antworkDOCS

API keys & scopes

Every request carries an API key as a bearer token. Keys are for servers. If you are connecting an assistant rather than writing code, use the MCP server instead, which signs in through your browser and needs no key at all.

Getting a key

Create one from your account settings. The full key is shown once, at the moment it is created, and cannot be retrieved afterwards because only its hash is stored. Losing it means creating another.

Authorization
Authorization: Bearer ak_a1b2c3d4e5f6a7b8_<secret>

Keys look like ak_<id>_<secret>. The <id> half is public and identifies the key in your settings; the secret half is the part that must never reach a repository, a log or a browser.

A revoked key stops working immediately on every server except one that used it in the last minute, which keeps a short cache. Revoke and rotate rather than waiting.

Scopes

4 scopes

A key carries scopes. write, publish and media each imply read. write and publish are separate rather than nested: creating a draft needs write, and creating a post that will actually go out needs publish. Keys created from settings carry all four scopes; there is no way to narrow a key there yet.

ScopeAllows
readRead posts and connected accounts.
writeCreate drafts, and delete or cancel posts.
publishCreate a post that will actually go out, now or on a schedule. Sufficient on its own.
mediaReserved for media endpoints. No endpoint checks it yet, so granting it changes nothing today.