> ## Documentation Index
> Fetch the complete documentation index at: https://help.onlyx.ai/llms.txt
> Use this file to discover all available pages before exploring further.

> ## Agent Instructions
> You are reading OnlyX Help: the OnlyX Help Center and the OnlyX developer documentation. OnlyX is an AI chatting and CRM platform for OnlyFans agencies. Its AI chatter is called Hugo in the app.
> Pages at the site root (for example /inbox/..., /hugo/..., /billing/...) are Help Center articles for agency owners, admins, chatters and creators who use the app at app.onlyx.ai. Words in bold are the exact button, menu and label names the app shows; keep them exactly as written. When these pages do not answer a question, the person can email support at support@onlyx.ai.
> Pages under /developers are the developer documentation. REST API base URL: https://api.onlyx.ai/v1 (authenticate with `Authorization: Bearer <API key>`; keys start with onx_sk_ and are created in app.onlyx.ai under Settings > API & MCP). MCP server: https://mcp.onlyx.ai/mcp (OAuth, or a Bearer API key). In the API the AI chatter is `ai` on the wire. Money is integer US cents in fields ending in Cents; timestamps are UTC ISO-8601.
> Rules for assistants acting on a user's behalf: discover ids with list calls and never invent them; before any call that reaches a real fan or the live OnlyFans account (sending a message, releasing a chat to the AI, turning AI on for a chat, resolving a hand-off, turning review mode off, changing the welcome message, creating a tracking link) show the user the exact content and get explicit confirmation; send every POST with an Idempotency-Key and reuse it on retry; never resend a message whose delivery status is unconfirmed; never ask a creator for her OnlyFans password or codes - she signs in herself through a connect link and the OnlyX Login app.

# List vault media

> Lists the creator's OnlyFans vault: photos, videos, GIFs and audio with size, length, the vault lists they are in and how they performed. The ids are what you use in messages (`mediaIds`, `previewMediaIds`), in the welcome message and on AI content levels. The list is OnlyX's stored copy of her vault, refreshed by OnlyX on its own schedule — reading it never touches her OnlyFans session; a creator who is not connected has an empty vault. Uploading is not available through the API yet. A creator the credential cannot see is `404 CREATOR_NOT_FOUND`.

**Scope:** requires `media:read`.

**Rate limit:** the general limit of 120 requests per 60 seconds per credential.



## OpenAPI

````yaml /developers/api-reference/openapi.json get /v1/creators/{creatorId}/media
openapi: 3.1.0
info:
  contact:
    email: developers@onlyx.ai
    name: OnlyX developers
    url: https://docs.onlyx.ai/
  description: >
    The OnlyX API runs your OnlyX workspace from your own code and AI tools:
    creators and their

    connection, the fan inbox, fans, vault media, statistics, the AI chatter's
    setup and tracking links.


    **Authentication.** Send an API key as `Authorization: Bearer onx_sk_…`
    (create one in OnlyX under

    Settings → API & MCP), or an OAuth access token issued to a connected app.
    Keys belong to the

    workspace, carry scopes, and can be limited to some creators.


    **Conventions.** JSON with camelCase fields; timestamps are ISO-8601 UTC
    with a `Z`; money is integer

    US cents (fields end in `Cents`). Lists return `{"data": [...], "hasMore":
    bool, "nextCursor": string|null}`

    and page with `limit` and `cursor`.


    **Scopes.** Every operation names the scope it needs in `x-required-scope`
    and in its description; a

    credential without it gets `403 INSUFFICIENT_SCOPE`.


    **Errors and limits.** Errors are `{"error": {"code", "message",
    "requestId"}}`; every response

    carries `X-Request-Id`. The default limit is 120 requests per 60 seconds per

    credential, reported in `X-RateLimit-*` headers; over it you get `429
    RATE_LIMITED` with `Retry-After`.

    Operations with limits of their own list them in `x-rate-limits`.


    **Idempotency and safety.** Every write accepts an `Idempotency-Key` header
    (required when sending a

    message, adding a creator and creating a tracking link): retry with the same
    key and you get the

    original answer instead of a second action. Operations marked
    `x-reaches-fans: true` can reach a real

    fan or change the live OnlyFans account.


