I have an older system that uses a SAS token containing an identifier and key to call an API Management endpoint and retrieve a subscription's primary and secondary keys. The request uses the `2014-02-14-preview` API version, but the response now returns both `primaryKey` and `secondaryKey` as `null` even though the subscription is active. This integration has not been changed in about three years, so I'm trying to determine whether the older API behavior has changed. I'm aware that there is an update approach for handling the keys, but I'd prefer a quicker compatible solution if one is available.
2 Answers
A normal subscription Get or List operation generally should not expose secret keys, since anyone with the relevant Reader permissions could potentially retrieve them. Use the subscription’s List Secrets operation instead, which is the supported endpoint for obtaining the primary and secondary keys. The older preview API may have returned them previously, but that behavior should not be relied on.
The `2014-02-14-preview` API version is extremely old and shouldn’t be used for production integrations. Try the current API version and specifically call the subscription secrets endpoint rather than expecting keys in the regular subscription response.

I also tested a 2022 API version, but the keys were still missing. It looks like the integration needs to be updated to use the dedicated secrets operation.