Authentication
Authenticate with a management token.
The management API authenticates with management tokens. A token starts with pmk_mgmt_, belongs to one project, and can do anything in that project that a team member can: read and change documents, publish, and create or revoke keys and other tokens. Treat it like a password.
Create a token#
Open your project in PMKIN, go to its API page and create a management token. PMKIN shows the token once. Copy it and store it as a secret, for example in an environment variable:
export PMKIN_MANAGEMENT_TOKEN=pmk_mgmt_...
A token can create more tokens with POST /tokens, for example one per script, so you can revoke each on its own.
Send the token#
Put the token in the Authorization header after Bearer and one space:
curl "https://api.pmkin.io/members" \-H "Authorization: Bearer $PMKIN_MANAGEMENT_TOKEN"
When it fails#
A missing, unknown, revoked or expired token gets a 401:
{"_tag": "Unauthorized","message": "Missing or invalid management token. Send \"Authorization: Bearer pmk_mgmt_...\" with an active token for this project."}
Check that the header is spelled right, that the token is complete, and that it hasn’t been revoked on the project’s API page. A delivery key doesn’t work here, and a management token doesn’t work on the delivery API.
DELETE /tokens/:id.AI agents#
MCP clients can sign in with OAuth instead of a token, so nobody has to copy a secret. See MCP OAuth.