Authentication
Authenticate with a delivery key in the Authorization header.
Every request to the delivery API carries a delivery key. The key decides which project’s content you get, so there’s no project id in the queries. Delivery keys can only read: they can’t change anything in PMKIN.
Create a delivery key#
Open your project’s API page
In PMKIN, open the project and choose API in the menu. It lists the project’s keys and the endpoint.
Create a key
Choose Create key, keep the access at Read and name the key after where it’s used, like “Website (production)”. One key per site or environment means you can revoke one without breaking the others.
Store it as a secret
Copy the key into your site’s environment, for example as
PMKIN_API_KEY. PMKIN shows the full key only once.
Send the key#
Put the key in the Authorization header with the Bearer scheme:
curl https://content.pmkin.io/graphql \--header "Authorization: Bearer $PMKIN_API_KEY" \--header "Content-Type: application/json" \--data '{"query": "{ categories { name slug } }"}'
A delivery key can list drafts’ titles and slugs with includeDrafts, and every request with it counts towards your usage. Fetch content in server code, at build time or in an API route, and don’t ship the key to browsers.
Revoke a key#
Revoke a key on the project’s API page when it leaks or a site goes away. Requests with a revoked key get a 401. Each server remembers keys for up to 10 seconds, so a revoked key can keep working that long.
Keys can also expire. A request with an expired key gets a 400 with the code UNAUTHENTICATED. Create a new key and swap it in.
Authentication errors#
| Status | Body | What to do |
|---|---|---|
| 401 | {"error":"Unauthorized: Bearer token missing or malformed"} | Send the header as Authorization: Bearer <key>, with nothing else around the key. |
| 401 | {"error":"Unauthorized."} | The key doesn’t exist or was revoked. Check it for typos, or create a new one. |
| 400 | UNAUTHENTICATED | The key has expired. Create a new one. |
See Errors for every error the API returns.