/v1 offers the same capabilities as the account MCP connection: find tools, run and build them, follow jobs, and manage saved logins and API keys. It accepts two kinds of bearer credential in the Authorization: Bearer header.
OAuth access tokens
An access token your MCP client obtained for the account MCP endpoint also works on/v1. It carries the same authorization: the permissions you granted, your account’s current role and the same jobs. A job started through MCP can be read and cancelled through /v1, and the other way round.
- Request the token for the account MCP endpoint’s exact URL as its
resource. There is no separate/v1resource. - An unauthenticated
/v1request returns401with aWWW-Authenticateheader whoseresource_metadatanames the account MCP endpoint’s protected-resource metadata. See authentication. - A token for an individual integration’s MCP endpoint does not work on
/v1.
API keys
An API key is a long-lived credential for programs that cannot complete an OAuth flow. Keys start withpom_. Each key belongs to you and to one account.
- Create keys on the Dashboard’s Settings → API keys page, or with
POST /v1/api-keysfrom a signed-in session. Creating or rotating a key needs a sign-in within the last five minutes. - The secret is shown once. Store it in a secret manager; Pomerado keeps only a digest and cannot show it again.
- A key never holds more than you do: if your role loses a permission, or you leave the account, the key loses it too.
- Every key expires, after 1 to 365 days. Rotate a key to replace its secret; the old secret stops working at once.
- Revoke a key on the Dashboard, with
DELETE /v1/api-keys/{id}, or with the MCP toolrevoke_api_key. Requests with it are refused from then on, and jobs it started stop. - An API key cannot list, create or revoke keys, reveal a saved login’s password or read its TOTP code. Those need you signed in.
Key management routes
Never send an API key or its secret in an MCP message, a URL or a log. Treat it like a password.