    Guides, the MCP server and more: [docs.onlyx.ai](https://docs.onlyx.ai).
  summary: >-
    Run your OnlyX workspace (creators, inbox, fans, stats and the AI chatter)
    from code and AI tools.
  title: OnlyX API
  version: 1.0.0
servers:
  - description: Production
    url: https://api.onlyx.ai
security:
  - bearerAuth: []
tags:
  - description: 'Who you are: the workspace and credential behind a key.'
    name: Workspace
  - description: >-
      The creators your workspace manages: list, read, add, rename, and the AI
      switch.
    name: Creators
  - description: >-
      Connecting a creator's OnlyFans account: connect links she opens on her
      own device, and the connection status to poll.
    name: Connect
  - description: >-
      The fan inbox: list and count conversations, read state, take over,
      release, and the per-chat AI switch.
    name: Conversations
  - description: Read message history and send text, free media and paid messages to fans.
    name: Messages
  - description: Conversations the AI chatter handed to your team, and resolving them.
    name: Hand-offs
  - description: >-
      Fans, their purchases, fan lists, and your team's notes, custom names and
      mute flag.
    name: Fans
  - description: >-
      Each creator's OnlyFans vault: media ids for messages and levels, and
      thumbnails.
    name: Media
  - description: >-
      Today, revenue, audience, the cached overview report, and each creator's
      transaction ledger.
    name: Stats
  - description: The brief the AI chatter follows to chat as each creator.
    name: AI persona
  - description: 'The AI content ladder: folders, ladders, priced levels and their media.'
    name: AI content
  - description: >-
      Follow-ups, review mode, the master AI switch, and OnlyFans' welcome
      message.
    name: AI settings
  - description: >-
      OnlyFans tracking and trial links, your cost fields, and creating new
      links.
    name: Tracking links
externalDocs:
  description: OnlyX developer documentation
  url: https://docs.onlyx.ai
paths:
  /v1/creators/{creatorId}/media:
    get:
      tags:
        - Media
      summary: List vault media
      description: >-
        Lists the creator's OnlyFans vault: photos, videos, GIFs and audio with
        size, length, the vault lists they are in and how they performed. The
        ids are what you use in messages (`mediaIds`, `previewMediaIds`), in the
        welcome message and on AI content levels. The list is OnlyX's stored
        copy of her vault, refreshed by OnlyX on its own schedule — reading it
        never touches her OnlyFans session; a creator who is not connected has
        an empty vault. Uploading is not available through the API yet. A
        creator the credential cannot see is `404 CREATOR_NOT_FOUND`.


        **Scope:** requires `media:read`.


        **Rate limit:** the general limit of 120 requests per 60 seconds per
        credential.
      operationId: listVaultMedia
      parameters:
        - description: The creator id (`cre_…`), from `GET /v1/creators`.
          in: path
          name: creatorId
          required: true
          schema:
            description: The creator id (`cre_…`), from `GET /v1/creators`.
            maxLength: 40
            title: Creatorid
            type: string
        - description: Only this media type.
          in: query
          name: type
          required: false
          schema:
            anyOf:
              - enum:
                  - photo
                  - video
                  - gif
                  - audio
                type: string
              - type: 'null'
            description: Only this media type.
            title: Type
        - description: Only media in this vault list (an id from `listIds`).
          in: query
          name: listId
          required: false
          schema:
            anyOf:
              - maxLength: 40
                pattern: ^[A-Za-z0-9_-]{1,40}$
                type: string
              - type: 'null'
            description: Only media in this vault list (an id from `listIds`).
            title: Listid
        - description: '`newest` (default), `oldest` or `earnings`.'
          in: query
          name: sort
          required: false
          schema:
            default: newest
            description: '`newest` (default), `oldest` or `earnings`.'
            enum:
              - newest
              - oldest
              - earnings
            title: Sort
            type: string
        - description: Page size, 1-100. Default 25.
          in: query
          name: limit
          required: false
          schema:
            default: 25
            description: Page size, 1-100. Default 25.
            maximum: 100
            minimum: 1
            title: Limit
            type: integer
        - description: >-
            Opaque cursor from the previous page's `nextCursor`. Omit for the
            first page.
          in: query
          name: cursor
          required: false
          schema:
            anyOf:
              - maxLength: 1024
                type: string
              - type: 'null'
            description: >-
              Opaque cursor from the previous page's `nextCursor`. Omit for the
              first page.
