Get started
Authentication
API keys, the Authorization header and how keys are stored.
Every request to the REST API and the MCP server is authenticated with an API key, sent as a bearer token:
Authorization: Bearer sh_…
Creating keys
Workspace owners and admins create keys under Developers in the dashboard. A key is sh_ followed by 48 random characters. It’s shown once: SocialHelper stores only a SHA-256 hash of it, so a lost key can’t be recovered, only replaced.
- A key works for the workspace it was created in, and only that workspace. Asking for another workspace’s account, post or media returns
404. - Keys don’t expire and can’t be limited to some accounts. Treat each one like a password, and give each app or agent its own key so you can revoke one without touching the rest.
- Revoking a key in the dashboard stops it at once. The dashboard also shows when each key was last used.
- The same key works for the MCP server.
Example
curl https://socialhelper.app/api/v1/accounts \
-H "Authorization: Bearer $SOCIALHELPER_API_KEY"
When authentication fails
A missing, malformed or revoked key, or a key whose workspace was deleted, gets 401:
{"message": "Unauthenticated."}
Rate limit
Each key can make 120 requests a minute, shared between REST and MCP. See Rate limits.
Never put an API key in browser or mobile app code, where anyone can read it. Call SocialHelper from your server, or from a server function in your app builder.