> ## Documentation Index
> Fetch the complete documentation index at: https://docs.basaltic.sh/llms.txt
> Use this file to discover all available pages before exploring further.

# List egress-only gateways



## OpenAPI

````yaml /api-reference/specs/network.yaml get /v1/egress-only-gateways
openapi: 3.0.3
info:
  title: Basaltic Network API
  version: 1.0.0
  description: |
    The VPC surface — networks and subnets, interfaces, route tables,
    security groups, internet, NAT and egress-only gateways, and floating
    IPs.
  contact:
    name: Basaltic Support
    email: ping@basaltic.sh
  license:
    name: Proprietary
    url: https://basaltic.sh/terms
servers:
  - url: https://network.{region}.basaltic.sh
    description: Regional API endpoint
    variables:
      region:
        default: sa-saopaulo-1
        description: Region code
security:
  - SignatureAuth: []
paths:
  /v1/egress-only-gateways:
    get:
      tags:
        - Networking
      summary: List egress-only gateways
      operationId: listEgressOnlyGateways
      parameters:
        - name: limit
          in: query
          schema:
            type: integer
            minimum: 1
            maximum: 500
            default: 50
            example: 50
        - name: marker
          in: query
          schema:
            type: string
            format: uuid
            example: b7d3f1a9-2c8e-4b6d-9f1a-3e5c7d2b8a4f
          description: Resume token — the last id from the previous page.
      responses:
        '200':
          description: List of egress-only gateways
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/EgressOnlyGatewayListResponse'
        '401':
          $ref: '#/components/responses/Unauthorized'
        '403':
          $ref: '#/components/responses/Forbidden'
        '500':
          $ref: '#/components/responses/InternalServerError'
      security:
        - SignatureAuth: []
components:
  schemas:
    EgressOnlyGatewayListResponse:
      type: object
      required:
        - egress_only_gateways
        - meta
      properties:
        egress_only_gateways:
          type: array
          items:
            $ref: '#/components/schemas/EgressOnlyGateway'
        meta:
          $ref: '#/components/schemas/PaginationMeta'
    EgressOnlyGateway:
      type: object
      description: >-
        The IPv6 analogue of a NAT gateway, and its inverse: a subnet whose
        route table points ::/0 at one gets OUTBOUND v6 (plus the return traffic
        of its own flows), but the internet can never initiate an inbound
        connection — a platform-band drop enforces that regardless of the
        tenant's security groups. It owns no address (v6 has no NAT) and reuses
        the VPC's internet gateway for the L3 uplink, so the VPC must have an
        IGW attached. One per VPC.
      required:
        - id
        - crn
        - name
        - vpc_id
        - tags
        - created_at
        - updated_at
      properties:
        id:
          type: string
          format: uuid
          readOnly: true
        crn:
          type: string
          readOnly: true
          example: crn:network:sa-saopaulo-1:my-account:egress-only-gateway/main
        name:
          type: string
          example: main
        description:
          type: string
          example: Egress-only v6 for the private tier
        vpc_id:
          type: string
          format: uuid
          example: 5f8d3a2e-1c4b-4e7a-9f6d-2b1a8c3e5d7f
        tags:
          type: object
          additionalProperties:
            type: string
        created_at:
          type: string
          format: date-time
          readOnly: true
        updated_at:
          type: string
          format: date-time
          readOnly: true
    PaginationMeta:
      type: object
      properties:
        total:
          type: integer
          description: Total number of items
          example: 150
        limit:
          type: integer
          description: Number of items per page
          example: 20
        marker:
          type: string
          description: >-
            Opaque cursor for the next page. Pass it back as the `marker` query
            parameter; treat it as a token, not a value to parse.
          example: 550e8400-e29b-41d4-a716-446655440000
        has_more:
          type: boolean
          description: Whether there are more items
          example: true
    Error:
      type: object
      required:
        - error
      properties:
        error:
          type: object
          required:
            - code
            - message
            - request_id
          properties:
            code:
              type: string
              description: Error code identifying the type of error
              example: INVALID_INPUT
            message:
              type: string
              description: Human-readable error message
              example: Invalid request parameters
            request_id:
              type: string
              format: uuid
              description: Request ID for debugging
              example: 550e8400-e29b-41d4-a716-446655440000
  responses:
    Unauthorized:
      description: Authentication required or token invalid
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
          example:
            error:
              code: UNAUTHORIZED
              message: Authentication required
              request_id: 550e8400-e29b-41d4-a716-446655440000
    Forbidden:
      description: Insufficient permissions
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
          example:
            error:
              code: ACCESS_DENIED
              message: You don't have permission to perform this action
              request_id: 550e8400-e29b-41d4-a716-446655440000
    InternalServerError:
      description: Internal server error
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/Error'
          example:
            error:
              code: INTERNAL_ERROR
              message: An internal error occurred
              request_id: 550e8400-e29b-41d4-a716-446655440000
  securitySchemes:
    SignatureAuth:
      type: apiKey
      in: header
      name: Authorization
      description: >
        Request signing with an access key issued to a service account. An

        HMAC-SHA256 over a canonical form of the request, close to AWS SigV4.

        The `basaltic` CLI signs for you.


        Send `Authorization`, `X-Date` (UTC, `YYYYMMDDTHHMMSSZ`) and `X-Nonce`

        (random per request); add `X-Content-Sha256` to bind a body, and

        `X-Amz-Security-Token` when using temporary credentials.


        ```

        Authorization: BASALTIC-HMAC-SHA256
        Credential=<access_key_id>/<date>/<region>/basaltic/basaltic_request,
        SignedHeaders=host;x-date;x-nonce, Signature=<hex>

        ```


        `<region>` is the region code you are calling, or `global` for the
        global

        services. A signature is valid for 5 minutes from `X-Date`, and mutating

        requests are replay-guarded on the nonce.


        **Full signing procedure, including a working implementation:**

        https://docs.basaltic.sh/authentication


        ## Rate limits

        There is no global request budget. A limit applies only where an

        operation documents a `429`, and that operation says what it counts.

        Those responses carry `X-RateLimit-Limit`, `X-RateLimit-Remaining`,

        `X-RateLimit-Reset` and, on a `429`, `Retry-After` — read them rather

        than hard-coding a number. Retrying before `Retry-After` is refused and

        extends the window. Everything else is bounded by quota, not by request

        rate.

````