> ## Documentation Index
> Fetch the complete documentation index at: https://docs.postinger.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Authentication and permissions

> Authorize one project and grant the access your integration needs.

## Choose an authentication method

| Interface | Authentication |
| - | - |
| CLI | Browser device login or customer API key |
| Remote MCP | Browser OAuth or customer API key |
| HTTP API | Customer API key as a Bearer token |

Project admins create API keys in **API keys**. Copy the key when it is created and store it securely; it is not displayed again. Use customer keys beginning with `pst_`, never provider administration keys.

```http theme={null}
Authorization: Bearer pst_your_customer_key
```

## Permissions

| Permission | Allows |
| - | - |
| `accounts-read` | List accounts and read publishing capabilities |
| `media-read` | Read media status |
| `media-write` | Reserve, transfer, complete, and abort uploads |
| `posts-read` | List and inspect posts |
| `posts-write` | Create and edit drafts |
| `posts-publish` | Publish; also required alongside `posts-write` for scheduling |
| `posts-delete` | Delete Postinger posts |
| `analytics-read` | Read stored analytics and analytics capabilities |

Editing a scheduled post also needs `posts-publish`, including when removing its schedule. Verify effective permissions with `GET /auth/session` or `postinger auth status --json`.

## Pause, revoke, or disconnect

Manage API keys in **API keys** and browser-authorized CLI/MCP connections in **Project settings → Connected apps**. A paused API key returns `403` with `api_key_paused`. Revoked or expired credentials cannot authorize new work. Previously accepted scheduled posts are not canceled by revoking credentials.


## Related topics

- [CLI authentication](/cli/authentication.md)
- [Verify API credentials and inspect project, expiry and effective permissions](/api-reference/authentication/verify-api-credentials-and-inspect-project-expiry-and-effective-permissions.md)
- [Retries, limits, and errors](/guides/retries-and-errors.md)
- [CLI quickstart](/cli/quickstart.md)
- [Automate with the CLI](/cli/automation.md)


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.