Management API

Keys and tokens

Create and revoke delivery keys, management tokens and OAuth grants.

Manage the credentials that reach your project. A secret is shown only once, in the response that creates it. Lists show a short preview, so you can tell credentials apart without exposing them.

Revoking is immediate
Revoking can’t be undone. Create the replacement and deploy it before you revoke the old credential.

Delivery keys#

Delivery keys let your website read published content from the delivery API. They can’t change anything.

List delivery keys#

GET/keys

Lists the project’s delivery keys. The secret isn’t included: it’s shown only once, when the key is created.

curl "https://api.pmkin.io/keys" \
-H "Authorization: Bearer $PMKIN_MANAGEMENT_TOKEN"
Response: 200 OK
[
{
"createdAt": "2026-10-09T09:00:00.000Z",
"id": "6703e5f6a7b8c9d0e1f2a3b4",
"lastUsedAt": "2026-10-10T18:22:31.000Z",
"name": "Website",
"previewKey": "a1b...9f0",
"projectId": "66f0b2c4d5e6f7a8b9c0d1e2",
"teamId": "66f0b2c4d5e6f7a8b9c0d1e1"
}
]

Create a delivery key#

POST/keys

Creates a read-only delivery key for the delivery API. The response has the secret in key, the only time you see it. Store it now.

Body
namestringrequired
expiresAtstring
curl -X POST "https://api.pmkin.io/keys" \
-H "Authorization: Bearer $PMKIN_MANAGEMENT_TOKEN" \
-H "Content-Type: application/json" \
-d '{
"name": "Website"
}'
Response: 200 OK
{
"createdAt": "2026-10-09T09:00:00.000Z",
"id": "6703e5f6a7b8c9d0e1f2a3b4",
"lastUsedAt": null,
"name": "Website",
"previewKey": "a1b...9f0",
"projectId": "66f0b2c4d5e6f7a8b9c0d1e2",
"teamId": "66f0b2c4d5e6f7a8b9c0d1e1",
"key": "a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0"
}

Revoke a delivery key#

DELETE/keys/:id

Revokes the key and returns it with revokedAt. Requests with it then get the delivery API’s unknown-key 401, within 10 seconds.

Path parameters
idstringrequired
Errors
NotFound404
curl -X DELETE "https://api.pmkin.io/keys/6703e5f6a7b8c9d0e1f2a3b4" \
-H "Authorization: Bearer $PMKIN_MANAGEMENT_TOKEN"
Response: 200 OK
{
"createdAt": "2026-10-09T09:00:00.000Z",
"id": "6703e5f6a7b8c9d0e1f2a3b4",
"lastUsedAt": "2026-10-10T18:22:31.000Z",
"name": "Website",
"previewKey": "a1b...9f0",
"projectId": "66f0b2c4d5e6f7a8b9c0d1e2",
"teamId": "66f0b2c4d5e6f7a8b9c0d1e1",
"revokedAt": "2026-10-11T08:00:00.000Z"
}

Management tokens#

Management tokens authenticate this API. Give each script or agent its own token, so you can see what each one did and revoke it alone.

List management tokens#

GET/tokens

Lists the project’s management tokens. lastClient is API for REST calls, or the MCP client’s name.

curl "https://api.pmkin.io/tokens" \
-H "Authorization: Bearer $PMKIN_MANAGEMENT_TOKEN"
Response: 200 OK
[
{
"createdAt": "2026-10-01T09:00:00.000Z",
"id": "6703f6a7b8c9d0e1f2a3b4c5",
"lastClient": "Claude Code",
"lastMcpAt": "2026-10-10T18:20:05.000Z",
"lastUsedAt": "2026-10-10T18:20:05.000Z",
"name": "Writing agent",
"previewToken": "pmk_mgmt_ab...c3d",
"projectId": "66f0b2c4d5e6f7a8b9c0d1e2"
}
]

Create a management token#

POST/tokens

Creates a management token for this project. The response has the secret in token, the only time you see it.

Body
namestringrequired
expiresAtstring
curl -X POST "https://api.pmkin.io/tokens" \
-H "Authorization: Bearer $PMKIN_MANAGEMENT_TOKEN" \
-H "Content-Type: application/json" \
-d '{
"expiresAt": "2027-01-01T00:00:00Z",
"name": "Publishing script"
}'
Response: 200 OK
{
"createdAt": "2026-10-11T08:00:00.000Z",
"expiresAt": "2027-01-01T00:00:00Z",
"id": "6703f6a7b8c9d0e1f2a3b4c6",
"name": "Publishing script",
"previewToken": "pmk_mgmt_9f...e21",
"projectId": "66f0b2c4d5e6f7a8b9c0d1e2",
"token": "pmk_mgmt_9f8e7d6c5b4a39281706f5e4d3c2b1a0e21"
}

Revoke a management token#

DELETE/tokens/:id

Revokes the token and returns it with revokedAt. It stops working at once, including for the caller if it revokes itself.

Path parameters
idstringrequired
Errors
NotFound404
curl -X DELETE "https://api.pmkin.io/tokens/6703f6a7b8c9d0e1f2a3b4c5" \
-H "Authorization: Bearer $PMKIN_MANAGEMENT_TOKEN"
Response: 200 OK
{
"createdAt": "2026-10-01T09:00:00.000Z",
"id": "6703f6a7b8c9d0e1f2a3b4c5",
"lastClient": "Claude Code",
"lastMcpAt": "2026-10-10T18:20:05.000Z",
"lastUsedAt": "2026-10-10T18:20:05.000Z",
"name": "Writing agent",
"previewToken": "pmk_mgmt_ab...c3d",
"projectId": "66f0b2c4d5e6f7a8b9c0d1e2",
"revokedAt": "2026-10-11T08:00:00.000Z"
}

Connected apps#

AI clients that sign in to the MCP server with OAuth get a grant instead of a token. Grants act as the person who connected the app.

List connected apps#

GET/oauth-grants

Lists the apps people connected to this project over MCP OAuth, with who connected each. projectId is null for a connection that reaches all of that person’s projects.

curl "https://api.pmkin.io/oauth-grants" \
-H "Authorization: Bearer $PMKIN_MANAGEMENT_TOKEN"
Response: 200 OK
[
{
"clientId": "c7f1e2d3a4b5",
"clientName": "Claude",
"createdAt": "2026-10-02T10:00:00.000Z",
"id": "6707a9b0c1d2e3f4a5b6c7d8",
"lastUsedAt": "2026-10-10T17:45:12.000Z",
"projectId": null,
"userId": "66f0b2c4d5e6f7a8b9c0d1f0",
"userName": "Maja Lind"
}
]

Disconnect an app#

DELETE/oauth-grants/:id

Disconnects the app: its access and refresh tokens stop working at once. A connection that reaches all of a person’s projects is disconnected from all of them.

Path parameters
idstringrequired
Errors
NotFound404
curl -X DELETE "https://api.pmkin.io/oauth-grants/6707a9b0c1d2e3f4a5b6c7d8" \
-H "Authorization: Bearer $PMKIN_MANAGEMENT_TOKEN"
Response: 200 OK
{
"clientId": "c7f1e2d3a4b5",
"clientName": "Claude",
"createdAt": "2026-10-02T10:00:00.000Z",
"id": "6707a9b0c1d2e3f4a5b6c7d8",
"lastUsedAt": "2026-10-10T17:45:12.000Z",
"projectId": null,
"userId": "66f0b2c4d5e6f7a8b9c0d1f0",
"userName": "Maja Lind",
"revokedAt": "2026-10-11T08:00:00.000Z"
}