Passmint
TemplatesIntegrationsDocsPricingBlog
Log inGet started
Passmint

Apple and Google Wallet passes from one API. Built for people who ship.

Product
  • Pass Designer
  • Developers
  • Distribution
  • Analytics
  • Templates
  • Integrations
  • Pricing
Developers
  • Documentation
  • API reference
  • Node SDK
  • Webhooks
  • MCP server
Company
  • Changelog
  • About
  • Contact
  • Support
  • Security
  • Terms
  • Privacy
Social
  • GitHub
  • X

© 2026 Passmint.

Apple Wallet & Google Wallet, one API.

Getting started

  • Overview
  • Quickstart

API

  • REST API reference
    • Authentication
    • Passes
    • Templates
    • Events
    • Webhooks
    • Errors
  • Webhooks
    • Event types
    • Creating a webhook
    • Payload format
    • Verifying signatures
    • Retries
  • MCP server
    • Install
    • The endpoint
    • Other clients
    • Read-only mode
    • Tools
    • Things worth knowing
    • Example prompts
    • What it doesn't do
    • Rate limits
  • Node.js SDK
    • Configuration
    • Passes
    • Templates
    • Webhook signatures
    • Errors
    • Idempotency

Open source

  • Passmint Package
AI agents

MCP server.

Connect Claude Code, Cursor, or any MCP client that can send an API key, and issue, update, and manage wallet passes in conversation. It's a hosted endpoint: there's no package to run, and your agent can install it for you.

01

Install

1. Create a test API key in Developers → API keys. It starts with pmk_test_.

2. Put it in your terminal. The install reads the key from this variable, so you never paste it into a chat with your agent. Then start your agent from the same terminal. (VS Code asks for the key itself, so skip this step.)

export PASSMINT_API_KEY=pmk_test_…

3. Install it in your client. Copy the setup prompt into your agent and it installs the server itself, or run the command yourself.

Let Claude Code set it up

Copy this prompt into Claude Code. It checks your key is set, runs the install, and confirms the connection. The key never goes into the chat.

Show the prompt
Install the Passmint MCP server in Claude Code for me.

1. Check that the PASSMINT_API_KEY environment variable is set, without printing its value: run `test -n "$PASSMINT_API_KEY" && echo set || echo missing`. If it's missing, stop and tell me to create a test API key at https://app.passmint.com/developers/keys, run `export PASSMINT_API_KEY=pmk_test_…` in my terminal, and restart you from that terminal.
2. Run this command. Your shell fills in the key, so it never appears in this chat:

claude mcp add --transport http --scope user passmint https://api.passmint.com/mcp \
  --header "Authorization: Bearer $PASSMINT_API_KEY"
3. Tell me to restart Claude Code so it loads the new server. Then call the Passmint `whoami` tool and tell me which organization I'm connected to and whether it's test or live mode.

Never ask me to paste the API key into this chat, and never print it, write it into a file in this project, or commit it.

Docs: https://passmint.com/docs/mcp

Or do it yourself

claude mcp add --transport http --scope user passmint https://api.passmint.com/mcp \
  --header "Authorization: Bearer $PASSMINT_API_KEY"

Stuck? See connecting an AI assistant in the help center.

02

The endpoint

The server lives at https://api.passmint.com/mcp and speaks the Streamable HTTP transport. Authenticate with the same secret API key you use for the REST API, as a bearer token in the Authorization header. A pmk_test_ key gives your assistant a test-mode connection, and a pmk_live_ key gives it a live one.

Start with a test key.A test-mode connection issues test passes and can never read or change a live pass. Templates are shared by test and live mode, so over a test key your assistant can create templates but not edit or archive them. When you're ready to issue real passes, run the install again with a live key.

Keep keys out of your repo. Every install above writes to your user-level config, not to a file in your project. If you add Passmint to a project-level file such as .cursor/mcp.json or .mcp.json, reference the environment variable rather than pasting the key.

03

Other clients

Any client that speaks Streamable HTTP and lets you set an Authorization header can connect with the same URL and key.

Custom connectors in the Claude apps (claude.ai and Claude Desktop) sign in with OAuth rather than an API key, and Passmint doesn't offer OAuth yet, so they can't connect today. Use Claude Code in the meantime.

