Security & API access

Postory is a tool for people whose accounts matter to them. So here is exactly how it connects to your accounts, what it is allowed to do, and what it cannot do — with nothing left out.

Official APIs only

Every post Postory publishes goes through the platform's own API — X API v2, the Threads Graph API, and AT Protocol against your PDS. Nothing is published by scraping, by driving a logged-in session, or by automating a browser.

OAuth only — we never see a password

You connect on the platform's own screen and approve the permissions there. Postory never asks for your social password. On Bluesky we use full AT Protocol OAuth rather than an app password, which most third-party clients still rely on.

No engagement automation

Postory does not follow, unfollow, like, retweet, bulk-DM, auto-reply to strangers, or scrape followers — for you or for anyone. This is the behaviour platforms actually suspend accounts over, and it does not exist in the product. The only replies it ever posts are the later parts of your own threads, which you wrote and scheduled yourself.

Tokens encrypted, revocable any time

Access and refresh tokens are stored encrypted at rest. You can disconnect from your Accounts page, or revoke Postory from the platform's own settings without touching Postory at all.

Every permission we request

You will see this same list on the platform's consent screen before you approve anything. If the two ever disagree, trust the consent screen and tell us.

X (Twitter)

X API v2 — api.x.com

tweet.read
Read posts, so drafts and analytics can reference them
tweet.write
Publish the posts you schedule
users.read
Read your profile and handle
media.write
Upload the images and video attached to your posts
offline.access
Keep the connection alive without asking you to reconnect

No follow, like, bookmark or direct-message permission is requested. Those actions are not possible with this connection.

Threads

Threads Graph API — graph.threads.net

threads_basic
Read your profile and handle
threads_content_publish
Publish the posts you schedule
threads_manage_insights
Read your own post and profile metrics
threads_manage_replies
Post replies inside your own threads
threads_read_replies
Read replies for analytics and Profile Audit

No follow or direct-message permission is requested.

Bluesky

AT Protocol — your own PDS, via OAuth with PAR, PKCE and DPoP

atproto transition:generic
The standard AT Protocol OAuth scope

Being straight with you: AT Protocol has not shipped granular scopes yet, so transition:generic is broad — it technically covers more than posting. Postory still only ever creates posts and reads public data; there is no follow, like or DM code in the product at all. When Bluesky ships fine-grained scopes, we will narrow this.

The free shadowban checker, and where its data comes from

The shadowban checker works without a login and without connecting anything, because a shadowban is only visible from the outside. An account looking at itself through the official API cannot see one — so a privileged lookup would return a clean result even for a limited account.

That means the checker reads public X data through a third-party provider rather than the official API. It touches no credentials, requires no OAuth connection, and works on any handle — including ones that have never heard of Postory. Nothing it reads is data you would not see by opening the profile in a logged-out browser.

The same public-data source powers reply and analytics lookups inside Profile Audit. It is never used to publish anything.

What Postory is not

Postory is not an X Enterprise partner, an official X reseller, or endorsed by X, Meta or Bluesky. It is an independent product that uses the public developer platforms those companies offer, under the permissions you grant. Some tools in this category display partnership badges; we would rather show you the permission list and let you check it yourself.

Revoking access

Disconnect any account from your Accounts page, or revoke Postory directly from the platform:

  • X: Settings → Security and account access → Apps and sessions → revoke Postory
  • Threads / Meta: Threads or Instagram settings → Apps and Websites → remove Postory
  • Bluesky: Settings → Privacy and security → revoke the Postory session

To delete your Postory account and everything attached to it, see data deletion.