Skip to content
Wahlu API

Authentication

Learn how to authenticate your API requests with API keys.

API key format

Wahlu API keys follow the format wahlu_live_.... Treat a key like a password: keep it on the server, never expose it in browser code and never commit it to source control.

Create an API key

Open Settings → API Keys in Wahlu. Give the key a clear name, select only the scopes it needs, and optionally restrict it to one or more brands. The secret is shown once, so copy it immediately.

Authorisation header

Send the key as a Bearer token on every authenticated request. The public platform-capabilities route is the only released route that does not require a key.

curl
curl https://api.wahlu.com/v1/context \
  -H "Authorization: Bearer wahlu_live_your_api_key_here"

Released-operation scopes

These scopes control the operations in the current public reference. A context read validates the key and returns its granted scopes, but does not itself require an additional scope.

ParameterTypeDescription
integrations:readscopeList a brand's connected publishing targets and read live target-supported TikTok privacy choices without changing credentials or integration state.
integrations:writescopeRefresh live target-supported TikTok privacy choices when provider access may rotate credentials or update reauthorisation state.
media:writescopeUpload or import media and create an explicitly reviewed repair derivative.
media:readscopeRead one media item and its current processing readiness.
posts:readscopeRead brand context, labels, content, drafts, Link in bio and Autopilot plans.
publications:readscopeRead publication History and safe post links for one brand.
notifications:readscopeRead your own notifications for one brand. Does not mark them as read.
posts:writescopeCreate or edit unused drafts, delete them, move schedules to drafts, or approve and regenerate Autopilot ideas.
schedule:writescopeCheck readiness and manage schedules. Approval also needs publish:execute; moving to drafts also needs posts:write.
schedule:readscopeRead one accessible Schedule and its bounded status.
publish:executeconditional scopeThe Publishing permission in the dashboard: post to your connected social media accounts. Required when approval_status is approved.

Approval is separate authority

A key with schedule:write can safely create a Schedule withapproval_status: "pending_review". Creating an explicitly approved Schedule additionally requires publish:execute. Wahlu fails closed when that extra scope is absent.

Brand restrictions

A restricted key can access only its selected brands. A resource outside that boundary is not disclosed. Start with GET /v1/context and use only the returned brands and links.