Skip to main content

Choose how to authenticate

Every REST request needs a token in its Authorization header:

Authorization: Bearer YOUR_TOKEN

Both methods below use the same REST endpoints at https://api.socialchamp.com/v1/rest.

MethodUse it whenHow to get it
API keyYour software works with your own Social Champ account.Create an API key.
OAuth access tokenYour integration works on behalf of other users.Set up an OAuth client and follow the OAuth guide.

An OAuth access token is checked first. If it is not accepted, the API checks whether the bearer value is an active API key.

What your token can do​

A scope is a permission attached to a token. Authentication identifies the account; scopes control which operations it can request. Account and workspace permissions still apply.

ScopeOperations
read_profileRead channels, profiles, posts, workspaces, calendars, labels, and collections.
manage_postCreate and edit posts, delete a single post, manage the queue, create labels, update calendars, and use AI content tools.
manage_teamRead or act on approvals, bulk-delete posts, and apply labels in bulk.

New API keys include read_profile and manage_post. manage_team is optional: select it when creating a key if your integration needs those operations. An existing key does not gain it automatically. OAuth integrations should request the scopes they need; the current REST token response does not echo them. Access can also depend on the connected user's role.

Each operation in the API reference lists its required scope. A missing scope returns 403.

When authentication fails​

The current REST authentication handler returns 400 with a message for a missing, invalid, expired, or revoked token. Do not assume every authentication failure returns 401. See Responses and retries.

Keep API keys, access tokens, and refresh tokens out of URLs, shared logs, and source control.