Skip to main content
The vault is the creator’s media library on OnlyFans: every photo, video, GIF and audio file she can attach to messages. OnlyX keeps a copy of the list, refreshed on its own schedule, so you can browse it, pick media, and attach it by id. Reading it never touches her OnlyFans session, and a creator who is not connected has an empty vault. Scope: media:read. Vault media ids are OnlyFans’ own ids: strings of digits such as "4012345678". They are the same ids you pass in mediaIds and previewMediaIds when sending, and in mediaIds when adding media to an AI content level. Always send them as strings.

List the vault

GET /v1/creators/{creatorId}/media
A creator the credential cannot see is 404 CREATOR_NOT_FOUND. If the vault cannot be read right now the answer is 503 MEDIA_UNAVAILABLE; try again in a few minutes.
Response 200

Fetch a thumbnail

GET /v1/creators/{creatorId}/media/{mediaId}/thumbnail returns a small preview image (the image bytes, not JSON: image/jpeg, image/png or image/webp). Only small previews are served: full-size originals and videos are not available through the API. The mediaId is the vault id (digits). This call has its own limit of 60 requests per 60 seconds per credential. The thumbnail endpoint needs your key like every other call, so you cannot put thumbnailUrl straight into an <img> tag in a browser. Fetch it on your server and serve it to your own interface. Responses may be cached privately for up to five minutes (cache-control: private, max-age=300).
Check the content-type response header for the image format.

Use media ids

In a message (Read and send messages):
  • previewMediaIds: sent free and unlocked.
  • mediaIds: locked behind priceCents (a paid message).
In an AI content level (Build the AI content ladder):
A media item can be on only one level at a time; adding it to a level moves it there.

Good to know

  • New uploads take a while to appear. OnlyX refreshes each creator’s vault regularly, and after she connects the first vault pages sync within the first minutes. If you need a file that was uploaded moments ago, refresh the vault from the dashboard.
  • Uploading to the vault is not in the API yet. Upload on OnlyFans or in the dashboard.
  • Media sends need consent. While the creator’s contentConsentRequired is true, OnlyFans blocks media in messages until she accepts its prompt. Text still works.
  • Pick proven content. sort=earnings lists what already sells; stats.buyers shows how many fans bought it.
  • The ids are her data. They identify files in her own vault and are only useful with her account.

From your AI assistant

With the MCP server connected, the assistant can browse the vault with list_vault_media and actually look at a thumbnail with view_vault_media, for example: “Show me Mia’s five best-selling videos and suggest which one to put in her Gym ladder.”