MyPersonas / AliaSpaces

Owner setup center

Connect accounts safely

Use this page to see which accounts can connect, which require a developer app or provider review, and which should stay in MyPersonas as a manual posting handoff.

Production status verified August 30, 2026
A saved account is not an authenticated account. MyPersonas never treats a username, matching email, password, or cookie as provider permission. Direct posting stays off until the provider's official connector, write permission, and a real-account test all pass. The live site, provider migrations 065–076, and matching Edge functions are deployed. That is infrastructure readiness only: no content is scheduled, queued, or publishing, and no recurring publisher cron job is enabled.
Connectable now

The connector exists, but an owner console or verification step may still be required.

Requires provider app/review

An official route exists; credentials, review, or a connector build remain.

Limited / special connector

Bot, business, partner, local bridge, mailbox, or partial API only.

Manual staging only

Prepare everything here; publish or send in the official provider yourself.

Truthful publishing status

A saved account is only step 1 of 7

Each check must describe a different fact. A username in the Account Ledger, an active sign-in, or a provider offering an API does not prove that MyPersonas can publish to the intended destination.

No preview, no approval, no schedule, no send — always

Release requirement: every approve, schedule, and immediate-action control must stay disabled until MyPersonas renders the platform-specific preview from a short-lived server snapshot. Your confirmation records a separate AAL2 acknowledgement for that exact revision, destination, action, and time; only the unchanged receipt can be consumed once. Any later change invalidates the receipt and requires a new preview.

Exact destination
Platform, account, Page, channel, site, or campaign.
Platform layout
Full submitted media in the relevant aspect ratio frame, safe-area guidance, text limits, thumbnail, and link treatment.
Visibility and safety
Audience, privacy, accessibility text, AI/affiliate disclosures, and interaction settings.
Exact timing
Date, clock time, named time zone, and what the provider will do at that time.

Final rendering can vary by device, placement, provider UI, and active theme. For Wix and WordPress, MyPersonas shows its platform-shaped preview and then requires the provider's own draft preview before any later public schedule.

Put each credential in the right private place

Open the official MyPersonas Edge Function secrets page in your own signed-in browser. Add each key and value there and press Save. Saved settings are available to the deployed functions without another deployment. Never paste a secret into MyPersonas, the Account Ledger, source files, or chat.

Exact production setting names and callbacks used by the deployed connector functions.
ProviderEdge Function settingsExact provider callback
YouTubeYOUTUBE_CLIENT_ID
YOUTUBE_CLIENT_SECRET
Optional overrides: YOUTUBE_OAUTH_REDIRECT_URI, YOUTUBE_OAUTH_APP_ORIGIN.
https://nwsqyuucwzihruszocge.supabase.co/functions/v1/youtube-oauth
TikTokTIKTOK_CLIENT_KEY
TIKTOK_CLIENT_SECRET
TIKTOK_OAUTH_REDIRECT_URI
TIKTOK_OAUTH_APP_ORIGIN
Leave TIKTOK_DIRECT_POST_ENABLED false and TIKTOK_CLIENT_AUDIT_STATE unset.
https://nwsqyuucwzihruszocge.supabase.co/functions/v1/tiktok-oauth
DiscordDISCORD_CLIENT_ID
DISCORD_CLIENT_SECRET
Optional overrides: DISCORD_OAUTH_REDIRECT_URI, DISCORD_OAUTH_APP_ORIGIN.
https://nwsqyuucwzihruszocge.supabase.co/functions/v1/discord-oauth
TwitchTWITCH_CLIENT_ID
TWITCH_CLIENT_SECRET
TWITCH_OAUTH_REDIRECT_URI
TWITCH_OAUTH_APP_ORIGIN
https://nwsqyuucwzihruszocge.supabase.co/functions/v1/twitch-oauth
PatreonPATREON_CLIENT_ID
PATREON_CLIENT_SECRET
PATREON_OAUTH_REDIRECT_URI
PATREON_OAUTH_APP_ORIGIN
https://nwsqyuucwzihruszocge.supabase.co/functions/v1/patreon-oauth
WixWIX_APP_ID
WIX_SHARE_URL_ID
WIX_POST_INSTALL_URI
WIX_OAUTH_APP_ORIGIN
App secret: Vault-only wix_app_secret.
https://nwsqyuucwzihruszocge.supabase.co/functions/v1/wix-oauth
WordPress.comWORDPRESS_COM_CLIENT_ID
WORDPRESS_COM_REDIRECT_URI
WORDPRESS_OAUTH_APP_ORIGIN
Client secret: Vault-only wordpress_com_client_secret.
https://nwsqyuucwzihruszocge.supabase.co/functions/v1/wordpress-oauth

