API keys & scopes
Every request carries an API key as a bearer token. Keys are for servers. If you are connecting an assistant rather than writing code, use the MCP server instead, which signs in through your browser and needs no key at all.
Getting a key
Create one from your account settings. The full key is shown once, at the moment it is created, and cannot be retrieved afterwards because only its hash is stored. Losing it means creating another.
Authorization: Bearer ak_a1b2c3d4e5f6a7b8_<secret>Keys look like ak_<id>_<secret>. The <id> half is public and identifies the key in your settings; the secret half is the part that must never reach a repository, a log or a browser.
Scopes
4 scopesA key carries scopes. write, publish and media each imply read. write and publish are separate rather than nested: creating a draft needs write, and creating a post that will actually go out needs publish. Keys created from settings carry all four scopes; there is no way to narrow a key there yet.
| Scope | Allows |
|---|---|
| read | Read posts and connected accounts. |
| write | Create drafts, and delete or cancel posts. |
| publish | Create a post that will actually go out, now or on a schedule. Sufficient on its own. |
| media | Reserved for media endpoints. No endpoint checks it yet, so granting it changes nothing today. |