> ## Documentation Index
> Fetch the complete documentation index at: https://docs.postonce.to/llms.txt
> Use this file to discover all available pages before exploring further.

# Connect account

> Computes a five-minute browser authorization URL bound to the authenticated profile without connecting or changing an account. Open the returned URL in a separate browser step to authorize the provider; then list accounts to verify connection. Depending on platform, the browser uses provider OAuth or a PostOnce-hosted credential or signer flow. Never enter provider credentials in chat. Partner accounts may send `external_user_id` and an allowed `redirect_url`; after consent the end user is redirected to `redirect_url` with `status`, `account_id`, `platform` and `external_user_id` (or `error`).



## OpenAPI

````yaml /openapi/public-api.yaml post /v1/accounts/connect/{platform}
openapi: 3.1.0
info:
  title: PostOnce Public API
  version: 1.0.0-alpha
  description: Public API for PostOnce paid users
servers:
  - url: https://postonce.to/api/public
security:
  - bearerAuth: []
paths:
  /v1/accounts/connect/{platform}:
    post:
      summary: Connect account
      description: >-
        Computes a five-minute browser authorization URL bound to the
        authenticated profile without connecting or changing an account. Open
        the returned URL in a separate browser step to authorize the provider;
        then list accounts to verify connection. Depending on platform, the
        browser uses provider OAuth or a PostOnce-hosted credential or signer
        flow. Never enter provider credentials in chat. Partner accounts may
        send `external_user_id` and an allowed `redirect_url`; after consent the
        end user is redirected to `redirect_url` with `status`, `account_id`,
        `platform` and `external_user_id` (or `error`).
      parameters:
        - $ref: '#/components/parameters/platform'
      requestBody:
        required: false
        content:
          application/json:
            schema:
              type: object
              properties:
                external_user_id:
                  type: string
                  maxLength: 200
                  description: >-
                    Partner accounts only. Your own id for the end user
                    connecting the account.
                redirect_url:
                  type: string
                  format: uri
                  description: >-
                    Partner accounts only. Must exactly match one of your
                    allowed redirect URLs.
      responses:
        '201':
          description: Account connection URL created successfully.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ConnectAccountResponse'
        '401':
          description: Missing, invalid, revoked, or expired API key.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/AuthErrorResponse'
        '403':
          description: Missing required scope.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
        '404':
          description: Unsupported platform.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
components:
  parameters:
    platform:
      name: platform
      in: path
      required: true
      schema:
        type: string
        enum:
          - bluesky
          - facebook
          - farcaster
          - nostr
          - telegram
          - instagram
          - linkedin
          - pinterest
          - reddit
          - snapchat
          - threads
          - tiktok
          - twitter
          - vimeo
          - youtube
      description: Social platform to connect.
  schemas:
    ConnectAccountResponse:
      type: object
      properties:
        data:
          type: object
          properties:
            hosted_url:
              type: string
              nullable: true
              example: >-
                https://postonce.to/dashboard/accounts?connect=twitter&source=public_api
            authorization_url:
              type: string
              nullable: true
              description: >-
                Five-minute browser connection URL bound to the API-key profile
                with signed state. OAuth platforms return a direct provider URL;
                Bluesky returns a PostOnce-hosted app-password form; Farcaster
                returns a PostOnce-hosted managed-signer approval flow; Nostr
                returns a PostOnce-hosted NIP-46 remote-signer flow; Telegram
                returns a PostOnce-hosted flow that adds @PostOnceBot as a
                channel admin.
              example: https://www.tiktok.com/v2/auth/authorize/?client_key=...
            mode:
              type: string
              enum:
                - credential_form_url
                - managed_signer
                - remote_signer
                - oauth_authorization_url
              example: oauth_authorization_url
            platform:
              type: string
              example: twitter
    AuthErrorResponse:
      type: object
      properties:
        error:
          type: object
          properties:
            code:
              type: string
              example: invalid_api_key
            message:
              type: string
              example: Invalid API key.
            hint:
              type: string
              description: Suggested action to resolve the error.
    ErrorResponse:
      type: object
      properties:
        error:
          type: object
          required:
            - code
            - message
          properties:
            code:
              type: string
              example: workflow_limit_reached
            message:
              type: string
              example: You have reached the maximum number of workflows for your plan.
            hint:
              type: string
              description: Suggested action to resolve the error.
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      bearerFormat: API Key
      description: >-
        Scoped API key issued in PostOnce Settings. OAuth authorization grants
        are not currently supported.
      x-scopes:
        accounts:read: List and read connected accounts.
        accounts:write: Connect and disconnect social accounts.
        media:read: Read uploaded media.
        media:write: Upload media.
        posts:read: Read posts and unpublished drafts.
        posts:write: Create, update, publish, cancel, retry, and delete posts and drafts.
        workflows:read: List and read crossposting workflows.
        workflows:write: Create, update, and delete crossposting workflows.

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.