Skip to main content

Browser sessions

Authorization requests expire after ten minutes. Browser login grants account and analytics reads, media access, and post reading, editing, and publishing. Post deletion is excluded. Use a separately scoped API key for deletion. Device sessions last at most 90 days. Their access tokens last at most one hour and renew automatically. Manage devices under Project settings → Connected apps.
For a browser session, logout revokes the device before removing local credentials. auth logout --local removes only the local file. For a manually supplied API key, logout removes the local copy without revoking the key; revoke it in the dashboard when needed.

API keys and automation

Create a customer key in API keys, with permissions appropriate for the job. Provide it through your environment or pipe it into login:
Setting POSTINGER_API_KEY is also enough to run commands without a saved login. It overrides saved credentials. Pair it with POSTINGER_API_URL when using another environment.

Choose a server

An explicit --api-url takes priority over the environment and saved URL. Without explicit configuration, the CLI uses the saved login’s URL or https://api.dev.postinger.dev. A saved credential cannot silently move to another server. Credentials live in $XDG_CONFIG_HOME/postinger/config.json, or ~/.config/postinger/config.json. This is a plaintext file with owner-only permissions. Do not commit it or copy it into an MCP tool argument.