API keys
Authenticate server-side requests with a scoped organization key.
An organization admin creates keys in Developers > API keys in the console. If you are a developer without console access, ask an admin for a key with the scopes your integration needs.
Live and test keys
pw_live_ keys send real mail. pw_test_ keys validate sends without queueing or counting them. Both are real, organization-specific keys. The literal Postmark token POSTMARK_API_TEST is not accepted.
The full key is shown once when it is created. Store it in your server’s secret environment, never in browser JavaScript, mobile app bundles, public repositories, or logs.
Scopes
| Scope | Permits |
|---|---|
email:send | Send single and batch messages, and delete suppressions. |
email:read | Read outbound messages, message details, and suppressions. |
domains:read | List the organization’s domains. |
members:read | List the organization’s members. |
Every active key can call GET /v1/me without another scope. Keys apply to the whole organization, not one domain or mailbox. Missing scope returns HTTP 403.
Authentication headers
Send one of these headers:
Authorization: Bearer pw_live_replace_with_your_key
X-Postmark-Server-Token: pw_live_replace_with_your_key
X-Prawnwire-Server-Token: pw_live_replace_with_your_key The server checks X-Postmark-Server-Token first, then X-Prawnwire-Server-Token, then the Bearer header. Avoid sending multiple credentials in the same request.
Revoke and rotate
An admin can revoke a key from Developers > API keys. Revoked keys immediately fail authentication. To rotate without interrupting service, create a replacement, update and verify the application’s configuration, then revoke the old key.
Test keys are not a read-only sandbox. Their no-send behavior applies to email submission; a test key with email:send can still delete suppressions. Grant only the scopes the integration needs.