Authentication

API Key Authentication

Mint API keys and authenticate machine-to-machine calls.

Key format

pnp_<environment>_<8 hex>.<secret>
  • The prefix (pnp_live_1a2b3c4d) identifies the key. It is safe to log and is shown in the dashboard list.
  • The secret (32 bytes, base64url) is shown exactly once, in the creation response. Store it in a secret manager.
  • live or test is part of the prefix, so a pasted key tells you which install it belongs to.

Sending the key

curl "https://staging-api.panoptesos.com/api/v1/public/orders" \
  -H "X-Api-Key: pnp_test_1a2b3c4d.YOUR_SECRET"

What a key can do

Effective permission is the owner's role capabilities AND the key's scopes. A key never exceeds the person who minted it. See Permissions & Scopes.

Three kinds of action stay closed to machines, whatever the scopes:

  • sign-in and every auth flow, and resetting another user's password;
  • minting API keys, OAuth clients and connector keys (so a leaked key cannot copy itself);
  • the vendor platform plane.

Key controls

Each key can carry a per-minute rate limit, a quota, an IP allow-list and an origin allow-list. A refusal answers 429 with a Retry-After header.

Session tokens (JWT)

A dashboard you build signs a user in through /api/v1/console/auth/* and sends Authorization: Bearer <accessToken>. Access tokens are short-lived; refresh tokens are single-use and rotate on every refresh.

OAuth (AI connectors)

AI clients connect through the OAuth 2.0 issuer at /api/v1/public/oauth/** with dynamic client registration. The user consents to each scope, one box at a time. An OAuth bearer is accepted on /api/v1/mcp only.