[{"data":1,"prerenderedAt":362},["ShallowReactive",2],{"api-docs-articles":3,"api-docs-nav-articles":72,"api-docs-article-authentication":85,"api-docs-related-authentication":358},[4,11,17,23,28,34,40,46,52,57,62,67],{"path":5,"title":6,"description":7,"category":8,"emoji":9,"order":10},"\u002Fdocs\u002Fapi\u002Fauthentication","Authentication","Authenticate Pallyy API requests with an API key, understand scopes for reading and writing, and restrict keys to specific social sets.","getting-started","🔑",1,{"path":12,"title":13,"description":14,"category":8,"emoji":15,"order":16},"\u002Fdocs\u002Fapi\u002Ferrors","Errors","How the Pallyy API reports errors: HTTP status codes, the machine-readable error code in the response body, and validation error details.","⚠️",3,{"path":18,"title":19,"description":20,"category":21,"emoji":22,"order":10},"\u002Fdocs\u002Fapi\u002Fmcp","MCP server","Connect Claude, ChatGPT, Cursor, or any MCP client to your Pallyy account: the server URL, what the tools can do, how consent works, and how to disconnect an app.","mcp","🤖",{"path":24,"title":25,"description":26,"category":21,"emoji":27,"order":16},"\u002Fdocs\u002Fapi\u002Fmcp-authorization","MCP authorization","How MCP clients sign in to Pallyy with OAuth 2.1: discovery documents, client identification, PKCE, scopes, token lifetimes, refresh rotation, and revocation.","🔐",{"path":29,"title":30,"description":31,"category":21,"emoji":32,"order":33},"\u002Fdocs\u002Fapi\u002Fmcp-tools","MCP tools","Reference for the 15 tools the Pallyy MCP server exposes to AI assistants: social sets, post sets, media, media uploads, and calendar notes, with every input.","🧰",2,{"path":35,"title":36,"description":37,"category":38,"emoji":39,"order":16},"\u002Fdocs\u002Fapi\u002Fmedia","Media library","Browse a social set's media library via the Pallyy API, filter by folder, type, or name, and reference items when creating posts.","endpoints","🖼️",{"path":41,"title":42,"description":43,"category":38,"emoji":44,"order":45},"\u002Fdocs\u002Fapi\u002Fmedia-uploads","Media uploads","Import images and videos into a Pallyy media library from a URL via the API, poll the upload's status, and use the result in posts.","⬆️",4,{"path":47,"title":48,"description":49,"category":38,"emoji":50,"order":51},"\u002Fdocs\u002Fapi\u002Fnotes","Notes","Read and create the notes pinned to a social set's calendar via the Pallyy API: reminders, recurring notes, and events imported from Google Calendar.","📝",5,{"path":53,"title":54,"description":55,"category":8,"emoji":56,"order":45},"\u002Fdocs\u002Fapi\u002Fpagination","Pagination and queries","How Pallyy API list endpoints paginate with page and size parameters, and how to pass nested filters and sorting in the query string.","📄",{"path":58,"title":59,"description":60,"category":38,"emoji":61,"order":33},"\u002Fdocs\u002Fapi\u002Fpost-sets","Post sets","Create, schedule, list, and update Pallyy post sets via the API: one scheduled slot holding a post for each social network it targets.","🗓️",{"path":63,"title":64,"description":65,"category":8,"emoji":66,"order":33},"\u002Fdocs\u002Fapi\u002Frate-limits","Rate limits","The Pallyy API allows 5 requests per second per account. Read the rate limit headers on every response and back off on 429s.","⏱️",{"path":68,"title":69,"description":70,"category":38,"emoji":71,"order":10},"\u002Fdocs\u002Fapi\u002Fsocial-sets","Social sets","List your Pallyy social sets and their connected accounts via the API. Almost every other endpoint needs a social set id.","👥",[73,74,75,76,77,78,79,80,81,82,83,84],{"path":5,"title":6,"category":8,"order":10},{"path":12,"title":13,"category":8,"order":16},{"path":18,"title":19,"category":21,"order":10},{"path":24,"title":25,"category":21,"order":16},{"path":29,"title":30,"category":21,"order":33},{"path":35,"title":36,"category":38,"order":16},{"path":41,"title":42,"category":38,"order":45},{"path":47,"title":48,"category":38,"order":51},{"path":53,"title":54,"category":8,"order":45},{"path":58,"title":59,"category":38,"order":33},{"path":63,"title":64,"category":8,"order":33},{"path":68,"title":69,"category":38,"order":10},{"id":86,"title":6,"body":87,"category":8,"datePublished":350,"dateUpdated":351,"description":7,"emoji":9,"extension":352,"meta":353,"navigation":354,"order":10,"path":5,"seo":355,"stem":356,"__hash__":357},"apiDocs\u002Fdocs\u002Fapi\u002Fauthentication.md",{"type":88,"value":89,"toc":344},"minimark",[90,94,105,112,123,128,153,156,182,186,193,201,207,211,214,296,305,320,324,327,335,341],[91,92,93],"p",{},"The Pallyy API is a REST API served over HTTPS. Every endpoint lives under a single base URL:",[95,96,101],"pre",{"className":97,"code":99,"language":100},[98],"language-text","https:\u002F\u002Fapp.pallyy.com\u002Fapi\u002Fv1\n","text",[102,103,99],"code",{"__ignoreMap":104},"",[91,106,107,108,111],{},"All requests are authenticated with an API key. Requests without a valid key receive a ",[102,109,110],{},"401"," response.",[91,113,114,115,118,119,122],{},"AI assistants connected through the ",[116,117,19],"a",{"href":18}," authenticate with OAuth access tokens instead. Those start with ",[102,120,121],{},"pallyy_oat_",", are accepted by every endpoint on this page, and follow the same scope and social set rules as a key.",[124,125,127],"h2",{"id":126},"api-keys","API keys",[91,129,130,131,140,141,144,145,152],{},"API keys are created from ",[132,133,134],"strong",{},[116,135,139],{"href":136,"rel":137},"https:\u002F\u002Fapp.pallyy.com\u002Fsettings\u002Fapi-keys",[138],"nofollow","Settings > API Keys"," in your Pallyy account and always start with the ",[102,142,143],{},"pallyy_"," prefix. The full key is only shown once, when it is created, so store it somewhere safe. If you lose a key, revoke it and ",[132,146,147],{},[116,148,151],{"href":149,"rel":150},"https:\u002F\u002Fapp.pallyy.com\u002Fsettings\u002Fapi-keys\u002Fcreate",[138],"create a new one",".",[91,154,155],{},"A few things to know about keys:",[157,158,159,163,166],"ul",{},[160,161,162],"li",{},"You can have up to 10 active keys per account.",[160,164,165],{},"Each key has a name, a set of scopes, and an optional social set restriction. All three can be changed after the key is created.",[160,167,168,169,175,176,178,179,152],{},"Keys can be disabled or revoked at any time by opening them from the ",[132,170,171],{},[116,172,174],{"href":136,"rel":173},[138],"API keys list",". Disabling is reversible, revoking is permanent. Requests with a disabled or revoked key receive a ",[102,177,110],{}," with the error code ",[102,180,181],{},"api-key:invalid",[124,183,185],{"id":184},"authenticating-requests","Authenticating requests",[91,187,188,189,192],{},"Pass your key as a bearer token in the ",[102,190,191],{},"Authorization"," header:",[95,194,199],{"className":195,"code":197,"language":198,"meta":104},[196],"language-bash","curl https:\u002F\u002Fapp.pallyy.com\u002Fapi\u002Fv1\u002Fsocial-sets \\\n  -H \"Authorization: Bearer pallyy_your_api_key\"\n","bash",[102,200,197],{"__ignoreMap":104},[91,202,203,204,152],{},"Requests that send a body must also set ",[102,205,206],{},"Content-Type: application\u002Fjson",[124,208,210],{"id":209},"scopes","Scopes",[91,212,213],{},"Every valid key can read. Scopes only gate writes: a key with no scopes is read-only. The \"In the app\" column is the label each scope carries when you create or edit a key in Pallyy.",[215,216,217,233],"table",{},[218,219,220],"thead",{},[221,222,223,227,230],"tr",{},[224,225,226],"th",{},"Scope",[224,228,229],{},"In the app",[224,231,232],{},"Grants",[234,235,236,250,270,283],"tbody",{},[221,237,238,244,247],{},[239,240,241],"td",{},[102,242,243],{},"post-sets:write",[239,245,246],{},"Edit posts",[239,248,249],{},"Create and update post sets",[221,251,252,257,260],{},[239,253,254],{},[102,255,256],{},"post-sets:publish",[239,258,259],{},"Publish posts",[239,261,262,263,265,266,269],{},"Required on top of ",[102,264,243],{}," to create or update post sets with status ",[102,267,268],{},"SCHEDULED",", meaning posts that will actually publish",[221,271,272,277,280],{},[239,273,274],{},[102,275,276],{},"media:write",[239,278,279],{},"Upload media",[239,281,282],{},"Create media uploads",[221,284,285,290,293],{},[239,286,287],{},[102,288,289],{},"notes:write",[239,291,292],{},"Edit notes",[239,294,295],{},"Create and update notes on the calendar",[91,297,298,299,178,302,152],{},"Calling a write endpoint with a key that is missing the required scope returns a ",[102,300,301],{},"403",[102,303,304],{},"api-key:missing_scope",[91,306,307,308,310,311,313,314,316,317,319],{},"The split between ",[102,309,243],{}," and ",[102,312,256],{}," exists so you can hand out keys that draft content without being able to publish it. A key with only ",[102,315,243],{}," (Edit posts) can create and update drafts, but any attempt to schedule requires ",[102,318,256],{}," (Publish posts).",[124,321,323],{"id":322},"social-set-restrictions","Social set restrictions",[91,325,326],{},"A key can be restricted to one or more social sets. A restricted key:",[157,328,329,332],{},[160,330,331],{},"Only sees its allowed sets when listing social sets.",[160,333,334],{},"Can only read and write resources that belong to those sets.",[91,336,337,338,152],{},"Resources outside the restriction are reported as ",[102,339,340],{},"404",[91,342,343],{},"A key with no restriction has access to all of the account's social sets.",{"title":104,"searchDepth":33,"depth":16,"links":345},[346,347,348,349],{"id":126,"depth":33,"text":127},{"id":184,"depth":33,"text":185},{"id":209,"depth":33,"text":210},{"id":322,"depth":33,"text":323},"2026-08-20","2026-09-04","md",{},true,{"title":6,"description":7},"docs\u002Fapi\u002Fauthentication","b4oEOKvRc1ENQu2jD-R2ff-8wnPL-elLG5rtsa_eins",[359,360,361],{"path":63,"title":64,"emoji":66,"order":33},{"path":12,"title":13,"emoji":15,"order":16},{"path":53,"title":54,"emoji":56,"order":45},1788947604348]