G

Ghost Admin API

REST discovered

Details
URL
https://{admin_domain}/ghost/api/admin/
Docs
https://docs.ghost.org/admin-api
Authentication
Admin API key for JWT token authentication compound discovered Get key ↗
Authorization: Ghost <credential>

In Ghost Admin, create a new Custom Integration from the Integrations screen and copy the Admin API key. This secret key is then used server-side to generate short-lived JWTs for requests. The docs describe this under token authentication and note that keys for individual users can also be found on their profile page: Admin API overview and Admin API JavaScript client.

Staff access token bearer discovered Get token ↗
Authorization: Ghost <credential>

Open the staff user's settings/profile page in Ghost Admin and copy the staff access token. The Admin API docs say staff access token authentication uses a token found in a user’s settings page and authenticates as that user with role-based permissions: Admin API overview.

Staff user email/password for session authentication basic discovered Get credentials ↗

Use a Ghost staff account's email address and password to sign in through the Admin API session flow. The docs state that user authentication uses email address and password, exchanges them for a cookie-based session via the session API, and may require second-factor codes: Admin API overview.