            title: Cursor
      responses:
        '200':
          content:
            application/json:
              example:
                data:
                  - createdAt: '2026-08-30T14:12:09.000Z'
                    durationSeconds: null
                    height: 1350
                    id: '4012345678'
                    listIds:
                      - '1234567'
                    stats:
                      buyers: 9
                      likes: 212
                      tipsCents: 4500
                    thumbnailUrl: >-
                      https://api.onlyx.ai/v1/creators/cre_8f2c1a9b0d7e4c3f2a1b/media/4012345678/thumbnail
                    type: photo
                    width: 1080
                hasMore: true
                nextCursor: >-
                  eyJrIjoiY3JlYXRvcnMiLCJwIjp7ImkiOiJjcmVfOGYyYzFhOWIwZDdlNGMzZjJhMWIifX0.Yp3k0Qm7T2vX9aLc4R8sWg
              schema:
                $ref: '#/components/schemas/VaultMediaPage'
          description: A page of vault media.
          headers:
            X-RateLimit-Limit:
              $ref: '#/components/headers/X-RateLimit-Limit'
            X-RateLimit-Remaining:
              $ref: '#/components/headers/X-RateLimit-Remaining'
            X-RateLimit-Reset:
              $ref: '#/components/headers/X-RateLimit-Reset'
            X-Request-Id:
              $ref: '#/components/headers/X-Request-Id'
        '400':
          content:
            application/json:
              examples:
                VALIDATION_ERROR:
                  summary: VALIDATION_ERROR
                  value:
                    error:
                      code: VALIDATION_ERROR
                      message: 'limit: Input should be less than or equal to 100'
                      requestId: req-3f9a1c2b7d4e5f60a1b2c3d4
              schema:
                $ref: '#/components/schemas/Error'
          description: >-
            The request is not valid and was not carried out. Fix it before
            retrying. `VALIDATION_ERROR`: the request is not valid; `message`
            names the field and the problem.
          headers:
            X-Request-Id:
              $ref: '#/components/headers/X-Request-Id'
        '401':
          $ref: '#/components/responses/Unauthorized'
        '403':
          content:
            application/json:
              examples:
                INSUFFICIENT_SCOPE:
                  summary: INSUFFICIENT_SCOPE
                  value:
                    error:
                      code: INSUFFICIENT_SCOPE
                      message: This key does not have the `media:read` scope.
                      requestId: req-3f9a1c2b7d4e5f60a1b2c3d4
                WORKSPACE_SUSPENDED:
                  summary: WORKSPACE_SUSPENDED
                  value:
                    error:
                      code: WORKSPACE_SUSPENDED
                      message: This workspace is suspended.
                      requestId: req-3f9a1c2b7d4e5f60a1b2c3d4
              schema:
                $ref: '#/components/schemas/Error'
          description: >-
            The credential may not do this. `INSUFFICIENT_SCOPE`: the credential
            lacks the `media:read` scope (the `WWW-Authenticate` header names
            it; an OAuth token's message says "token" instead of "key").
            `WORKSPACE_SUSPENDED`: the workspace is suspended.
          headers:
            WWW-Authenticate:
              $ref: '#/components/headers/WWW-Authenticate'
            X-Request-Id:
              $ref: '#/components/headers/X-Request-Id'
        '404':
          content:
            application/json:
              examples:
                CREATOR_NOT_FOUND:
                  summary: CREATOR_NOT_FOUND
                  value:
                    error:
                      code: CREATOR_NOT_FOUND
                      message: Creator not found.
                      requestId: req-3f9a1c2b7d4e5f60a1b2c3d4
              schema:
                $ref: '#/components/schemas/Error'
          description: >-
            Not found. An id that does not exist, belongs to another workspace,
            or is outside this credential's creators all get the same answer.
