API reference
Authentication: API keys and scopes
The Preflight API authenticates every request with an API key sent as a bearer token in the Authorization header. A key belongs to one workspace, carries scopes that decide what it may read, write or publish, and is created once under Settings → API keys on a plan that includes the API. Only the capability sheet, GET /v1/platforms, is open without a key.
Authentication
Every request carries an API key as a bearer token. Create one under Settings → API keys; the Pro and Studio plans include the API, and a key issued on them keeps working if the workspace later moves down a plan. The key is shown once and stored only as a hash, so a lost key is replaced rather than recovered. A key belongs to one workspace and lasts a year unless you choose another expiry.
curl https://preflight.social/v1/posts \ -H "Authorization: Bearer sk_live_…"
A key carries scopes: posts:read, posts:write (drafts), posts:publish (anything that goes live: scheduling, publishing, changing a scheduled post, retrying, editing or deleting a live post), media:read, media:write, webhooks:read, webhooks:write, or * for everything. Settings offers them as Full access, Schedule and publish, Drafts only and Read only, with an expiry of 30 days, 90 days or a year. Give a key the narrowest set that does its job; a missing scope answers 403 forbidden and names it.
GET /v1/platforms needs no key: it is the capability sheet — each network's character limit, maxMediaPerPost, what it requires and what it supports. Networks are named youtube, tiktok, instagram, facebook, threads, twitter (X), linkedin, pinterest, bluesky, mastodon, telegram, discord and tumblr.
Questions: info@preflight.social. The same API as a schema: openapi.json (OpenAPI 3.1).
Write it once. Let the rules be our problem.
Preflight checks every post against each network's rules before it leaves, then publishes it to twelve networks. Free plan, no card.