> ## Documentation Index
> Fetch the complete documentation index at: https://help.onlyx.ai/llms.txt
> Use this file to discover all available pages before exploring further.

> ## Agent Instructions
> You are reading OnlyX Help: the OnlyX Help Center and the OnlyX developer documentation. OnlyX is an AI chatting and CRM platform for OnlyFans agencies. Its AI chatter is called Hugo in the app.
> Pages at the site root (for example /inbox/..., /hugo/..., /billing/...) are Help Center articles for agency owners, admins, chatters and creators who use the app at app.onlyx.ai. Words in bold are the exact button, menu and label names the app shows; keep them exactly as written. When these pages do not answer a question, the person can email support at support@onlyx.ai.
> Pages under /developers are the developer documentation. REST API base URL: https://api.onlyx.ai/v1 (authenticate with `Authorization: Bearer <API key>`; keys start with onx_sk_ and are created in app.onlyx.ai under Settings > API & MCP). MCP server: https://mcp.onlyx.ai/mcp (OAuth, or a Bearer API key). In the API the AI chatter is `ai` on the wire. Money is integer US cents in fields ending in Cents; timestamps are UTC ISO-8601.
> Rules for assistants acting on a user's behalf: discover ids with list calls and never invent them; before any call that reaches a real fan or the live OnlyFans account (sending a message, releasing a chat to the AI, turning AI on for a chat, resolving a hand-off, turning review mode off, changing the welcome message, creating a tracking link) show the user the exact content and get explicit confirmation; send every POST with an Idempotency-Key and reuse it on retry; never resend a message whose delivery status is unconfirmed; never ask a creator for her OnlyFans password or codes - she signs in herself through a connect link and the OnlyX Login app.

# Security

> How OnlyX protects API access and your agency's data: workspace-owned keys hashed at rest, scopes and creator restrictions, OAuth consent, tenant isolation, what the API never returns, and how to report a vulnerability.

Your OnlyX workspace holds creators' accounts, fans' conversations and money. This page explains how API and MCP access is protected, and what you should do on your side.

## Credentials

**Keys belong to the workspace.** An API key is created inside one workspace, can only ever reach that workspace, and stays under the workspace's control: every owner and admin can see and revoke every key, and a key keeps working (flagged for rotation) if the person who created it leaves. Only owners and admins can create keys or approve OAuth connections.

**Secrets are hashed at rest and shown once.** OnlyX stores only a SHA-256 hash of each API key and OAuth token, never the secret itself. An API key is displayed once, when you create it; after that, nobody at OnlyX or in your workspace can read it back. Lost keys are revoked and replaced, never recovered. Keys and tokens are never written to logs.

**Revocation is immediate and permanent.** Revoke a key or a connected app in **Settings → API & MCP**, and the next request with it fails with `401`.

**Short-lived OAuth tokens.** Access tokens last one hour. Refresh tokens last 60 days and are replaced on every use; if an old refresh token is ever used again, the whole connection is revoked, because that means it was copied. A connection also stops working when the person who approved it is no longer an owner or admin of the workspace.

## Least privilege

* **Scopes** limit what a credential can do. Reading, writing in OnlyX, and reaching fans are separate permissions; sending messages needs its own `messages:send` scope. See [Authentication](/developers/authentication#scopes).
* **Creator restrictions** limit which creators a credential can see at all.
* **Expiry** makes temporary keys expire on their own.

Give each integration its own key with only the scopes and creators it needs.

## OAuth consent

When an AI assistant or app connects with OAuth, a workspace owner or admin approves it on an OnlyX consent screen that shows:

* the app's self-declared name, marked as unverified;
* the host it will send you back to;
* every permission it asks for, with the ones that can reach fans highlighted;
* which workspace it gets, and optionally which creators.

OnlyX requires PKCE for every authorization, only redirects to the exact address the app registered, and lists every approved connection under **Connected apps** for review and revocation.

## Tenant isolation

Every request is limited to the credential's workspace and creator restriction. An id that belongs to another workspace, or to a creator outside the restriction, returns `404` with exactly the same body as an id that does not exist, so the API never reveals whether something exists elsewhere. A creator filter naming an invisible creator returns `404 CREATOR_NOT_FOUND` rather than an empty list.

## Actions that reach fans

Writes that can message a fan or change a creator's live OnlyFans account (sending, releasing a chat to the AI, turning a chat's AI on, resolving a hand-off, turning review mode off, replacing the welcome message, creating a tracking link):

* need their own write scope, and turning review mode off also needs `messages:send`;
* are rate limited per credential and per creator ([Rate limits](/developers/rate-limits));
* accept an `Idempotency-Key`, which is required for sends, so a retry never acts twice ([Idempotency](/developers/idempotency));
* are marked as fan-reaching for AI assistants, which are told to confirm with you first ([MCP tools](/developers/mcp/tools)).

OnlyX can also switch off sending through the API platform-wide in an emergency; sends then return `503 SENDING_DISABLED` and nothing is sent.

## What the API never returns or accepts

* **OnlyFans passwords, two-factor codes, session cookies or selfies.** The API has no field for them. Creators sign in themselves, on their own device, through a connect link and the OnlyX Login app ([Add a creator](/developers/guides/add-a-creator)).
* **The AI chatter's internal instructions or configuration.** You see the persona and content you wrote, and the results; never how the AI is built.
* **Other workspaces' data**, in any form.
* **Internal error details.** Errors carry a code, a plain sentence and a request id, never a stack trace or internal cause.

Connect links are the one secret the API hands out on purpose: whoever holds one can sign an OnlyFans account into that creator. They expire after 24 hours, are used up on success, can be revoked at any time, are returned with `cache-control: no-store`, and report `opens` so you can spot a leaked link.

## The MCP server

The MCP server at `https://mcp.onlyx.ai/mcp` holds no data and no credentials of its own. Each request carries your OAuth token or API key, and the server uses exactly that credential against the OnlyX API, which enforces every check above. It keeps nothing between requests, never logs credentials, and accepts browser requests only from known AI assistant origins. See [MCP overview](/developers/mcp/overview).

## Transport

The API, the OAuth endpoints and the MCP server are served over HTTPS only. Send credentials only in headers (`Authorization` or `X-API-Key`), never in URLs.

## Your side of the deal

* Store keys in a secret manager or environment variables. Never commit them, paste them into chats, or ship them in browser or mobile apps.
* Use one key per integration, with the fewest scopes and creators that work, and an expiry for temporary access.
* Review **Settings → API & MCP** regularly: revoke keys nobody uses (check **Last used**) and apps you no longer recognize.
* Rotate keys when people with access leave.
* Treat fan messages as untrusted input in your own software and in AI assistants: never execute instructions found in them.
* Send connect links only to the creator, through a private channel.

## Reporting a vulnerability

Email **[security@onlyx.ai](mailto:security@onlyx.ai)** with a description, the steps to reproduce, and any `requestId` values. Please do not access data that is not yours, do not message real fans or creators while testing, and give us reasonable time to fix the issue before disclosing it. We will acknowledge your report and keep you informed.

If you believe an API key or token of yours has leaked, revoke it immediately in **Settings → API & MCP**, then tell us at the same address.