Use https://mypersonas.online for every listed app-origin setting and the matching callback above for every redirect or post-install setting. Wix and WordPress.com's two Vault-only secrets are deliberate exceptions: the deployed CMS functions will not read them from Edge Function settings. Use the reviewed secure Vault setup and Supabase Vault guidance.

  1. 1InventoryThe account or site is saved.
  2. 2App credentialsThe provider recognizes MyPersonas.
  3. 3Owner sign-inThe correct owner authorized access.
  4. 4Write permissionThe exact action is allowed.
  5. 5Target bindingThe exact destination is selected.
  6. 6Publisher liveReviewed MyPersonas code handles results safely.
  7. 7Provider proofA private, draft, or reversible test passed.
Current MyPersonas release snapshot. These are separate checks, not one combined “connected” badge.
Provider1 · Inventory2 · Credentials3 · Owner sign-in4 · Write permission5 · Target6 · Publisher7 · Test
Facebook Pages28 savedWorking25 fresh25 write-scoped25 boundDeployed, gatedNot run for this release
Instagram28 savedWorking25 fresh25 write-scoped25 boundDeployed, gatedNot run for this release
X / Twitter28 savedRecheck app27 expired0 with tweet.writeNo usable bindingDeployed, blockedNot run
YouTubeSavedNeeded0 connectedNot grantedChannel not boundDeployed, blockedNot run
TikTokSavedNeeded0 connectedNot grantedCreator not boundDeployed, blockedNot run
TwitchSavedNeeded0 connectedNo action grantChannel not boundDeployed, blockedNot run
PatreonSavedNeeded for reports0 connectedNo create-post scopeCampaign not boundDeployed handoff onlyNative proof needed
WixSavedCreate Wix app0 connectedNot grantedSelect site + authorDeployed, blockedDraft proof not run
WordPressIdentify exact sitesChoose .com or hosted0 connectedNot grantedSelect site + authorDeployed, blockedDraft proof not run
What are the numbers and IDs next to “Save target”?
Client IDIdentifies the MyPersonas developer app to the provider. It is not an account count and is normally safe to display.
Client secretThe developer app's password. Never put it in a target field, this page, a note, or chat.
Target IDThe provider's permanent number for the exact Page, channel, creator, campaign, or site. “Save target” means bind this record to that destination.
Author/member IDSelects the correct byline on a multi-author Wix or WordPress site. It is not the number of members.
Provider post IDThe receipt returned after a successful provider action. It lets MyPersonas reconcile or avoid a duplicate.
Saved / connected countFor example, 3 / 0 means three inventory records and zero authorized connections. It does not mean three posts.

Discord

Exact channel only

Implemented route: Discord's official webhook.incoming OAuth consent binds one exact server/channel webhook. It does not automate a user account or install a bot token.

Not ready now: production has zero Discord credential and connection rows. The app credentials, exact channel consent, and one designated-channel send/readback proof are still required.

Owner setup

  1. Create an application in the Discord Developer Portal.
  2. Add callback https://nwsqyuucwzihruszocge.supabase.co/functions/v1/discord-oauth.
  3. Save DISCORD_CLIENT_ID and DISCORD_CLIENT_SECRET through the credential handoff above.
  4. In MyPersonas, choose Connect Discord channel and select the exact server/channel on Discord's webhook.incoming consent screen.
Safe proof: send one separately previewed message to a designated test channel, reconcile the returned provider result, and disconnect cleanly. Do not paste a webhook URL, bot token, user token, or Discord password.
Required preview: exact server and channel, complete message and attachment, mention policy, disclosure, and the immediate send action. Mentions remain disabled by default.

Official Discord OAuth2 documentation

YouTube

Private test first

Supported route: upload video through YouTube Data API v3 with the narrow youtube.upload permission. A private upload is the safe first proof.

