Skip to content
API

Automate the schedule without widening access.

Issue workspace-owned keys, reveal them once & grant only the scopes each integration needs. Everything the app schedules, your scripts can schedule.

Get started freeSee pricing
Surface

The schedule, callable.

Everything below lives under /public/v1, authenticates with a scoped key & counts against per-workspace rate limits.

POST/postsCreate, schedule or draft a post — validated server-side with the same rules as the dashboard, rejected as a readable 400.
GET/postsList scheduled posts for a date range.
GET/posts/:id/statusRead the publishing job status of one post.
DELETE/posts/:idRemove a post & its scheduled deliveries.
POST/uploadUpload a media file (multipart).
POST/upload-from-urlImport media from a URL into the workspace library.
GET/find-slot/:idReturn the next free posting slot for a channel.
GET/integrationsList connected channels & their identifiers.
GET/analytics/:integrationPlatform-reported metrics for one connected channel.

Keys are shown once · scopes are deny-by-default

Capabilities

Keys that behave like credentials.

These are working parts of Publishly, not roadmap promises.

Keys shown once, hashed forever

Keys are hashed before storage — the raw value appears once at creation, is never recoverable from the database & revokes independently.

Scopes end where the grant ends

Grant read or write per resource — posts, integrations, media, notifications — & nothing beyond the grant.

Integrations you can watch & throttle

Server-side rate limiting & last-used timestamps keep every customer integration observable.

Foundations

The same reliability everywhere.

No matter where a post starts, Publishly applies the same delivery checks, failure reasons, safe retries, and account protections.

Delivery · 01

Every post gets a delivery receipt

A post is only marked successful after Publishly confirms it is live. The receipt stores the result and the live link, separately for every account you chose.

Delivery · 02

Every failure gets a reason and an alert

You see what happened, what needs fixing, and whether Publishly will try again. Developers can send the same alert straight into their own software through a signed webhook.

Delivery · 03

Retries that never double-post

Short platform problems are retried safely. If Publishly cannot prove what happened, it stops and asks you to check instead of risking the same post appearing twice.

Delivery · 04

Expiring and disconnected accounts are caught early

Warnings start before a known connection expiry. If a connection dies, Publishly flags it, stops sending posts to that account, and keeps the rest of your calendar moving.

Security · 05

Tokens encrypted before they’re stored

Your social account credentials are locked with industry-standard authenticated encryption before they are stored.

Security · 06

Every connection through the platform’s own front door

Nine of the ten featured networks use the platform’s official connect and permission screens. Bluesky uses a separate app password you create and revoke inside Bluesky — never your account password. Publishly does not automate a browser login.

Security · 07

API keys you can limit and revoke

Give each key only the access it needs and revoke it at any time. A full key is shown once and is never stored in a form Publishly can reveal later.

Security · 08

An audit trail that answers questions

Team invitations, channel changes, key management & bulk operations are recorded per workspace — who, what, when, from where.

Security · 09

Client isolation by design

Workspaces keep every brand’s accounts, tokens, media & history separate — a client’s data leaves with them, cleanly.

Source · 10

The source, on offer

Built on the open-source Postiz engine (AGPL-3.0). The corresponding source of the running service is available to every user.

Everything the app does, a scoped key can do — & nothing a scoped key was not granted.

Connect an account and schedule one real post.

Keep the receipt. Start free with no credit card.