Keys and tokens
Create and revoke delivery keys, management tokens and OAuth grants.
Manage the credentials that reach your project. A secret is shown only once, in the response that creates it. Lists show a short preview, so you can tell credentials apart without exposing them.
Delivery keys#
Delivery keys let your website read published content from the delivery API. They can’t change anything.
List delivery keys#
/keysLists the project’s delivery keys. The secret isn’t included: it’s shown only once, when the key is created.
curl "https://api.pmkin.io/keys" \-H "Authorization: Bearer $PMKIN_MANAGEMENT_TOKEN"
[{"createdAt": "2026-10-09T09:00:00.000Z","id": "6703e5f6a7b8c9d0e1f2a3b4","lastUsedAt": "2026-10-10T18:22:31.000Z","name": "Website","previewKey": "a1b...9f0","projectId": "66f0b2c4d5e6f7a8b9c0d1e2","teamId": "66f0b2c4d5e6f7a8b9c0d1e1"}]
Create a delivery key#
/keysCreates a read-only delivery key for the delivery API. The response has the secret in key, the only time you see it. Store it now.
namestringrequired- A name that says what uses it, such as
WebsiteorWriting agent. expiresAtstring- When it stops working, as an ISO 8601 timestamp. Leave it out for no expiry.
curl -X POST "https://api.pmkin.io/keys" \-H "Authorization: Bearer $PMKIN_MANAGEMENT_TOKEN" \-H "Content-Type: application/json" \-d '{"name": "Website"}'
{"createdAt": "2026-10-09T09:00:00.000Z","id": "6703e5f6a7b8c9d0e1f2a3b4","lastUsedAt": null,"name": "Website","previewKey": "a1b...9f0","projectId": "66f0b2c4d5e6f7a8b9c0d1e2","teamId": "66f0b2c4d5e6f7a8b9c0d1e1","key": "a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6e7f8a9b0c1d2e3f4a5b6c7d8e9f0"}
Revoke a delivery key#
/keys/:idRevokes the key and returns it with revokedAt. Requests with it then get the delivery API’s unknown-key 401, within 10 seconds.
idstringrequired- The key’s id.
NotFound404- No key with this id in the token’s project.
curl -X DELETE "https://api.pmkin.io/keys/6703e5f6a7b8c9d0e1f2a3b4" \-H "Authorization: Bearer $PMKIN_MANAGEMENT_TOKEN"
{"createdAt": "2026-10-09T09:00:00.000Z","id": "6703e5f6a7b8c9d0e1f2a3b4","lastUsedAt": "2026-10-10T18:22:31.000Z","name": "Website","previewKey": "a1b...9f0","projectId": "66f0b2c4d5e6f7a8b9c0d1e2","teamId": "66f0b2c4d5e6f7a8b9c0d1e1","revokedAt": "2026-10-11T08:00:00.000Z"}
Management tokens#
Management tokens authenticate this API. Give each script or agent its own token, so you can see what each one did and revoke it alone.
List management tokens#
/tokensLists the project’s management tokens. lastClient is API for REST calls, or the MCP client’s name.
curl "https://api.pmkin.io/tokens" \-H "Authorization: Bearer $PMKIN_MANAGEMENT_TOKEN"
[{"createdAt": "2026-10-01T09:00:00.000Z","id": "6703f6a7b8c9d0e1f2a3b4c5","lastClient": "Claude Code","lastMcpAt": "2026-10-10T18:20:05.000Z","lastUsedAt": "2026-10-10T18:20:05.000Z","name": "Writing agent","previewToken": "pmk_mgmt_ab...c3d","projectId": "66f0b2c4d5e6f7a8b9c0d1e2"}]
Create a management token#
/tokensCreates a management token for this project. The response has the secret in token, the only time you see it.
namestringrequired- A name that says what uses it, such as
WebsiteorWriting agent. expiresAtstring- When it stops working, as an ISO 8601 timestamp. Leave it out for no expiry.
curl -X POST "https://api.pmkin.io/tokens" \-H "Authorization: Bearer $PMKIN_MANAGEMENT_TOKEN" \-H "Content-Type: application/json" \-d '{"expiresAt": "2027-01-01T00:00:00Z","name": "Publishing script"}'
{"createdAt": "2026-10-11T08:00:00.000Z","expiresAt": "2027-01-01T00:00:00Z","id": "6703f6a7b8c9d0e1f2a3b4c6","name": "Publishing script","previewToken": "pmk_mgmt_9f...e21","projectId": "66f0b2c4d5e6f7a8b9c0d1e2","token": "pmk_mgmt_9f8e7d6c5b4a39281706f5e4d3c2b1a0e21"}
Revoke a management token#
/tokens/:idRevokes the token and returns it with revokedAt. It stops working at once, including for the caller if it revokes itself.
idstringrequired- The token’s id.
NotFound404- No token with this id in the project.
curl -X DELETE "https://api.pmkin.io/tokens/6703f6a7b8c9d0e1f2a3b4c5" \-H "Authorization: Bearer $PMKIN_MANAGEMENT_TOKEN"
{"createdAt": "2026-10-01T09:00:00.000Z","id": "6703f6a7b8c9d0e1f2a3b4c5","lastClient": "Claude Code","lastMcpAt": "2026-10-10T18:20:05.000Z","lastUsedAt": "2026-10-10T18:20:05.000Z","name": "Writing agent","previewToken": "pmk_mgmt_ab...c3d","projectId": "66f0b2c4d5e6f7a8b9c0d1e2","revokedAt": "2026-10-11T08:00:00.000Z"}
Connected apps#
AI clients that sign in to the MCP server with OAuth get a grant instead of a token. Grants act as the person who connected the app.
List connected apps#
/oauth-grantsLists the apps people connected to this project over MCP OAuth, with who connected each. projectId is null for a connection that reaches all of that person’s projects.
curl "https://api.pmkin.io/oauth-grants" \-H "Authorization: Bearer $PMKIN_MANAGEMENT_TOKEN"
[{"clientId": "c7f1e2d3a4b5","clientName": "Claude","createdAt": "2026-10-02T10:00:00.000Z","id": "6707a9b0c1d2e3f4a5b6c7d8","lastUsedAt": "2026-10-10T17:45:12.000Z","projectId": null,"userId": "66f0b2c4d5e6f7a8b9c0d1f0","userName": "Maja Lind"}]
Disconnect an app#
/oauth-grants/:idDisconnects the app: its access and refresh tokens stop working at once. A connection that reaches all of a person’s projects is disconnected from all of them.
idstringrequired- The connected app’s id.
NotFound404- No connected app with this id for the project.
curl -X DELETE "https://api.pmkin.io/oauth-grants/6707a9b0c1d2e3f4a5b6c7d8" \-H "Authorization: Bearer $PMKIN_MANAGEMENT_TOKEN"
{"clientId": "c7f1e2d3a4b5","clientName": "Claude","createdAt": "2026-10-02T10:00:00.000Z","id": "6707a9b0c1d2e3f4a5b6c7d8","lastUsedAt": "2026-10-10T17:45:12.000Z","projectId": null,"userId": "66f0b2c4d5e6f7a8b9c0d1f0","userName": "Maja Lind","revokedAt": "2026-10-11T08:00:00.000Z"}