04

Read-only mode

Add ?mode=read-only to the URL and the connection is given only the tools that read. Issuing, updating, voiding, and template changes disappear from the tool list entirely:

https://api.passmint.com/mcp?mode=read-only

Spelling is forgiving — readonly and READ-ONLY work too — but a modevalue we don't recognise is rejected outright rather than quietly giving you full access.

This is a guardrail, not a security boundary. It stops an assistant reaching for a tool you didn't want it to have — it does not stop anyone holding the key from opening a second connection without the flag. If you need enforcement, use a test-mode key you're willing to revoke — it can never touch a live pass.

05

Tools

Fifteen tools, built around what you actually do with passes rather than mapped one-to-one onto API endpoints.

  • whoami — Which organization this connection belongs to, test or live mode, your plan and usage against its limits, and your Apple certificates and Google issuers.
  • list_templates — Find a template to issue from. Returns names and ids, without the full design. Archived templates on request.
  • get_template — One template with its full design and scan policy, so the agent knows which field keys a pass can carry.
  • create_template — Create a template from a full design. Pass a starter_template_id for artwork — images can't be uploaded here.
  • update_template — Change a template's name, design, or platforms. Does not affect passes already issued. Needs a live key.
  • archive_template — Stop new issuance from a template. Existing passes keep working. Needs a live key and confirmation.
  • issue_pass — Issue a pass and return its add-to-wallet URL, plus any delivery warnings.
  • get_pass — One pass: field values, voided state, how many times it's been scanned, delivery status, wallet links.
  • list_passes — Passes in the organization, filterable by template or holder email.
  • update_pass — Change a pass's field values and re-render it for the holder's wallet.
  • void_pass — Permanently invalidate a pass. Cannot be undone. Requires confirmation.
  • get_pass_events — A pass's lifecycle history — including whether the holder actually installed it.
  • get_pass_redemptions — A pass's scan log: each scan accepted or rejected, why, and at which scanner.
  • create_pass_download_link — An expiring link to the pass. Required for templates that only allow download links.
  • get_pass_analytics — The funnel across passes: issued, added to wallet, active, removed, with confidence levels.

void_pass and archive_templateboth require an explicit confirmation before they'll act, because neither can be reversed through the API.

06

Things worth knowing

Updates aren't instantly visible. When a pass is updated, whether the holder sees a lock-screen message depends on the template: a field only produces a notification if it was given a change message in its design. And Apple passes currently refresh when the device next checks in rather than on a push, so an update is not immediate. Ask your assistant to say so rather than promising the holder an instant change.

Analytics carry confidence levels. Wallet platforms don't reliably report when someone deletes a pass, so get_pass_analytics marks removals, active counts, and update delivery rates with how sure we are. Anything not marked exact is an estimate.

Live passes need your own credentials. Live Apple passes are signed with your own Pass Type ID certificate, and live Google passes need your own issuer — both set up in Settings. Without them, issue_pass returns a warning for that platform rather than a working pass.

07

Example prompts

Things worth asking once you're connected:

  • “What pass templates do we have, and which one is the conference badge?”
  • “Issue a badge for Priya Raman, priya@example.com, seat 12B — give me the add-to-wallet link.”
  • “Has Priya's badge been scanned at the door yet?”
  • “What share of this month's conference badges have been added to a wallet?”
  • “How close are we to our API quota, and when does our Apple certificate expire?”
  • “How's the install rate on the summer promo compared to last month?”
  • “Find the pass for alex@example.com and void it — they requested a refund.”
08

What it doesn't do

  • Bulk changes. Each pass is updated or voided by its own tool call, within the rate limit below, and passes can be found only by template or holder email. For changes across many passes, use the REST API.
  • Images. Artwork comes from a starter template. Upload your own in the dashboard.
  • Webhooks, scanners, API keys, and certificates. These are set up in the dashboard. Your assistant can see which certificates and issuers you have, but can't add or change them.
  • Claude apps.claude.ai and Claude Desktop connectors need OAuth, which isn't available yet.
09

Rate limits

Tool calls are limited to 60 per minute per API key, on top of the normal API rate limits and your plan's monthly call quota. Every tool call counts as an API call for billing, exactly as if you had made the request yourself.

Up next:
The MCP server is a thin layer over the REST API — anything an assistant can do through it, you can do with an API call, and the same plan limits and permissions apply. Questions, or a client that won't connect? support@passmint.com.