Posteady
Posteady Docs
GuidesAPI referenceMCP
GuidesGetting started

Authentication

Create, use, and revoke a workspace API key.

Every REST request uses a workspace API key. Create one in Posteady settings → API keys while the intended workspace is selected. REST access requires Creator or above.

Get an API key

Send the key

export POSTEADY_API_KEY="pk_replace_with_your_key"
curl https://www.posteady.com/api/v1/accounts \
  --header "Authorization: Bearer $POSTEADY_API_KEY"

Keep the full key when it is shown immediately after creation; it cannot be read again from the key list. Store it in a server-side environment variable or secret manager. Do not embed it in browser code or public repositories.

Workspace and permissions

A key selects exactly one workspace. There is no REST workspaceId override. To work in a different workspace, create a key there. The API checks the key owner's current membership, role, and operation permissions on every request, so an existing key does not retain permissions that were revoked.

GET /api/v1/workspaces returns the workspace attached to the key. See Accounts and capabilities.

Revoke or replace a key

Revoke the key in the same API keys settings tab when an integration is no longer needed or a key has been exposed. To rotate it, create a replacement, update your integration, then revoke the old key. Requests using an invalid or revoked key return 401 UNAUTHENTICATED.

Continue with Quickstart, Errors, or MCP authentication for OAuth-based AI clients.

On this page