id, never against bare credentials.
Two connect shapes
Both end with a row in
platform_accounts and an id you reference from post bodies as targets[].accountId.
OAuth: connect → complete
connect.sh
Credentials: Bluesky
Bluesky doesn’t have OAuth; it uses scoped app passwords. Generate one at bsky.app/settings/app-passwords, then submit:bluesky.sh
platform_auth_failed.
Meta surfaces each connect separately
Facebook Pages, Instagram Business, and Threads each have their own connect flow — one OAuth perplatform_accounts row. Connecting facebook discovers Pages via GET /me/accounts; connecting instagram runs the standalone Instagram Login OAuth and uses /me?fields=id for the Content Publishing API user id; connecting threads runs Threads’ own OAuth at threads.net. No silent fan-out — every connected identity is one explicit OAuth.
Token lifecycle
We refresh access tokens on each platform’s published schedule and AES-256-GCM encrypt them at rest:
Subscribe to
token.expiring and token.revoked to know when a connection needs user attention.
Listing and disconnecting
Errors during connect
See also
- Authentication — letmepost API keys (separate from OAuth tokens).
- Per-platform pages — exact scope sets and quirks.

