Delivery API

Authentication

Authenticate with a delivery key in the Authorization header.

Every request to the delivery API carries a delivery key. The key decides which project’s content you get, so there’s no project id in the queries. Delivery keys can only read: they can’t change anything in PMKIN.

Create a delivery key#

  1. Open your project’s API page

    In PMKIN, open the project and choose API in the menu. It lists the project’s keys and the endpoint.

  2. Create a key

    Choose Create key, keep the access at Read and name the key after where it’s used, like “Website (production)”. One key per site or environment means you can revoke one without breaking the others.

  3. Store it as a secret

    Copy the key into your site’s environment, for example as PMKIN_API_KEY. PMKIN shows the full key only once.

Send the key#

Put the key in the Authorization header with the Bearer scheme:

bash
curl https://content.pmkin.io/graphql \
--header "Authorization: Bearer $PMKIN_API_KEY" \
--header "Content-Type: application/json" \
--data '{"query": "{ categories { name slug } }"}'
Keep keys on the server

A delivery key can list drafts’ titles and slugs with includeDrafts, and every request with it counts towards your usage. Fetch content in server code, at build time or in an API route, and don’t ship the key to browsers.

Revoke a key#

Revoke a key on the project’s API page when it leaks or a site goes away. Requests with a revoked key get a 401. Each server remembers keys for up to 10 seconds, so a revoked key can keep working that long.

Keys can also expire. A request with an expired key gets a 400 with the code UNAUTHENTICATED. Create a new key and swap it in.

Authentication errors#

StatusBodyWhat to do
401{"error":"Unauthorized: Bearer token missing or malformed"}Send the header as Authorization: Bearer <key>, with nothing else around the key.
401{"error":"Unauthorized."}The key doesn’t exist or was revoked. Check it for typos, or create a new one.
400UNAUTHENTICATEDThe key has expired. Create a new one.

See Errors for every error the API returns.