/v1 endpoint and the MCP server require a Pav API key, sent as a bearer
token.
Create a key
- Sign in at app.pav.bio.
- Open Settings → Developer.
- Create a key. Choose a personal key (tied to your user) or an organization key (tied to your organization).
- Copy the secret. It is shown once and cannot be retrieved later.
Rotate and revoke
Create a new key, move your clients to it, then revoke the old key in Settings → Developer. Revocation takes effect within a few minutes.Scopes
The API is read-only. Keys created without custom scopes work on every endpoint. A key created with custom scopes must includepav:pipeline:read;
otherwise requests return 403 forbidden.
Authentication errors
Example 401 response