curl --request POST \
--url https://api.onlyx.ai/v1/creators/{creatorId}/connect-link \
--header 'Authorization: Bearer <token>'import requests
url = "https://api.onlyx.ai/v1/creators/{creatorId}/connect-link"
headers = {"Authorization": "Bearer <token>"}
response = requests.post(url, headers=headers)
print(response.text)const options = {method: 'POST', headers: {Authorization: 'Bearer <token>'}};
fetch('https://api.onlyx.ai/v1/creators/{creatorId}/connect-link', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));{
"createdAt": "2026-09-26T10:03:40.000Z",
"expiresAt": "2026-09-27T10:03:40.000Z",
"lastOpenedAt": null,
"opens": 0,
"status": "active",
"url": "https://app.onlyx.ai/connect/Qm9vX3RoaXNfaXNfYW5fZXhhbXBsZV90b2tlbl9vbmx5"
}Create a connect link
Creates a one-time link the creator opens on her own phone or computer to connect her OnlyFans account. She needs no OnlyX account: she signs in to OnlyFans herself with the OnlyX Login app, entering her password, any 2FA or e-mail code, and completing OnlyFans’ face (selfie) verification with her own camera. The API never sees her password or codes. A link lasts 24 hours and is burned when she connects. There is one live link per creator: if one is already active it is returned instead of a new one, so repeating this call is safe. Treat the URL like a password and send it only to her; the response is never cached (Cache-Control: no-store). Limited to 20 per hour per workspace. A creator that has no OnlyFans account behind her (a test creator), or whose connection is final (not_a_creator, duplicate), is 409 CREATOR_NOT_CONNECTABLE. After sending the link, poll GET /v1/creators/{creatorId}/connection.
Scope: requires creators:write.
Rate limits: 20 links per hour per workspace — on top of the general limit of 120 requests per 60 seconds per credential.
Idempotency: repeating this call is safe on its own; an Idempotency-Key is accepted and checked, but no response is stored for replay.
curl --request POST \
--url https://api.onlyx.ai/v1/creators/{creatorId}/connect-link \
--header 'Authorization: Bearer <token>'import requests
url = "https://api.onlyx.ai/v1/creators/{creatorId}/connect-link"
headers = {"Authorization": "Bearer <token>"}
response = requests.post(url, headers=headers)
print(response.text)const options = {method: 'POST', headers: {Authorization: 'Bearer <token>'}};
fetch('https://api.onlyx.ai/v1/creators/{creatorId}/connect-link', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));{
"createdAt": "2026-09-26T10:03:40.000Z",
"expiresAt": "2026-09-27T10:03:40.000Z",
"lastOpenedAt": null,
"opens": 0,
"status": "active",
"url": "https://app.onlyx.ai/connect/Qm9vX3RoaXNfaXNfYW5fZXhhbXBsZV90b2tlbl9vbmx5"
}Authorizations
An API key (onx_sk_…) created in OnlyX under Settings → API & MCP, or an OAuth access token (onx_at_…) issued to a connected app. Send it as Authorization: Bearer <credential>. API keys may also be sent as X-API-Key: <key>.
Headers
Optional and not needed: this call is idempotent on its own, so repeating it is always safe and no response is stored for replay. A key you send is still checked (8 to 64 letters, digits, - or _; a malformed one is 400 VALIDATION_ERROR).
8 - 64^[A-Za-z0-9_-]{8,64}$Path Parameters
The creator id (cre_…).
Response
The active connect link (a live one is returned instead of a new one).
When the link was created.
When the link stops working (24 hours after creation).
When it was last opened.
How many times the link was opened. More opens than you expect can mean the link leaked: revoke it and create a new one.
active: can be opened now. used: she connected with it (links are burned on success). expired: older than 24 hours. revoked: you cancelled it. none: no link was ever created.
active, used, expired, revoked, none The link to send her. Anyone holding it can start the sign-in for this creator, so send it only to her. null unless status is active.