            `CREATOR_NOT_FOUND`: no creator with this `creatorId` is visible to
            this credential.
          headers:
            X-Request-Id:
              $ref: '#/components/headers/X-Request-Id'
        '429':
          $ref: '#/components/responses/RateLimited'
        '500':
          $ref: '#/components/responses/InternalError'
        '503':
          content:
            application/json:
              examples:
                MEDIA_UNAVAILABLE:
                  summary: MEDIA_UNAVAILABLE
                  value:
                    error:
                      code: MEDIA_UNAVAILABLE
                      message: >-
                        The vault can't be read right now. Try again in a few
                        minutes.
                      requestId: req-3f9a1c2b7d4e5f60a1b2c3d4
              schema:
                $ref: '#/components/schemas/Error'
          description: >-
            Temporarily unavailable. Retry later. `MEDIA_UNAVAILABLE`: the vault
            can't be read right now. Try again in a few minutes.
          headers:
            X-Request-Id:
              $ref: '#/components/headers/X-Request-Id'
components:
  schemas:
    VaultMediaPage:
      description: 'A page of vault media: `{data, hasMore, nextCursor}`.'
      examples:
        - data:
            - createdAt: '2026-08-30T14:12:09.000Z'
              durationSeconds: null
              height: 1350
              id: '4012345678'
              listIds:
                - '1234567'
              stats:
                buyers: 9
                likes: 212
                tipsCents: 4500
              thumbnailUrl: >-
                https://api.onlyx.ai/v1/creators/cre_8f2c1a9b0d7e4c3f2a1b/media/4012345678/thumbnail
              type: photo
              width: 1080
          hasMore: true
          nextCursor: >-
            eyJrIjoiY3JlYXRvcnMiLCJwIjp7ImkiOiJjcmVfOGYyYzFhOWIwZDdlNGMzZjJhMWIifX0.Yp3k0Qm7T2vX9aLc4R8sWg
      properties:
        data:
          items:
            $ref: '#/components/schemas/VaultMedia'
          type: array
        hasMore:
          type: boolean
        nextCursor:
          anyOf:
            - type: string
            - type: 'null'
      required:
        - data
        - hasMore
      title: VaultMediaPage
      type: object
    Error:
      properties:
        error:
          properties:
            code:
              description: Stable, machine-readable error code.
              type: string
            message:
              description: What went wrong, in a sentence for a person.
              type: string
            requestId:
              description: >-
                The id of this request (also in the `X-Request-Id` header).
                Quote it to support.
              type: string
          required:
            - code
            - message
            - requestId
          type: object
      required:
        - error
      type: object
    VaultMedia:
      examples:
        - createdAt: '2026-08-30T14:12:09.000Z'
          durationSeconds: null
          height: 1350
          id: '4012345678'
          listIds:
            - '1234567'
          stats:
            buyers: 9
            likes: 212
            tipsCents: 4500
          thumbnailUrl: >-
            https://api.onlyx.ai/v1/creators/cre_8f2c1a9b0d7e4c3f2a1b/media/4012345678/thumbnail
          type: photo
          width: 1080
      properties:
        createdAt:
          anyOf:
            - type: string
            - type: 'null'
          description: When it was added to the vault.
        durationSeconds:
          anyOf:
            - type: integer
            - type: 'null'
          description: Length of a video or audio item in seconds; `null` for photos.
        height:
          anyOf:
            - type: integer
            - type: 'null'
          description: Height in pixels, when known.
        id:
          description: >-
            The OnlyFans vault media id (a string of digits). Use it in
            `mediaIds` / `previewMediaIds`.
          type: string
        listIds:
          description: The OnlyFans vault lists (folders) it is in, by OnlyFans list id.
          items:
            type: string
          type: array
        stats:
          $ref: '#/components/schemas/VaultMediaStats'
          description: Performance, as reported by OnlyFans.
        thumbnailUrl:
          description: >-
            The API URL of a small preview image. It needs your credential like
            every other call.
          type: string
        type:
          description: The media type.
          enum:
            - photo
            - video
            - gif
            - audio
          type: string
        width:
          anyOf:
            - type: integer
            - type: 'null'
          description: Width in pixels, when known.
      required:
        - id
        - type
        - createdAt
        - width
        - height
        - durationSeconds
        - listIds
        - stats
        - thumbnailUrl
      title: VaultMedia
      type: object
    VaultMediaStats:
      properties:
        buyers:
          description: Fans who bought it in a paid message or post.
          type: integer
        likes:
          description: Likes on posts that used it.
          type: integer
        tipsCents:
          description: Tips on posts that used it, in cents.
          type: integer
      required:
        - likes
        - tipsCents
        - buyers
      title: VaultMediaStats
      type: object
  headers:
    X-RateLimit-Limit:
      description: >-
        Requests allowed in the current window of the tightest limit this
        request counted against.
      example: 120
      schema:
        type: integer
    X-RateLimit-Remaining:
      description: Requests left in that window.
