pom_. Send it as Authorization: Bearer pom_... on the REST API or any Pomerado MCP. Each key belongs to you and to one account.
Create a key
Create a key on the Dashboard’s Settings > API keys page, by copying a setup that uses a key on the Connect agent page, or withPOST /v1/api-keys.
- Permissions. By default, a key carries every permission you hold except
api_keys:manage,billing:manageandteam:manage. To include those, or to narrow the key, name 1 to 16 permissions. - Expiry. A key lasts 90 days unless you choose 1 to 365. Once it expires, requests with it answer
401 unauthorized. - Secret. The secret is shown once. Keep it in a secret manager or an environment variable, never in a file you commit or share.
api_keys:manage itself:
To keep a secret out of an agent’s conversation, send
"deliver": "dashboard". The answer is a Dashboard link where you finish creating the key and see the secret.Integration keys
An integration key works for one integration only. Create it withintegration_id. It reaches only that integration’s MCP, its tools and the jobs it started, and carries at most tools:read, runs:create, jobs:read and jobs:cancel. Use one to give a product agent a single site, such as Google Flights, and nothing more.
Rotate a key
POST /v1/api-keys/{id}/rotate replaces a key’s secret. The old secret stops working at once. The key keeps its ID, permissions, expiry and running jobs.
Revoke a key
Revoke a key on the API keys page, or withDELETE /v1/api-keys/{id}. Requests with it are refused from then on, and the jobs it started stop. Revoke and replace any key that may have been exposed.
Details
Details
- A key never holds more than you do. If your role loses a permission, or you leave the account, the key loses it too.
- You can hold up to 50 keys you haven’t revoked.
- A key never creates, rotates or revokes a key with a permission it lacks. It may always revoke itself.
- A key can’t reveal a saved login’s password or read its authenticator code. Those answer a Dashboard link.
- From an MCP client, use
call_pomerado_apiwithapi_keys.create,api_keys.rotateorapi_keys.revoke.