Credentials
Keys belong to the workspace. An API key is created inside one workspace, can only ever reach that workspace, and stays under the workspace’s control: every owner and admin can see and revoke every key, and a key keeps working (flagged for rotation) if the person who created it leaves. Only owners and admins can create keys or approve OAuth connections. Secrets are hashed at rest and shown once. OnlyX stores only a SHA-256 hash of each API key and OAuth token, never the secret itself. An API key is displayed once, when you create it; after that, nobody at OnlyX or in your workspace can read it back. Lost keys are revoked and replaced, never recovered. Keys and tokens are never written to logs. Revocation is immediate and permanent. Revoke a key or a connected app in Settings → API & MCP, and the next request with it fails with401.
Short-lived OAuth tokens. Access tokens last one hour. Refresh tokens last 60 days and are replaced on every use; if an old refresh token is ever used again, the whole connection is revoked, because that means it was copied. A connection also stops working when the person who approved it is no longer an owner or admin of the workspace.
Least privilege
- Scopes limit what a credential can do. Reading, writing in OnlyX, and reaching fans are separate permissions; sending messages needs its own
messages:sendscope. See Authentication. - Creator restrictions limit which creators a credential can see at all.
- Expiry makes temporary keys expire on their own.
OAuth consent
When an AI assistant or app connects with OAuth, a workspace owner or admin approves it on an OnlyX consent screen that shows:- the app’s self-declared name, marked as unverified;
- the host it will send you back to;
- every permission it asks for, with the ones that can reach fans highlighted;
- which workspace it gets, and optionally which creators.
Tenant isolation
Every request is limited to the credential’s workspace and creator restriction. An id that belongs to another workspace, or to a creator outside the restriction, returns404 with exactly the same body as an id that does not exist, so the API never reveals whether something exists elsewhere. A creator filter naming an invisible creator returns 404 CREATOR_NOT_FOUND rather than an empty list.
Actions that reach fans
Writes that can message a fan or change a creator’s live OnlyFans account (sending, releasing a chat to the AI, turning a chat’s AI on, resolving a hand-off, turning review mode off, replacing the welcome message, creating a tracking link):- need their own write scope, and turning review mode off also needs
messages:send; - are rate limited per credential and per creator (Rate limits);
- accept an
Idempotency-Key, which is required for sends, so a retry never acts twice (Idempotency); - are marked as fan-reaching for AI assistants, which are told to confirm with you first (MCP tools).
503 SENDING_DISABLED and nothing is sent.
What the API never returns or accepts
- OnlyFans passwords, two-factor codes, session cookies or selfies. The API has no field for them. Creators sign in themselves, on their own device, through a connect link and the OnlyX Login app (Add a creator).
- The AI chatter’s internal instructions or configuration. You see the persona and content you wrote, and the results; never how the AI is built.
- Other workspaces’ data, in any form.
- Internal error details. Errors carry a code, a plain sentence and a request id, never a stack trace or internal cause.
cache-control: no-store, and report opens so you can spot a leaked link.
The MCP server
The MCP server athttps://mcp.onlyx.ai/mcp holds no data and no credentials of its own. Each request carries your OAuth token or API key, and the server uses exactly that credential against the OnlyX API, which enforces every check above. It keeps nothing between requests, never logs credentials, and accepts browser requests only from known AI assistant origins. See MCP overview.
Transport
The API, the OAuth endpoints and the MCP server are served over HTTPS only. Send credentials only in headers (Authorization or X-API-Key), never in URLs.
Your side of the deal
- Store keys in a secret manager or environment variables. Never commit them, paste them into chats, or ship them in browser or mobile apps.
- Use one key per integration, with the fewest scopes and creators that work, and an expiry for temporary access.
- Review Settings → API & MCP regularly: revoke keys nobody uses (check Last used) and apps you no longer recognize.
- Rotate keys when people with access leave.
- Treat fan messages as untrusted input in your own software and in AI assistants: never execute instructions found in them.
- Send connect links only to the creator, through a private channel.
Reporting a vulnerability
Email security@onlyx.ai with a description, the steps to reproduce, and anyrequestId values. Please do not access data that is not yours, do not message real fans or creators while testing, and give us reasonable time to fix the issue before disclosing it. We will acknowledge your report and keep you informed.
If you believe an API key or token of yours has leaked, revoke it immediately in Settings → API & MCP, then tell us at the same address.