Skip to main content
Authentication in Pomerado has two separate levels, and this page explains both.

Pomerado authentication

Every request to Pomerado carries one credential, sent as Authorization: Bearer:
  • OAuth sign-in. Your MCP client signs you in through a browser, with no key to handle. Best for chat and coding agents. See sign in with OAuth.
  • API key. A pom_ token for programs and headless agents. See API keys.
  • Integration key. An API key limited to one integration. See integration keys.
An agent without a browser can get an API key by having you approve a short code. See sign in with a code. Whatever the credential, it acts for one account and never with more than your role allows. See permissions. On the Dashboard, your session renews itself, so you sign in again only after it ends or you sign out. Only deleting the account and changing the password ask for a sign-in within the last five minutes.

Website logins

A website login is the account Pomerado signs in with on a site, such as your Instacart account. You save it once in the Dashboard, or on the protected page a job links to when it needs one, and jobs use it from then on. See saved logins.

How the two relate

The levels stay separate. Your Pomerado credential decides which saved logins a job may use, but it never holds a website password. Pomerado asks for a password only on its own protected pages, so never paste one into a chat or a request, and no API key or OAuth app can reveal one.