Skip to main content
Last Reviewed: 2026-09-29

Authenticate with the Pantheon Public API

Authentication

Learn how to authenticate with the Pantheon Public API using a Personal Access Token.


The Pantheon Public API authenticates every request with a Personal Access Token (PAT). Your token identifies you and grants the same access as your Pantheon account.

Warning:
Personal Access Tokens only

The Pantheon Public API supports Personal Access Tokens only. Legacy Machine Tokens are not supported.

Create a Personal Access Token

Follow the steps in Creating and Revoking Personal Access Tokens to create a token in your Personal Settings. Copy the token when it's shown, because you can't view it again.

Information:
Note

Personal Access Tokens expire 90 days after creation. If you use a token in an automated system, such as a CI/CD pipeline, plan to rotate it before it expires.

Store your token

Keep your token out of your scripts and source code. The examples in this guide read the token from the PANTHEON_TOKEN environment variable:

In CI/CD systems, store the token as a secret and expose it to your job as an environment variable.

Send the token with each request

Include your token in the Authorization header of every request, using the Bearer scheme:

Requests with a missing, expired, or revoked token are rejected.

Make your first request

Confirm that your token works by requesting the current user. This "who am I" request returns the Pantheon account that the token belongs to:

The response describes your user account, including your user ID, name, email address and more. This response is large and contains SSH key fingerprints. To show only the ID, name and email address fields with jq, structure your request like this:

Next steps

Now that you're authenticated, get information about a site.