> ## Documentation Index
> Fetch the complete documentation index at: https://docs.base44.com/llms.txt
> Use this file to discover all available pages before exploring further.

# List app code files

> <Info>This API is in beta. Endpoints, fields, and behavior may still change, so avoid depending on it in production.</Info>

Returns the path of every file in the app's source, the list the builder's code editor shows in its file tree.

Files the app's `.gitignore` excludes, dependency and build folders, most dotfiles, and binary or media files are left out. Read a file's text with [Get an app code file](/api-reference/get-an-app-code-file).

Reads come from the app's live sandbox, the same files the builder's code editor shows, including changes that haven't been published yet. If no sandbox is running, the call starts one, so the first call after a quiet period takes noticeably longer than later ones.

Internally this route can follow a feature branch, but the parameter that selects one isn't part of the public API, so reads come from the app's main line.

This is limited to 60 requests a minute per app for each workspace's personal API keys, so every key in a workspace shares one allowance. Some workspaces have a different limit.

<Note>This endpoint accepts a personal API key, including a read-only one, from anyone with access to the app, viewers included. Workspace API keys are not authorized for it.</Note>



## OpenAPI

````yaml /developers/references/app-management/app-management-openapi.json get /api/apps/{app_id}/code/file-list
openapi: 3.1.0
info:
  title: Base44 App Management API
  version: 1.0.0
servers:
  - url: https://app.base44.com
security:
  - PersonalAccessTokenAuth: []
paths:
  /api/apps/{app_id}/code/file-list:
    get:
      summary: List app code files
      description: >-
        <Info>This API is in beta. Endpoints, fields, and behavior may still
        change, so avoid depending on it in production.</Info>


        Returns the path of every file in the app's source, the list the
        builder's code editor shows in its file tree.


        Files the app's `.gitignore` excludes, dependency and build folders,
        most dotfiles, and binary or media files are left out. Read a file's
        text with [Get an app code file](/api-reference/get-an-app-code-file).


        Reads come from the app's live sandbox, the same files the builder's
        code editor shows, including changes that haven't been published yet. If
        no sandbox is running, the call starts one, so the first call after a
        quiet period takes noticeably longer than later ones.


        Internally this route can follow a feature branch, but the parameter
        that selects one isn't part of the public API, so reads come from the
        app's main line.


        This is limited to 60 requests a minute per app for each workspace's
        personal API keys, so every key in a workspace shares one allowance.
        Some workspaces have a different limit.


        <Note>This endpoint accepts a personal API key, including a read-only
        one, from anyone with access to the app, viewers included. Workspace API
        keys are not authorized for it.</Note>
      operationId: file_list_api_apps__app_id__code_file_list_get
      parameters:
        - name: app_id
          in: path
          required: true
          schema:
            type: string
            description: ID of the app whose code to read.
            title: App Id
          description: ID of the app whose code to read.
          example: 6820f3a4e7b91d003c45a1f2
      responses:
        '200':
          description: The path of every file in the app's source.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/FileList'
        '401':
          description: Missing or invalid credentials.
        '403':
          description: You don't have access to this app, or you used a workspace API key.
        '404':
          description: App not found.
        '429':
          description: >-
            Too many requests for this app in the last minute from personal API
            keys in your workspace.
components:
  schemas:
    FileList:
      properties:
        paths:
          items:
            type: string
          type: array
          title: Paths
          description: Path of each file, relative to the app root.
          example:
            - package.json
            - src/App.jsx
            - src/pages/Home.jsx
      type: object
      required:
        - paths
      title: FileList
      description: The paths of the app's source files.
  securitySchemes:
    PersonalAccessTokenAuth:
      type: http
      scheme: bearer
      description: 'Personal access token, sent as `Authorization: Bearer <token>`.'

````