> For clean Markdown of any page, append .md to the page URL. > For a complete documentation index, see https://docs.givechariot.com/v2026-04-01/api/authorization-tokens/list/llms.txt. > For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://docs.givechariot.com/_mcp/server. # List Authorization Tokens GET https://api.givechariot.com/v1/donor_accounts/{id}/authorization_tokens List Authorization Tokens for a Donor Account. Token codes are never returned by this endpoint — only the metadata is returned. Reference: https://docs.givechariot.com/api/authorization-tokens/list ## Authentication - `Authorization` header (bearer token, required) — Bearer authentication of the form `Bearer `, where token is your auth token. ## Servers - `https://api.givechariot.com` (Production, default) - `https://sandboxapi.givechariot.com` (Sandbox) ## Request ### Path parameters - `id` (string, required) — The unique id of the Donor Account ### Query parameters - `status` (enum, optional) — Filter tokens by status. - Allowed values: `pending`, `verified`, `revoked`, `expired` - `page_limit` (integer, optional, default: 10) — the number of results to return; defaults to 10, max is 100 - `page_token` (string, optional) — A cursor for paginating; pass the value from `next_page_token` of the previous response. ## Response ### 200 The response for DonorAccounts.listAuthorizationTokens - `results` (list of DonorAuthorizationToken, optional) - `next_page_token` (string, optional, nullable) — A cursor token to use to retrieve the next page of results by making another API call to the same endpoint with the same parameters (only changing the page_token). If specified, then more results exist on the server that were not returned, otherwise no more results exist on the server. ## Errors ### 400 Bad Request Error The request is invalid or contains invalid parameters - `type` (string, required) — A URI reference identifying the problem type. - `title` (string, required) — A short, human-readable summary of the problem type. - `status` (integer, required) — The HTTP status code for this error. - `detail` (string, required) — A human-readable explanation specific to this occurrence. ### 401 Unauthorized Error Unauthorized. The request is missing the security (OAuth2 Bearer token) requirements and the server is unable to verify the identify of the caller. - `type` (string, required) — A URI reference identifying the problem type. - `title` (string, required) — A short, human-readable summary of the problem type. - `status` (integer, required) — The HTTP status code for this error. - `detail` (string, required) — A human-readable explanation specific to this occurrence. ### 403 Forbidden Error Access denied - `type` (string, required) — A URI reference identifying the problem type. - `title` (string, required) — A short, human-readable summary of the problem type. - `status` (integer, required) — The HTTP status code for this error. - `detail` (string, required) — A human-readable explanation specific to this occurrence. ### 404 Not Found Error Resource Not Found - `type` (string, required) — A URI reference identifying the problem type. - `title` (string, required) — A short, human-readable summary of the problem type. - `status` (integer, required) — The HTTP status code for this error. - `detail` (string, required) — A human-readable explanation specific to this occurrence. ### 500 Internal Server Error Internal Server Error - `type` (string, required) — A URI reference identifying the problem type. - `title` (string, required) — A short, human-readable summary of the problem type. - `status` (integer, required) — The HTTP status code for this error. - `detail` (string, required) — A human-readable explanation specific to this occurrence. ## Types ### DonorAuthorizationToken A Donor Authorization Token is a single-use binding credential that ties a [Donor Account](/api/donor-accounts) to a verified identity exchange between DAFpay and the DAF. Tokens have two creation paths: - **DAF-Initiated Setup**: The DAF creates a Donor Account and then a token, surfaces the token's `code` to the donor via their portal, and the donor enters the `code` into DAFpay to approve their account. - **Donor-Initiated Verification**: After a donor submits a Grant Request without an approved Donor Account, DAFpay automatically creates a token and emails the `code` to the donor. The DAF later receives the `code` from the donor and calls [Verify Authorization Token](/api/authorization-tokens/verify) to approve the linked Donor Account. Tokens are single-use: once verified, the token's status becomes `verified` and the `code` cannot be used again. - `id` (string, required) — The unique identifier for this object. - `donor_account_id` (string, required) — The ID of the [Donor Account](/api/donor-accounts) this token is bound to. - `status` (enum, required) — The status of a [Donor Authorization Token](/api/authorization-tokens). * `pending`: The token has been issued but not yet verified. * `verified`: The token has been verified and can no longer be used. * `revoked`: The token was explicitly revoked before being verified. * `expired`: The token's `expires_at` has passed and it can no longer be verified. - Allowed values: `pending`, `verified`, `revoked`, `expired` - `created_at` (datetime, required) — Time when the token was issued. Expressed in RFC 3339 format. - `expires_at` (datetime, required) — Time at which this token will expire and can no longer be verified. Defaults to 30 days after creation; configurable via the `expires_in` parameter on [Create Authorization Token](/api/authorization-tokens/create). - `code` (string, optional) — The token's secret code value. The `code` is **only returned in the response of [Create Authorization Token](/api/authorization-tokens/create)**. It is omitted from all other responses (Get, List). If the code is lost, [revoke](/api/authorization-tokens/revoke) the token and create a new one. The format is a 12-character alphanumeric string designed to be easy for donors to read aloud or copy. Codes are not case-sensitive when verified. - `verified_at` (datetime, optional) — Time at which the token was verified. Only set when `status` is `verified`. - `revoked_at` (datetime, optional) — Time at which the token was revoked. Only set when `status` is `revoked`. - `metadata` (map from string to string, optional) — A map of arbitrary string keys and values to store information about the object. ## Examples **Response** ```json { "results": [ { "id": "auth_token_01jpjenf5q6cawy43yxfcrxhct", "donor_account_id": "donor_account_01jpjenf5q6cawy43yxfcrxhct", "status": "verified", "created_at": "2026-04-01T12:00:00Z", "expires_at": "2026-05-01T12:00:00Z", "verified_at": "2026-04-02T18:30:00Z" } ], "next_page_token": null } ```