Authentication
Authorization: Bearer rb_YOUR_KEY Content-Type: application/json
Keys expire after 90 days and can be revoked instantly. They never expose platform tokens. Limits: 120 requests per minute per key, 30 publications per hour per user. Keep keys off browsers and public repositories.
Endpoints
| Request | Scope / purpose |
|---|---|
| GET /api/v1/connections | connections:read · Your authorized destinations. |
| POST /api/v1/posts | posts:write · Facebook, Instagram and YouTube publishing. |
| GET /api/v1/posts/:id | posts:write · Read publication status. |
| POST /api/v1/posts/:id | posts:write · Check and advance processing. |
| GET /api/v1/ads?connectionId=… | ads:write · Campaigns and last 30 days performance. Optional after cursor. |
| POST /api/v1/ads | ads:write · Create a paused campaign. |
| PATCH /api/v1/ads | ads:write · Set campaign ACTIVE, PAUSED or DELETED. |
Publication request
Every creation requires a unique Idempotency-Key of 16–128 letters, numbers, underscores or hyphens. Repeating the same key and content returns the existing result. Reusing it for different content returns 409.
{
"connectionId": "YOUR_CONNECTION_ID",
"text": "Content approved by the account owner",
"consent": true
}YouTube additionally requires title, assetId, privacy (public, private or unlisted), madeForKids and syntheticMedia booleans. Instagram requires an uploaded JPEG or MP4 asset. Upload through the workspace or the media API below.
The consent flag must represent the owner’s actual approval. TikTok cannot be published through this API: its creator-facing preview, visibility and disclosure choices must be completed in the workspace.
Media API
POST /api/v1/media (posts:write scope) with name, type and size in bytes. The response contains assetId and a short-lived uploadUrl. PUT the exact file bytes to uploadUrl using its returned Content-Type. Then POST /api/v1/media with action="finish" and assetId. The server verifies the file before it can be published. Never publish using an unfinished upload. Supported types: image/jpeg, image/png, video/mp4, video/quicktime and video/webm, up to 250 MB.
Uploaded media is publicly retrievable through an unguessable storage URL so the approved destination can fetch it. Do not upload confidential content. Media is removed after 30 days.
Ads requests
{
"connectionId": "AD_CONNECTION_ID",
"name": "Summer launch",
"objective": "OUTCOME_TRAFFIC"
}Campaign creation also requires Idempotency-Key. Objectives: OUTCOME_AWARENESS, OUTCOME_TRAFFIC, OUTCOME_ENGAGEMENT, OUTCOME_LEADS, OUTCOME_SALES, OUTCOME_APP_PROMOTION. Campaigns start PAUSED with no special ad category. Use Meta Ads Manager for regulated categories, ad sets, budgets, targeting and creatives.
{
"connectionId": "AD_CONNECTION_ID",
"campaignId": "CAMPAIGN_ID",
"status": "PAUSED",
"confirmed": true
}Set confirmed=true only after the account owner approves activation or deletion. Activation can start configured ads spending. Campaign ownership is checked against the selected ad account.
Outcomes and errors
Statuses: preparing, processing, published, failed and unconfirmed. A published status represents platform confirmation. For unconfirmed, check the native account before resubmitting. 401 means invalid access; 403 insufficient scope; 409 conflicting/pending action; 429 rate limit; 5xx temporary failure. Do not blindly retry writes after uncertain network outcomes.