      example: 117
      schema:
        type: integer
    X-RateLimit-Reset:
      description: When that window resets, as Unix epoch seconds.
      example: 1790431380
      schema:
        type: integer
    X-Request-Id:
      description: >-
        The id of this request. Your own `X-Request-Id` (8 to 64 letters, digits
        or `-`) is echoed back; otherwise OnlyX creates one. Also in every error
        body as `requestId`: quote it to support.
      example: req-3f9a1c2b7d4e5f60a1b2c3d4
      schema:
        type: string
    WWW-Authenticate:
      description: >-
        The authentication challenge (RFC 6750), for example `Bearer
        error="insufficient_scope", scope="messages:send"`.
      schema:
        type: string
    Retry-After:
      description: Seconds to wait before trying again.
      example: 12
      schema:
        type: integer
  responses:
    Unauthorized:
      content:
        application/json:
          examples:
            INVALID_API_KEY:
              summary: INVALID_API_KEY
              value:
                error:
                  code: INVALID_API_KEY
                  message: The API key is invalid, expired or revoked.
                  requestId: req-3f9a1c2b7d4e5f60a1b2c3d4
            INVALID_TOKEN:
              summary: INVALID_TOKEN
              value:
                error:
                  code: INVALID_TOKEN
                  message: The access token is invalid, expired or revoked.
                  requestId: req-3f9a1c2b7d4e5f60a1b2c3d4
            UNAUTHORIZED:
              summary: UNAUTHORIZED
              value:
                error:
                  code: UNAUTHORIZED
                  message: >-
                    Authentication required. Send your API key as
                    `Authorization: Bearer onx_sk_…`.
                  requestId: req-3f9a1c2b7d4e5f60a1b2c3d4
          schema:
            $ref: '#/components/schemas/Error'
      description: >-
        No credential was sent (`UNAUTHORIZED`), or it is invalid, expired or
        revoked (`INVALID_API_KEY` for API keys, `INVALID_TOKEN` for OAuth
        access tokens: refresh the token or reconnect the app). Too many failed
        attempts from one address with credentials OnlyX never issued are
        answered `429 RATE_LIMITED` instead.
      headers:
        WWW-Authenticate:
          $ref: '#/components/headers/WWW-Authenticate'
        X-Request-Id:
          $ref: '#/components/headers/X-Request-Id'
    RateLimited:
      content:
        application/json:
          examples:
            RATE_LIMITED:
              summary: RATE_LIMITED
              value:
                error:
                  code: RATE_LIMITED
                  message: Too many requests. Try again in 12 seconds.
                  requestId: req-3f9a1c2b7d4e5f60a1b2c3d4
          schema:
            $ref: '#/components/schemas/Error'
      description: >-
        Over a rate limit (`RATE_LIMITED`). Wait `Retry-After` seconds, then
        retry — with the same `Idempotency-Key` for a write.
      headers:
        Retry-After:
          $ref: '#/components/headers/Retry-After'
        X-RateLimit-Limit:
          $ref: '#/components/headers/X-RateLimit-Limit'
        X-RateLimit-Remaining:
          $ref: '#/components/headers/X-RateLimit-Remaining'
        X-RateLimit-Reset:
          $ref: '#/components/headers/X-RateLimit-Reset'
        X-Request-Id:
          $ref: '#/components/headers/X-Request-Id'
    InternalError:
      content:
        application/json:
          examples:
            INTERNAL_ERROR:
              summary: INTERNAL_ERROR
              value:
                error:
                  code: INTERNAL_ERROR
                  message: Something went wrong on our side.
                  requestId: req-3f9a1c2b7d4e5f60a1b2c3d4
          schema:
            $ref: '#/components/schemas/Error'
      description: >-
        Something went wrong on OnlyX's side (`INTERNAL_ERROR`). Retry with
        backoff (reuse the `Idempotency-Key` for a write); quote `requestId` to
        support if it persists.
      headers:
        X-Request-Id:
          $ref: '#/components/headers/X-Request-Id'
  securitySchemes:
    bearerAuth:
      bearerFormat: onx_sk_… API key or onx_at_… access token
      description: >-
        An API key (`onx_sk_…`) created in OnlyX under Settings → API & MCP, or
        an OAuth access token (`onx_at_…`) issued to a connected app. Send it as
        `Authorization: Bearer <credential>`. API keys may also be sent as
        `X-API-Key: <key>`.
      scheme: bearer
      type: http

````