limit and cursor and answer with their rows plus nextCursor. Pass nextCursor back as cursor until it is null.
- Cursors are opaque. A malformed cursor is
400 invalid_request. - Lists carry no total count.
- A
limitoutside the endpoint’s range is400 invalid_request.
GET /instruments/search takes limit 1–25 (default 10) and does not page. GET /api_keys is not paginated: an account holds at most 10 active keys.