Skip to main content
The REST API under /v1 offers the same capabilities as the account MCP connection: find tools, run and build them, follow jobs, and manage saved logins and API keys. It accepts two kinds of bearer credential in the Authorization: Bearer header.

OAuth access tokens

An access token your MCP client obtained for the account MCP endpoint also works on /v1. It carries the same authorization: the permissions you granted, your account’s current role and the same jobs. A job started through MCP can be read and cancelled through /v1, and the other way round.
  • Request the token for the account MCP endpoint’s exact URL as its resource. There is no separate /v1 resource.
  • An unauthenticated /v1 request returns 401 with a WWW-Authenticate header whose resource_metadata names the account MCP endpoint’s protected-resource metadata. See authentication.
  • A token for an individual integration’s MCP endpoint does not work on /v1.

API keys

An API key is a long-lived credential for programs that cannot complete an OAuth flow. Keys start with pom_. Each key belongs to you and to one account.
  • Create keys on the Dashboard’s Settings → API keys page, or with POST /v1/api-keys from a signed-in session. Creating or rotating a key needs a sign-in within the last five minutes.
  • The secret is shown once. Store it in a secret manager; Pomerado keeps only a digest and cannot show it again.
  • A key never holds more than you do: if your role loses a permission, or you leave the account, the key loses it too.
  • Every key expires, after 1 to 365 days. Rotate a key to replace its secret; the old secret stops working at once.
  • Revoke a key on the Dashboard, with DELETE /v1/api-keys/{id}, or with the MCP tool revoke_api_key. Requests with it are refused from then on, and jobs it started stop.
  • An API key cannot list, create or revoke keys, reveal a saved login’s password or read its TOTP code. Those need you signed in.

Key management routes

Never send an API key or its secret in an MCP message, a URL or a log. Treat it like a password.