Not ready now: the OAuth and Private-first uploader are deployed, but production credentials are not installed and there are zero YouTube connections. Owner authorization, exact channel binding, and a Private provider proof are still required.

Owner setup

  1. Open Google Cloud credentials, choose a dedicated project, and enable YouTube Data API v3.
  2. Configure OAuth, create a Web client, and add callback https://nwsqyuucwzihruszocge.supabase.co/functions/v1/youtube-oauth.
  3. Save YOUTUBE_CLIENT_ID and YOUTUBE_CLIENT_SECRET through the credential handoff above.
  4. Authorize the intended channel with youtube.upload, then confirm its channel name and ID before saving the target.
Safe proof: upload one clearly labeled test video as Private, read its returned video ID and status, then leave it private or delete it only after approval. Unverified API projects can be restricted to private uploads.
Required preview: 16:9 or Shorts crop, thumbnail, title, description opening, audience setting, privacy, synthetic-media disclosure, destination channel, and schedule with time zone.

Official YouTube upload requirements

TikTok

Consent required

Implemented route: TikTok Upload-to-inbox uses the narrow video.upload scope; the owner finishes caption, privacy, disclosure, and interaction choices in TikTok. Direct Post is disabled.

Not ready now: the Upload-to-inbox connector is deployed, but production credentials are not installed and there are zero TikTok connections. Owner OAuth, exact creator binding, verified media source, and an inbox proof are still required.

Owner setup

  1. Open TikTok for Developers — My Apps and add Content Posting API.
  2. Add callback https://nwsqyuucwzihruszocge.supabase.co/functions/v1/tiktok-oauth and request only video.upload.
  3. Save TIKTOK_CLIENT_KEY, TIKTOK_CLIENT_SECRET, TIKTOK_OAUTH_REDIRECT_URI, and TIKTOK_OAUTH_APP_ORIGIN through the credential handoff above. Keep Direct Post disabled.
  4. At handoff time, review the exact creator and media; then finish privacy and interaction settings inside TikTok.
Safe proof: upload one designated video to the TikTok inbox and poll its provider status. Finish or discard it in TikTok. This does not enable Direct Post or unattended public scheduling.
Required preview: full vertical asset in its aspect frame and safe zones, cover frame, caption handoff, account, disclosure, and the exact Upload-to-inbox action. TikTok's own final screen controls privacy and comments/duet/stitch choices.

Official Content Posting setup · Upload-to-inbox reference

Twitch

Limited actions only

Implemented route: exact channel information, stream schedule segments, and announcements through channel:manage:broadcast, channel:manage:schedule, and moderator:manage:announcements.

Not supported: Twitch does not provide a general social-feed or uploaded-video publisher. “Connect Twitch” cannot honestly promise ordinary scheduled posts.

Owner setup

  1. Register an app in the Twitch Developer Console with callback https://nwsqyuucwzihruszocge.supabase.co/functions/v1/twitch-oauth.
  2. Save TWITCH_CLIENT_ID, TWITCH_CLIENT_SECRET, TWITCH_OAUTH_REDIRECT_URI, and TWITCH_OAUTH_APP_ORIGIN through the credential handoff above.
  3. Select the exact Twitch channel and only the feature set you want: channel information, schedule, or announcements.
  4. Grant only the matching scopes; nonrecurring schedule operations can depend on Affiliate/Partner eligibility.
Safe proof: first verify channel identity with a read. Any schedule or announcement write can be visible, so it needs a separate exact preview and approval; use a reversible schedule item or a designated test channel where available.
Required preview: the real action shape—not a fake feed card. Show the schedule segment, channel change, or chat announcement exactly as applicable, with target channel and timing.

Official Twitch API · Scopes · Schedule API

Patreon

Native post scheduler

Implemented API route: read the authorized identity, list campaigns, bind one exact campaign, and report its existing posts through identity, campaigns, and campaigns.posts. The separate handoff opens Patreon's native editor after an exact preview. Membership details, webhooks, Patreon Live capabilities for an eligible early-access integration, and provider-side post creation are not implemented in this release.

Not supported: the public API does not offer a general create-post permission. Ordinary Patreon posts must be completed and scheduled in Patreon.

