﻿---
title: stack es security get-api-key cli command
description: Get API key information. Behaviour flags: --dry-run — validate all inputs and exit without performing any action 
url: https://www.elastic.co/elastic/docs-builder/docs/4089/reference/elastic-cli/cli/stack/es/security/get-api-key
applies_to:
  - Elastic Cloud Serverless: Preview
  - Elastic Stack: Preview
---

# stack es security get-api-key cli command
<cli-modifiers>
</cli-modifiers>

```bash
elastic stack es security get-api-key [options]
```

Get API key information.
**Behaviour flags:**
`--dry-run` — validate all inputs and exit without performing any action

## Options

<definitions>
  <definition term="--id string">
    An API key id.
    This parameter cannot be used with any of `name`, `realm_name` or `username`.
  </definition>
  <definition term="--name string">
    An API key name.
    This parameter cannot be used with any of `id`, `realm_name` or `username`.
    It supports prefix search with wildcard.
  </definition>
  <definition term="--owner">
    A boolean flag that can be used to query API keys owned by the currently authenticated user.
    The `realm_name` or `username` parameters cannot be specified when this parameter is set to `true` as they are assumed to be the currently authenticated ones.
  </definition>
  <definition term="--realm-name string">
    The name of an authentication realm.
    This parameter cannot be used with either `id` or `name` or when `owner` flag is set to `true`.
  </definition>
  <definition term="--username string">
    The username of a user.
    This parameter cannot be used with either `id` or `name` or when `owner` flag is set to `true`.
  </definition>
  <definition term="--with-limited-by">
    Return the snapshot of the owner user's role descriptors
    associated with the API key. An API key's actual
    permission is the intersection of its assigned role
    descriptors and the owner user's role descriptors.
  </definition>
  <definition term="--active-only">
    A boolean flag that can be used to query API keys that are currently active. An API key is considered active if it is neither invalidated, nor expired at query time. You can specify this together with other parameters such as `owner` or `name`. If `active_only` is false, the response will include both active and inactive (expired or invalidated) keys.
  </definition>
  <definition term="--with-profile-uid">
    Determines whether to also retrieve the profile uid, for the API key owner principal, if it exists.
  </definition>
  <definition term="--error-trace">
    When set to `true` Elasticsearch will include the full stack trace of errors
    when they occur.
  </definition>
  <definition term="--filter-path string">
    Comma-separated list of filters in dot notation which reduce the response
    returned by Elasticsearch.
    **Repeatable:** pass `--filter-path` multiple times to supply more than one value
  </definition>
  <definition term="--human">
    When set to `true` will return statistics in a format suitable for humans.
    For example `"exists_time": "1h"` for humans and
    `"exists_time_in_millis": 3600000` for computers. When disabled the human
    readable values will be omitted. This makes sense for responses being consumed
    only by machines.
  </definition>
  <definition term="--pretty">
    If set to `true` the returned JSON will be "pretty-formatted". Only use
    this option for debugging only.
  </definition>
  <definition term="--input-file string">
    path to a JSON file to use as command input
  </definition>
  <definition term="--dry-run">
    validate all inputs and exit without performing any action (preview changes without applying them)
  </definition>
</definitions>


## Global Options

<definitions>
  <definition term="--json">
    output as JSON
  </definition>
</definitions>