NibAdmin API key

Creating your Ghost Admin API key

Nib has no account system of its own. It signs in to your blog the way Ghost expects a third-party tool to: with an Admin API key that you create on your own site and can revoke at any time.

It takes about three minutes, once per blog.

The five steps

  1. Open Ghost Admin on your site

    That is your blog address with /ghost/ on the end, for example https://example.com/ghost/. You need to be the Owner or an Administrator. Editors and Contributors cannot create integrations.

  2. Go to Settings, Advanced, Integrations

    On Ghost 5 and 6, Integrations sits under Settings in the Advanced group. Older versions of the admin panel put it in the left sidebar.

  3. Add a custom integration and call it Nib

    Scroll past the built-in integrations to Add custom integration. The name lets you find this key later and revoke only this one, without touching anything else you have connected.

  4. Copy the Admin API Key, not the Content API Key

    The integration page shows three values. Nib needs the Admin API Key: a long identifier, a colon, and a longer secret, like 6410…a2:9f3c…7be1. The Content API key is read-only and cannot publish. Pasting it gives an authentication error in the last step.

  5. Paste it into Nib

    In Nib, enter your site address and paste the key. Nib signs a short-lived token with it and calls your site straight away. If that call fails, Nib undoes the half-made connection and shows the error then, rather than the first time you publish. Nib stores the key encrypted on the phone and uses it only to talk to your own site.

What the key can do. A Ghost Admin API key has the same access as the admin panel, because Ghost offers no narrower scope. Give Nib its own integration rather than reusing one. Revoking it is then one click on your own site, and it stops working at once.

When it will not connect

“Authentication failed” or a 401 error

Usually the Content API key instead of the Admin API key, or a partial copy. Copy the Admin API Key again in full. It must contain a colon with characters on both sides.

The address changes as you type it

Phone keyboards autocorrect domains. A Polish keyboard turns wspanialy.eu into wspaniały.eu before you press connect. Nib turns off autocorrect and capitalisation on the address and key fields for this reason. If a value pasted from a password manager still looks changed, retype the last few characters and check.

A self-hosted site behind Cloudflare Access, basic auth or a VPN

Nib talks to /ghost/api/admin/ directly. Anything in front of your site that asks for a second login refuses the request before Ghost sees it. Allow the API path, or connect from inside the network.

Plain http, or a self-signed certificate

Release builds of Nib block unencrypted HTTP, so an http:// site will not connect, and there is no per-site switch. An Admin API key sent unencrypted is a key you have given away. Put a certificate in front of Ghost. Let's Encrypt is free.

Ghost in a subdirectory

If Ghost runs at example.com/blog/, enter the address with that path. Nib tidies the URL but cannot guess a subdirectory you left out.

Still stuck

In Nib, Settings, Help, Report a problem opens an email with your app version and phone model filled in, and nothing else: no blog address, no key, no draft. Add what you saw and I will answer.

Revoking it later

Go to the same page where you created it. Delete the Nib integration in Ghost Admin and the key stops working everywhere at once, including on a phone you no longer have. Removing the blog inside Nib also deletes the stored key, its drafts and its offline queue from the phone.

Have your key ready?

Install Nib, enter your site address, paste the key. No blog yet? Choose Explore demo on the setup screen.

Get Nib on Google Play

Free to write and publish. Android 8.0 or newer.