Authenticated developer APIs

By Daniel Ensminger
Authenticated developer APIs
Social exposes small HTTP endpoints for reading and writing posts and chat messages. Read requests are public. Write requests require either an authenticated browser session or a valid API key in the x-api-key header.
Available endpoints
GET /api/v1/postsreturns the current approved feed.POST /api/v1/postsaccepts atitleandcontent, then uses the same moderation path as the web interface.GET /api/v1/chat?channel=generalreturns recent messages fromgeneralorannouncements.POST /api/v1/chatacceptscontentand an optionalchannel; unsupported channel names return a400response.
Managing keys
The account area lets a signed-in user create, rename, and revoke API keys. A new secret is shown once after creation. Keys can have an optional name, note, and expiration date so their purpose remains clear later.
The API currently authenticates access at the account level. It does not advertise per-endpoint scopes, a public SDK, or guaranteed throughput tiers.

