Management API

Authentication

Authenticate with a management token.

The management API authenticates with management tokens. A token starts with pmk_mgmt_, belongs to one project, and can do anything in that project that a team member can: read and change documents, publish, and create or revoke keys and other tokens. Treat it like a password.

Create a token#

Open your project in PMKIN, go to its API page and create a management token. PMKIN shows the token once. Copy it and store it as a secret, for example in an environment variable:

Terminal
export PMKIN_MANAGEMENT_TOKEN=pmk_mgmt_...

A token can create more tokens with POST /tokens, for example one per script, so you can revoke each on its own.

Send the token#

Put the token in the Authorization header after Bearer and one space:

curl "https://api.pmkin.io/members" \
-H "Authorization: Bearer $PMKIN_MANAGEMENT_TOKEN"

When it fails#

A missing, unknown, revoked or expired token gets a 401:

Response: 401 Unauthorized
{
"_tag": "Unauthorized",
"message": "Missing or invalid management token. Send \"Authorization: Bearer pmk_mgmt_...\" with an active token for this project."
}

Check that the header is spelled right, that the token is complete, and that it hasn’t been revoked on the project’s API page. A delivery key doesn’t work here, and a management token doesn’t work on the delivery API.

Keep tokens on the server
Never put a management token in browser code or a public repository. If one leaks, revoke it at once on the API page or with DELETE /tokens/:id.

AI agents#

MCP clients can sign in with OAuth instead of a token, so nobody has to copy a secret. See MCP OAuth.