Authentication
API Key Authentication
Mint API keys and authenticate machine-to-machine calls.
Key format
pnp_<environment>_<8 hex>.<secret>
- The prefix (
pnp_live_1a2b3c4d) identifies the key. It is safe to log and is shown in the dashboard list. - The secret (32 bytes, base64url) is shown exactly once, in the creation response. Store it in a secret manager.
liveortestis part of the prefix, so a pasted key tells you which install it belongs to.
Sending the key
curl "https://staging-api.panoptesos.com/api/v1/public/orders" \
-H "X-Api-Key: pnp_test_1a2b3c4d.YOUR_SECRET"
What a key can do
Effective permission is the owner's role capabilities AND the key's scopes. A key never exceeds the person who minted it. See Permissions & Scopes.
Three kinds of action stay closed to machines, whatever the scopes:
- sign-in and every auth flow, and resetting another user's password;
- minting API keys, OAuth clients and connector keys (so a leaked key cannot copy itself);
- the vendor platform plane.
Key controls
Each key can carry a per-minute rate limit, a quota, an IP allow-list and an origin allow-list.
A refusal answers 429 with a Retry-After header.
Session tokens (JWT)
A dashboard you build signs a user in through /api/v1/console/auth/* and sends
Authorization: Bearer <accessToken>. Access tokens are short-lived; refresh tokens are
single-use and rotate on every refresh.
OAuth (AI connectors)
AI clients connect through the OAuth 2.0 issuer at /api/v1/public/oauth/** with dynamic client
registration. The user consents to each scope, one box at a time. An OAuth bearer is accepted on
/api/v1/mcp only.