Getting started

Authentication

Every request carries your API key as a bearer token. Get it in the Creator OS app under Settings → API keys. Keys start with cos_live_.

Each key belongs to exactly one workspace and can only see that workspace’s accounts, posts and inbox, so an agency can hand one client’s key to an agent without exposing any other client. Keep keys server-side, and regenerate a key from Settings if it leaks: the old one stops working immediately.

curl "https://creatoros-production-5658.up.railway.app/v1/me" \
  -H "Authorization: Bearer $CREATOROS_API_KEY"

A missing or wrong key returns 401 with the error code unauthorized.

Read only or read & write

Workspace keys are read & write. For an agent that should only look, create a read-only key in Settings → API keys. A read-only key can call every GET endpoint (plus the validation tools) and gets 403 insufficient_scope for anything that would publish, reply or change something. Apps you connect through the MCP server get their own key with the access you chose, listed in Settings under Connected apps.