> ## Documentation Index
> Fetch the complete documentation index at: https://docs.anycrm.anyreach.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# List User Personal Access Tokens

User PATs (`pat_…`) are Logto-native personal access tokens with no local database row at all — see [Authentication](/authentication) for how they differ from organization API keys. They're addressed by **name, not id**, and names must be unique per user. None of the other seven PAT/key management endpoints require a dedicated manage scope — a PAT or key is inherently scoped to the caller's own identity, so any authenticated request can call them.

Scoped to the caller's own Logto user id — organization context is irrelevant here, since user PATs aren't org-bound. This reads straight from Logto's personal-access-token list for the caller, filtered to names carrying the `pat_` prefix this app uses internally (org API keys are backed by Logto PATs too, but named differently, so they don't leak into this list).

<Note>The `value` field below is whatever Logto's Management API returns for each token on this call. Because user PATs are entirely Logto-managed (no local hash-and-discard step like `ak_` keys), this reference cannot promise it's a one-time reveal the way `pat_key` on org keys is — treat any `value` you receive as sensitive and avoid depending on repeat calls continuing to return it.</Note>

### Auth

Requires `pats:read`, which every default role carries. This reads the caller's own Logto personal access tokens, keyed on the token's subject — there is no way to read another member's, not even as an org admin. No active organization is needed either: user PATs aren't org-bound.

### Response

`200 OK` — a bare JSON array.

| Field        | Type             | Description                                                  |
| ------------ | ---------------- | ------------------------------------------------------------ |
| `name`       | `string`         | Token name with the internal `pat_` storage prefix stripped. |
| `value`      | `string`         | The token value as returned by Logto for this call.          |
| `created_at` | `string \| null` | ISO 8601 timestamp.                                          |
| `expires_at` | `string \| null` | ISO 8601 timestamp, or `null` if the token never expires.    |


## OpenAPI

````yaml GET /user-pats
openapi: 3.1.0
info:
  title: anycrm-api
  version: 0.0.1
servers: []
security: []
tags:
  - name: Customer Intelligence
    description: >-
      Company research and ICP-fit scoring — create a research run, track its
      progress, and read back scored companies as leads.
  - name: Outreach
    description: >-
      The cold-email management console — domains, mailboxes, and campaigns — as
      a thin control plane over the SalesForge stack.
  - name: AnyCard
    description: >-
      Authenticated CRUD for AnyCard, the org's digital business-card /
      lead-capture product.
  - name: AnyCard Events
    description: >-
      Event-attribution analytics for AnyCard — which captured leads converted,
      broken down by source, owner, and deal.
  - name: AnyCard Share Links
    description: >-
      Unauthenticated endpoints reached by anyone who scans a QR code or opens a
      shared AnyCard link.
  - name: AI
    description: >-
      A streaming (SSE) AI chat endpoint with account-commit actions it can take
      on the caller's behalf.
  - name: Analytics Assistant
    description: >-
      The natural-language analytics assistant — a guarded text-to-SQL loop
      (SSE) that answers ad-hoc questions over the org's CRM data as a
      least-privilege, read-only database role.
  - name: Account Readiness
    description: >-
      Account Readiness Profiles — AI-scored signals on whether an account is
      ready for outreach or expansion, computed via a Temporal workflow.
  - name: Integrations
    description: >-
      Pipedream Connect — issuing connect tokens and managing the org's
      connected third-party accounts.
  - name: Feedback
    description: >-
      User-submitted platform feedback (bug reports, feature requests) — global,
      not scoped to one organization.
  - name: Public Media
    description: >-
      Unauthenticated image reads for publicly-embeddable assets (card photos,
      inline email images) — allowlisted by key shape; everything else in the
      storage bucket stays private.
  - name: Service Health
    description: Service liveness.
paths:
  /user-pats:
    get:
      tags:
        - User PATs
      summary: List User Pats
      operationId: list_user_pats_user_pats_get
      responses:
        '200':
          description: Successful Response
          content:
            application/json:
              schema:
                items:
                  $ref: '#/components/schemas/UserPatResponse'
                type: array
                title: Response List User Pats User Pats Get
      security:
        - HTTPBearer: []
components:
  schemas:
    UserPatResponse:
      properties:
        name:
          type: string
          title: Name
        value:
          type: string
          title: Value
        created_at:
          anyOf:
            - type: string
            - type: 'null'
          title: Created At
        expires_at:
          anyOf:
            - type: string
            - type: 'null'
          title: Expires At
      type: object
      required:
        - name
        - value
      title: UserPatResponse
  securitySchemes:
    HTTPBearer:
      type: http
      scheme: bearer

````