Every tool that promises to manage your Ghost members asks for the same thing first: an Admin API key. PayGlue asks for one too, and so does every other automation that touches members.
What the request does not tell you is how much that key can do. I wrote this article as the answer I would want to read if I were the one pasting the key into a form.
What the key grants
Ghost has two APIs. The Content API is read only and public by design: it serves your published posts to your theme. The Admin API is the other one, and it does everything the admin screen does.
That means: read and edit posts, including drafts. Read and edit pages. Read, create and delete members. Manage newsletters, tiers, labels, settings, themes, staff users and integrations. Send emails through Ghost.
There is no narrower key. Ghost does not offer “members only” permissions on an integration. A tool that needs to create a member holds a key that could also read your unpublished drafts and change your theme. Whether it does any of that depends on the tool you hand the key to, and nothing in the key itself will tell you.
Why there is no way around it
I looked for one when I built this. Ghost has no webhook that creates a member from the outside, and no import endpoint a service could push to. I also found no setting anywhere that says “let this provider grant access”. The Admin API is the only door in, and the key is what opens it.
So from our side the key is the connection itself. Without it there is nothing for PayGlue to write to.
What PayGlue calls, exactly
Here is the complete list of what PayGlue does with your key. I wrote it with the adapter code open rather than from memory.
- Look up a member by email when a purchase arrives, so an existing member is updated instead of duplicated.
- Create or update that member: set them to comped, or to free plus a label, depending on whether Stripe is connected in your Ghost. Add or remove the
payglue-active,payglue-endedandpayglue-providerlabels that say where the member came from. - Subscribe the member to the newsletters you chose in the mapping, and trigger the welcome email you picked.
- Read your site settings, for the health check on the connection page and to see whether Stripe is connected, which decides between comped and free plus label.
That is all of it. PayGlue never reads a post, and it never touches pages, themes, staff users or integrations. It does not send emails through Ghost on its own either. The key gets used in two situations: when an event needs processing, and when you press the health check button. Nothing runs on a schedule.
Contrast: a tool that reads your content
The pay-per-read tool I wrote about last week uses its key differently, and its docs say so: after a reader unlocks an article, it fetches the full post through the Admin API and renders it into the page. For what that product does, that is a legitimate use. It is also a much wider level of access than ours, which is exactly why the list above matters. Two tools hold the same key and do very different things with it.
What happens to the key on our side
We encrypt it at rest and decrypt it only for the moment a call goes out. After you save it, the dashboard shows dots, and nobody, including me, can read it back. It stays in the EU. We never send it to a payment provider or to anyone else, and deleting your workspace or account deletes the key with it. The details, including the algorithm, are in the security overview.
How to keep control
Create the key as its own custom integration in Ghost, under Settings, Integrations, and name it PayGlue. That way it belongs to one tool. You can see in Ghost that it exists, and you can revoke it without touching anything else.
If you regenerate or delete the key, PayGlue’s copy stops working. Purchases keep arriving but cannot be turned into members, the health check goes red, the events page shows the failures, and you get an email once they repeat. Paste the new key and PayGlue retries the queued events.
One more thing the key does not do: it never gets used to look around. There is no scheduled call that lists your members or reads your settings to keep something in sync. The health check runs when you press the button, the member calls run when a purchase arrives, and between those two moments the key sits encrypted and unused.
That is the whole contract. If you would rather have it as a reference page than as an article, it lives in the docs as Why PayGlue needs a Ghost Admin API key.
