> ## Documentation Index
> Fetch the complete documentation index at: https://docs.pomerado.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Manage API keys

> Create, rotate and revoke the keys programs and agents use, including integration keys.

An API key is a long-lived token for programs and agents that can't sign in with OAuth. This page covers creating, rotating and revoking keys.

A key starts with `pom_`. Send it as `Authorization: Bearer pom_...` on the REST API or any Pomerado MCP. Each key belongs to you and to one account.

## Create a key

Create a key on the Dashboard's **Settings** > **API keys** page, by copying a setup that uses a key on the **Connect agent** page, or with `POST /v1/api-keys`.

* **Permissions.** By default, a key carries every permission you hold except `api_keys:manage`, `billing:manage` and `team:manage`. To include those, or to narrow the key, name 1 to 16 permissions.
* **Expiry.** A key lasts 90 days unless you choose 1 to 365. Once it expires, requests with it answer `401 unauthorized`.
* **Secret.** The secret is shown once. Keep it in a secret manager or an environment variable, never in a file you commit or share.

A key that creates other keys needs `api_keys:manage` itself:

```bash theme={null}
curl -X POST https://api.pomerado.ai/v1/api-keys \
  -H "Authorization: Bearer $POMERADO_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"name": "Nightly price check", "expires_in_days": 30}'
```

<Note>
  To keep a secret out of an agent's conversation, send `"deliver": "dashboard"`. The answer is a Dashboard link where you finish creating the key and see the secret.
</Note>

## Integration keys

An integration key works for one integration only. Create it with `integration_id`. It reaches only that integration's MCP, its tools and the jobs it started, and carries at most `tools:read`, `runs:create`, `jobs:read` and `jobs:cancel`. Use one to give a product agent a single site, such as Google Flights, and nothing more.

## Rotate a key

`POST /v1/api-keys/{id}/rotate` replaces a key's secret. The old secret stops working at once. The key keeps its ID, permissions, expiry and running jobs.

## Revoke a key

Revoke a key on the API keys page, or with `DELETE /v1/api-keys/{id}`. Requests with it are refused from then on, and the jobs it started stop. Revoke and replace any key that may have been exposed.

<Accordion title="Details">
  * A key never holds more than you do. If your role loses a permission, or you leave the account, the key loses it too.
  * You can hold up to 50 keys you haven't revoked.
  * A key never creates, rotates or revokes a key with a permission it lacks. It may always revoke itself.
  * A key can't reveal a saved login's password or read its authenticator code. Those answer a Dashboard link.
  * From an MCP client, use `call_pomerado_api` with `api_keys.create`, `api_keys.rotate` or `api_keys.revoke`.
</Accordion>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.