member is not present, its value is assumed to be "about:blank".

  - `title` (string)
    Short, human-readable summary of the problem type.
Other than for the purposes of localization, this should not change from occurrence to occurrence of the problem.

  - `detail` (string)
    Human-readable explanation that is specific to this occurrence of the problem.

  - `instance` (string)
    URI reference that identifies the specific occurrence of the problem.
It may or may not yield further information if dereferenced.

## Response 403:

  - `403` (unknown)
    Access forbidden.

## Response 403 fields (application/json):

  - `status` (integer)
    HTTP status code.

  - `type` (string)
    Problem type in the form of a [URI](https://tools.ietf.org/html/rfc3986) reference.
It should provide human-readable documentation for the problem type.
When this member is not present, its value is assumed to be "about:blank".

  - `title` (string)
    Short, human-readable summary of the problem type.
Other than for the purposes of localization, this should not change from occurrence to occurrence of the problem.

  - `detail` (string)
    Human-readable explanation that is specific to this occurrence of the problem.

  - `instance` (string)
    URI reference that identifies the specific occurrence of the problem.
It may or may not yield further information if dereferenced.

