> ## Documentation Index
> Fetch the complete documentation index at: https://help.onlyx.ai/llms.txt
> Use this file to discover all available pages before exploring further.

> ## Agent Instructions
> You are reading OnlyX Help: the OnlyX Help Center and the OnlyX developer documentation. OnlyX is an AI chatting and CRM platform for OnlyFans agencies. Its AI chatter is called Hugo in the app.
> Pages at the site root (for example /inbox/..., /hugo/..., /billing/...) are Help Center articles for agency owners, admins, chatters and creators who use the app at app.onlyx.ai. Words in bold are the exact button, menu and label names the app shows; keep them exactly as written. When these pages do not answer a question, the person can email support at support@onlyx.ai.
> Pages under /developers are the developer documentation. REST API base URL: https://api.onlyx.ai/v1 (authenticate with `Authorization: Bearer <API key>`; keys start with onx_sk_ and are created in app.onlyx.ai under Settings > API & MCP). MCP server: https://mcp.onlyx.ai/mcp (OAuth, or a Bearer API key). In the API the AI chatter is `ai` on the wire. Money is integer US cents in fields ending in Cents; timestamps are UTC ISO-8601.
> Rules for assistants acting on a user's behalf: discover ids with list calls and never invent them; before any call that reaches a real fan or the live OnlyFans account (sending a message, releasing a chat to the AI, turning AI on for a chat, resolving a hand-off, turning review mode off, changing the welcome message, creating a tracking link) show the user the exact content and get explicit confirmation; send every POST with an Idempotency-Key and reuse it on retry; never resend a message whose delivery status is unconfirmed; never ask a creator for her OnlyFans password or codes - she signs in herself through a connect link and the OnlyX Login app.

# Workspaces

> The workspace is your agency's account in OnlyX. Keys, OAuth connections, creators and all data belong to exactly one workspace.

A **workspace** is your agency's account in OnlyX. Everything the API can see or change lives inside one workspace:

```mermaid theme={"system"}
flowchart TD
  W[Workspace] --> M[Team members and roles]
  W --> K[API keys and connected apps]
  W --> C[Creators]
  C --> P[AI persona, AI content, AI settings]
  C --> V[Vault media]
  C --> T[Tracking links]
  C --> F[Fans]
  F --> CV[Conversation]
  CV --> MS[Messages]
  CV --> H[Hand-offs]
```

## One credential, one workspace

Every API key and every OAuth connection belongs to exactly one workspace, and can only ever read or change that workspace:

* A key is created **inside** a workspace (Settings → API & MCP) and keeps belonging to it, even if the person who created it leaves.
* An OAuth connection is approved **for** a workspace. The consent screen asks which one, and only offers workspaces where you are an owner or admin.
* If you run several workspaces, create one key per workspace. There is no cross-workspace key.

Check which workspace a credential belongs to with `GET /v1/me`:

<CodeGroup>
  ```bash cURL theme={"system"}
  curl https://api.onlyx.ai/v1/me \
    -H "Authorization: Bearer $ONLYX_API_KEY"
  ```

  ```python Python theme={"system"}
  import os, requests

  me = requests.get(
      "https://api.onlyx.ai/v1/me",
      headers={"Authorization": f"Bearer {os.environ['ONLYX_API_KEY']}"},
      timeout=30,
  ).json()
  print(me["workspace"]["name"], me["workspace"]["timezone"])
  ```

  ```javascript JavaScript theme={"system"}
  const me = await (
    await fetch("https://api.onlyx.ai/v1/me", {
      headers: { Authorization: `Bearer ${process.env.ONLYX_API_KEY}` },
    })
  ).json();
  console.log(me.workspace.name, me.workspace.timezone);
  ```
</CodeGroup>

```json Response 200 theme={"system"}
{
  "workspace": { "id": "agc_1a2b3c4d5e6f7a8b9c0d", "name": "Northstar Talent", "timezone": "Europe/London" },
  "credential": {
    "kind": "api_key",
    "id": "apk_0c9d8e7f6a5b4c3d2e1f",
    "name": "Revenue dashboard",
    "scopes": ["workspace:read", "creators:read", "stats:read", "money:read"],
    "creatorIds": null
  },
  "rateLimit": { "limit": 120, "windowSeconds": 60 }
}
```

## Members, roles and what a key can do

People join a workspace with a role: **owner**, **admin**, **supervisor**, **chatter** or **content assistant**. Only owners and admins can create API keys, approve OAuth connections, and see or revoke the workspace's keys and connected apps.

`credential.kind` is `api_key` or `oauth` (a connected app's token), `credential.scopes` always includes the implicit `workspace:read`, and `credential.creatorIds` is `null` when the credential can see every creator. `rateLimit` is the general limit for this credential.

A credential does not inherit anyone's role. What it can do is exactly:

1. its **scopes** (see [Authentication](/developers/authentication#scopes)), narrowed by
2. its **creator restriction**, if it has one.

So a Read only key created by an owner can read everything and change nothing, and a key restricted to two creators sees only those two creators, their fans and their chats.

## Timezone

Each workspace has a timezone (for example `Europe/London` or `America/New_York`), shown in `GET /v1/me`. The API uses it wherever a "day" matters:

* `GET /v1/stats/today` means today in the workspace timezone.
* Daily series in revenue and overview reports are split at local midnight.
* `start` and `end` dates (`YYYY-MM-DD`) in report windows are local dates.

Timestamps on objects (`createdAt`, `lastMessageAt`, and so on) are always UTC, with milliseconds and a `Z` suffix, for example `2026-09-26T14:02:31.000Z`. Change the workspace timezone in the dashboard's workspace settings.

## Isolation between workspaces

Workspaces never see each other's data. If you ask for an id that belongs to another workspace, the API answers `404` with the same body it gives for an id that never existed. It never tells you that the id exists somewhere else. The same rule protects creators outside a key's creator restriction.

A suspended workspace gets `403 WORKSPACE_SUSPENDED` on every call until the suspension is lifted.

## Ids

Every object has a stable id with a prefix that says what it is. Always take ids from API responses; never build them yourself.

| Prefix | Object |
| - | - |
| `agc_` | Workspace |
| `cre_` | Creator |
| `cnv_` | Conversation (one creator and one fan) |
| `msg_` | Message |
| `fan_` | Fan (a subscriber of one creator) |
| `lst_` | Fan list |
| `esc_` | Hand-off |
| `fld_`, `col_`, `set_` | AI content folder, ladder, level |
| `trk_` | Tracking link |
| `apk_` | API key |
| `oag_` | Connected app (an approved OAuth connection); `GET /v1/me` shows it as the credential `id` when you call with that app's token |
| digits only, for example `4012345678` | Vault media: the OnlyFans id of a photo, video, GIF or audio file in the creator's vault |

A fan is per creator: the same person subscribed to two of your creators is two fans with two ids.

## Related

* [Creators](/developers/concepts/creators): the accounts inside a workspace.
* [Authentication](/developers/authentication): creating keys and approving apps.
* [Security](/developers/security): how workspace data is protected.
