Skip to main content
An API key is a long-lived token for programs and agents that can’t sign in with OAuth. This page covers creating, rotating and revoking keys. A key starts with pom_. Send it as Authorization: Bearer pom_... on the REST API or any Pomerado MCP. Each key belongs to you and to one account.

Create a key

Create a key on the Dashboard’s Settings > API keys page, by copying a setup that uses a key on the Connect agent page, or with POST /v1/api-keys.
  • Permissions. By default, a key carries every permission you hold except api_keys:manage, billing:manage and team:manage. To include those, or to narrow the key, name 1 to 16 permissions.
  • Expiry. A key lasts 90 days unless you choose 1 to 365. Once it expires, requests with it answer 401 unauthorized.
  • Secret. The secret is shown once. Keep it in a secret manager or an environment variable, never in a file you commit or share.
A key that creates other keys needs api_keys:manage itself:
To keep a secret out of an agent’s conversation, send "deliver": "dashboard". The answer is a Dashboard link where you finish creating the key and see the secret.

Integration keys

An integration key works for one integration only. Create it with integration_id. It reaches only that integration’s MCP, its tools and the jobs it started, and carries at most tools:read, runs:create, jobs:read and jobs:cancel. Use one to give a product agent a single site, such as Google Flights, and nothing more.

Rotate a key

POST /v1/api-keys/{id}/rotate replaces a key’s secret. The old secret stops working at once. The key keeps its ID, permissions, expiry and running jobs.

Revoke a key

Revoke a key on the API keys page, or with DELETE /v1/api-keys/{id}. Requests with it are refused from then on, and the jobs it started stop. Revoke and replace any key that may have been exposed.
  • A key never holds more than you do. If your role loses a permission, or you leave the account, the key loses it too.
  • You can hold up to 50 keys you haven’t revoked.
  • A key never creates, rotates or revokes a key with a permission it lacks. It may always revoke itself.
  • A key can’t reveal a saved login’s password or read its authenticator code. Those answer a Dashboard link.
  • From an MCP client, use call_pomerado_api with api_keys.create, api_keys.rotate or api_keys.revoke.