prawnwire Developers

API keys

Authenticate server-side requests with a scoped organization key.

An organization admin creates keys in Developers > API keys in the console. If you are a developer without console access, ask an admin for a key with the scopes your integration needs.

Live and test keys

pw_live_ keys send real mail. pw_test_ keys validate sends without queueing or counting them. Both are real, organization-specific keys. The literal Postmark token POSTMARK_API_TEST is not accepted.

The full key is shown once when it is created. Store it in your server’s secret environment, never in browser JavaScript, mobile app bundles, public repositories, or logs.

Scopes

ScopePermits
email:sendSend single and batch messages, and delete suppressions.
email:readRead outbound messages, message details, and suppressions.
domains:readList the organization’s domains.
members:readList the organization’s members.

Every active key can call GET /v1/me without another scope. Keys apply to the whole organization, not one domain or mailbox. Missing scope returns HTTP 403.

Authentication headers

Send one of these headers:

Choose one authentication header
Authorization: Bearer pw_live_replace_with_your_key
X-Postmark-Server-Token: pw_live_replace_with_your_key
X-Prawnwire-Server-Token: pw_live_replace_with_your_key

The server checks X-Postmark-Server-Token first, then X-Prawnwire-Server-Token, then the Bearer header. Avoid sending multiple credentials in the same request.

Revoke and rotate

An admin can revoke a key from Developers > API keys. Revoked keys immediately fail authentication. To rotate without interrupting service, create a replacement, update and verify the application’s configuration, then revoke the old key.

Test keys are not a read-only sandbox. Their no-send behavior applies to email submission; a test key with email:send can still delete suppressions. Grant only the scopes the integration needs.

Search documentation

Type to search the documentation.