Choose how to authenticate
Every REST request needs a token in its Authorization header:
Authorization: Bearer YOUR_TOKEN
Both methods below use the same REST endpoints at https://api.socialchamp.com/v1/rest.
| Method | Use it when | How to get it |
|---|---|---|
| API key | Your software works with your own Social Champ account. | Create an API key. |
| OAuth access token | Your integration works on behalf of other users. | Set up an OAuth client and follow the OAuth guide. |
An OAuth access token is checked first. If it is not accepted, the API checks whether the bearer value is an active API key.
What your token can do
A scope is a permission attached to a token. Authentication identifies the account; scopes control which operations it can request. Account and workspace permissions still apply.
| Scope | Operations |
|---|---|
read_profile | Read channels, profiles, posts, workspaces, calendars, labels, and collections. |
manage_post | Create and edit posts, delete a single post, manage the queue, create labels, update calendars, and use AI content tools. |
manage_team | Read or act on approvals, bulk-delete posts, and apply labels in bulk. |
New API keys include read_profile and manage_post. manage_team is optional: select it when creating a key if your integration needs those operations. An existing key does not gain it automatically. OAuth integrations should request the scopes they need; the current REST token response does not echo them. Access can also depend on the connected user's role.
Each operation in the API reference lists its required scope. A missing scope returns 403.
When authentication fails
The current REST authentication handler returns 400 with a message for a missing, invalid, expired, or revoked token. Do not assume every authentication failure returns 401. See Responses and retries.
Keep API keys, access tokens, and refresh tokens out of URLs, shared logs, and source control.