Authenticate with the Pantheon Public API
Authentication
Learn how to authenticate with the Pantheon Public API using a Personal Access Token.
The Pantheon Public API authenticates every request with a Personal Access Token (PAT). Your token identifies you and grants the same access as your Pantheon account.
The Pantheon Public API supports Personal Access Tokens only. Legacy Machine Tokens are not supported.
Create a Personal Access Token
Follow the steps in Creating and Revoking Personal Access Tokens to create a token in your Personal Settings. Copy the token when it's shown, because you can't view it again.
Personal Access Tokens expire 90 days after creation. If you use a token in an automated system, such as a CI/CD pipeline, plan to rotate it before it expires.
Store your token
Keep your token out of your scripts and source code. The examples in this guide read the token from the PANTHEON_TOKEN environment variable:
In CI/CD systems, store the token as a secret and expose it to your job as an environment variable.
Send the token with each request
Include your token in the Authorization header of every request, using the Bearer scheme:
Requests with a missing, expired, or revoked token are rejected.
Make your first request
Confirm that your token works by requesting the current user. This "who am I" request returns the Pantheon account that the token belongs to:
The response describes your user account, including your user ID, name, email address and more. This response is large and contains SSH key fingerprints. To show only the ID, name and email address fields with jq, structure your request like this:
Next steps
Now that you're authenticated, get information about a site.