What a Tool Can Do With Your Ghost Admin API Key, and What Ours Does

A single silver key lying on a dark reflective surface, lit from the sidePhoto: rc.xyz NFT gallery
On this page

Every tool that promises to manage your Ghost members asks for the same thing first: an Admin API key. PayGlue asks for one too, and so does every other automation that touches members.

What the request does not tell you is how much that key can do. I wrote this article as the answer I would want to read if I were the one pasting the key into a form.

What the key grants

Ghost has two APIs. The Content API is read only and public by design: it serves your published posts to your theme. The Admin API is the other one, and it does everything the admin screen does.

That means: read and edit posts, including drafts. Read and edit pages. Read, create and delete members. Manage newsletters, tiers, labels, settings, themes, staff users and integrations. Send emails through Ghost.

There is no narrower key. Ghost does not offer “members only” permissions on an integration. A tool that needs to create a member holds a key that could also read your unpublished drafts and change your theme. Whether it does any of that depends on the tool you hand the key to, and nothing in the key itself will tell you.

Why there is no way around it

I looked for one when I built this. Ghost has no webhook that creates a member from the outside, and no import endpoint a service could push to. I also found no setting anywhere that says “let this provider grant access”. The Admin API is the only door in, and the key is what opens it.

So from our side the key is the connection itself. Without it there is nothing for PayGlue to write to.

What PayGlue calls, exactly

Here is the complete list of what PayGlue does with your key. I wrote it with the adapter code open rather than from memory.

  • Look up a member by email when a purchase arrives, so an existing member is updated instead of duplicated.
  • Create or update that member: set them to comped, or to free plus a label, depending on whether Stripe is connected in your Ghost. Add or remove the payglue-active, payglue-ended and payglue-provider labels that say where the member came from.
  • Subscribe the member to the newsletters you chose in the mapping, and trigger the welcome email you picked.
  • Read your site settings, for the health check on the connection page and to see whether Stripe is connected, which decides between comped and free plus label.

That is all of it. PayGlue never reads a post, and it never touches pages, themes, staff users or integrations. It does not send emails through Ghost on its own either. The key gets used in two situations: when an event needs processing, and when you press the health check button. Nothing runs on a schedule.

Contrast: a tool that reads your content

The pay-per-read tool I wrote about last week uses its key differently, and its docs say so: after a reader unlocks an article, it fetches the full post through the Admin API and renders it into the page. For what that product does, that is a legitimate use. It is also a much wider level of access than ours, which is exactly why the list above matters. Two tools hold the same key and do very different things with it.

What happens to the key on our side

We encrypt it at rest and decrypt it only for the moment a call goes out. After you save it, the dashboard shows dots, and nobody, including me, can read it back. It stays in the EU. We never send it to a payment provider or to anyone else, and deleting your workspace or account deletes the key with it. The details, including the algorithm, are in the security overview.

How to keep control

Create the key as its own custom integration in Ghost, under Settings, Integrations, and name it PayGlue. That way it belongs to one tool. You can see in Ghost that it exists, and you can revoke it without touching anything else.

If you regenerate or delete the key, PayGlue’s copy stops working. Purchases keep arriving but cannot be turned into members, the health check goes red, the events page shows the failures, and you get an email once they repeat. Paste the new key and PayGlue retries the queued events.

One more thing the key does not do: it never gets used to look around. There is no scheduled call that lists your members or reads your settings to keep something in sync. The health check runs when you press the button, the member calls run when a purchase arrives, and between those two moments the key sits encrypted and unused.

That is the whole contract. If you would rather have it as a reference page than as an article, it lives in the docs as Why PayGlue needs a Ghost Admin API key.

Photo by rc.xyz NFT gallery on Unsplash

Frequently asked

Why does PayGlue need a Ghost Admin API key at all?

Because Ghost has exactly one way for an outside service to create or update a member: the Admin API. There is no webhook, import or setting that does it without the key.

What can an Admin API key do in Ghost?

Everything the admin can: read and edit posts, pages, members, newsletters, settings, themes and staff. Ghost does not offer a member-only key, so any tool that manages members holds a key that could also read your drafts.

What does PayGlue do with the key?

It looks up members by email, creates or updates them, sets labels and newsletter subscriptions, and reads your site settings for the health check. It never reads posts, never changes your theme and never touches staff users.

How do I revoke it?

Delete the custom integration in Ghost under Settings, Integrations. The key stops working immediately and PayGlue's health check goes red.