Security & API access
Postory is a tool for people whose accounts matter to them. So here is exactly how it connects to your accounts, what it is allowed to do, and what it cannot do — with nothing left out.
Official APIs only
Every post Postory publishes goes through the platform's own API — X API v2, the Threads Graph API, and AT Protocol against your PDS. Nothing is published by scraping, by driving a logged-in session, or by automating a browser.
OAuth only — we never see a password
You connect on the platform's own screen and approve the permissions there. Postory never asks for your social password. On Bluesky we use full AT Protocol OAuth rather than an app password, which most third-party clients still rely on.
No engagement automation
Postory does not follow, unfollow, like, retweet, bulk-DM, auto-reply to strangers, or scrape followers — for you or for anyone. This is the behaviour platforms actually suspend accounts over, and it does not exist in the product. The only replies it ever posts are the later parts of your own threads, which you wrote and scheduled yourself.
Tokens encrypted, revocable any time
Access and refresh tokens are stored encrypted at rest. You can disconnect from your Accounts page, or revoke Postory from the platform's own settings without touching Postory at all.
Every permission we request
You will see this same list on the platform's consent screen before you approve anything. If the two ever disagree, trust the consent screen and tell us.
X (Twitter)
X API v2 — api.x.com
- tweet.read
- Read posts, so drafts and analytics can reference them
- tweet.write
- Publish the posts you schedule
- users.read
- Read your profile and handle
- media.write
- Upload the images and video attached to your posts
- offline.access
- Keep the connection alive without asking you to reconnect
No follow, like, bookmark or direct-message permission is requested. Those actions are not possible with this connection.
Threads
Threads Graph API — graph.threads.net
- threads_basic
- Read your profile and handle
- threads_content_publish
- Publish the posts you schedule
- threads_manage_insights
- Read your own post and profile metrics
- threads_manage_replies
- Post replies inside your own threads
- threads_read_replies
- Read replies for analytics and Profile Audit
No follow or direct-message permission is requested.
Bluesky
AT Protocol — your own PDS, via OAuth with PAR, PKCE and DPoP
- atproto transition:generic
- The standard AT Protocol OAuth scope
Being straight with you: AT Protocol has not shipped granular scopes yet, so transition:generic is broad — it technically covers more than posting. Postory still only ever creates posts and reads public data; there is no follow, like or DM code in the product at all. When Bluesky ships fine-grained scopes, we will narrow this.
The free shadowban checker, and where its data comes from
The shadowban checker works without a login and without connecting anything, because a shadowban is only visible from the outside. An account looking at itself through the official API cannot see one — so a privileged lookup would return a clean result even for a limited account.
That means the checker reads public X data through a third-party provider rather than the official API. It touches no credentials, requires no OAuth connection, and works on any handle — including ones that have never heard of Postory. Nothing it reads is data you would not see by opening the profile in a logged-out browser.
The same public-data source powers reply and analytics lookups inside Profile Audit. It is never used to publish anything.
What Postory is not
Postory is not an X Enterprise partner, an official X reseller, or endorsed by X, Meta or Bluesky. It is an independent product that uses the public developer platforms those companies offer, under the permissions you grant. Some tools in this category display partnership badges; we would rather show you the permission list and let you check it yourself.
Revoking access
Disconnect any account from your Accounts page, or revoke Postory directly from the platform:
- X: Settings → Security and account access → Apps and sessions → revoke Postory
- Threads / Meta: Threads or Instagram settings → Apps and Websites → remove Postory
- Bluesky: Settings → Privacy and security → revoke the Postory session
To delete your Postory account and everything attached to it, see data deletion.