Skip to main content
Every /v1 endpoint and the MCP server require a Pav API key, sent as a bearer token.
The API Reference playground accepts the same key.

Create a key

  1. Sign in at app.pav.bio.
  2. Open Settings → Developer.
  3. Create a key. Choose a personal key (tied to your user) or an organization key (tied to your organization).
  4. Copy the secret. It is shown once and cannot be retrieved later.

Rotate and revoke

Create a new key, move your clients to it, then revoke the old key in Settings → Developer. Revocation takes effect within a few minutes.

Scopes

The API is read-only. Keys created without custom scopes work on every endpoint. A key created with custom scopes must include pav:pipeline:read; otherwise requests return 403 forbidden.

Authentication errors

Example 401 response
See Rate limits and errors for the full error list.
Treat a key like a password. Keep it out of source control, logs and client-side code. Read it from an environment variable or a secret store.