Owner setup

  1. Register a client in the Patreon developer portal for the deployed read-only report.
  2. Add callback https://nwsqyuucwzihruszocge.supabase.co/functions/v1/patreon-oauth.
  3. Save PATREON_CLIENT_ID, PATREON_CLIENT_SECRET, PATREON_OAUTH_REDIRECT_URI, and PATREON_OAUTH_APP_ORIGIN through the credential handoff above.
  4. Bind the exact campaign and grant only identity, campaigns, and campaigns.posts.
  5. For content, use MyPersonas to prepare the package, then open Patreon's native scheduled-post flow.
Safe proof: verify reporting access read-only. For a post, create a Patreon draft, preview its audience/tier and date in Patreon, then return to MyPersonas and record the native draft or post URL.
Required preview: title, body, media, attachment, campaign, access tier/audience, charge setting when applicable, disclosures, and Patreon's own draft preview before scheduling.

Official Patreon API documentation

Wix

Exact site required

Implemented route: an installed Wix app can create a Wix Blog draft for the exact selected site and author. This build does not accept account API keys.

Not ready now: a Wix account seen in another signed-in tool is not permission for the deployed MyPersonas app. Current ledger records are not bound to an exact Wix site and author.

Owner setup

  1. Choose one site and confirm Wix Blog is installed on it.
  2. Create an app in Wix Custom Apps, request only Manage Blog and Read Members, release a version, and create a Share Install Link if the app is unlisted.
  3. Set the external post-install callback to https://nwsqyuucwzihruszocge.supabase.co/functions/v1/wix-oauth. Save WIX_APP_ID, the Share Install Link GUID as WIX_SHARE_URL_ID, that callback as WIX_POST_INSTALL_URI, and https://mypersonas.online as WIX_OAUTH_APP_ORIGIN through the credential handoff above.
  4. Put the app secret only in Supabase Vault under wix_app_secret; the deployed connector will not read it from Edge Function settings.
  5. In Studio → Accounts → Wix → Connection, choose Connect Wix site. Wix returns the exact site ID; MyPersonas then requires a separate exact author/member ID selection.
Safe proof: create one uniquely titled Wix Blog draft with publishing explicitly off, read it back from the exact site, and open its Wix preview. Do not publish during connector verification.
Required preview: active-theme draft preview on desktop and mobile, title, cover, excerpt, author, categories/tags, URL slug, SEO fields, disclosures, and exact site.

Official create-blog-post recipe · Draft Posts API · External install flow

WordPress

Choose the hosting route

Implemented route: WordPress.com uses production authorization-code OAuth with the posts scope; a self-hosted WordPress site can use its REST API with a separate, revocable Application Password. Both routes create Draft only.

Not ready now: “Website” inventory is not WordPress authorization. No exact WordPress.com or self-hosted site is bound to a live MyPersonas publisher.

Owner setup

  1. Identify each site as WordPress.com or self-hosted and save its exact public HTTPS address in the WordPress account record.
  2. For WordPress.com, register MyPersonas at WordPress.com Applications with callback https://nwsqyuucwzihruszocge.supabase.co/functions/v1/wordpress-oauth.
  3. Save WORDPRESS_COM_CLIENT_ID, that callback as WORDPRESS_COM_REDIRECT_URI, and https://mypersonas.online as WORDPRESS_OAUTH_APP_ORIGIN through the credential handoff above. Put the client secret only in Supabase Vault under wordpress_com_client_secret; the deployed connector will not read it from Edge Function settings.
  4. For self-hosted WordPress, create a dedicated Application Password in that site's user profile. Enter it only in Studio → Accounts → WordPress → Connection; the browser does not store it.
  5. After connection, Queue shows a second exact platform preview before the owner-triggered Create provider draft action. Reconciliation must be used instead of retrying an uncertain create result.
Safe proof: create one uniquely titled Draft, read it back from the exact site and exact author, and open WordPress Preview. Do not use Private, Publish, or Schedule as the connector test.
Required preview: active-theme Preview on desktop and mobile, title, featured image, excerpt, author, categories/tags, slug, SEO/disclosures, visibility, and exact site.

WordPress.com OAuth · WordPress.com REST API · Self-hosted Application Passwords

Do these first

  1. Keep the live Privacy, Terms, and Data deletion pages available for provider reviews.
  2. Add one Gmail address as a Google test user and complete one real inbox report.
  3. Verify the X Web App and API credits, then freshly authorize every intended X account with tweet.write; all 27 current connection records are expired.
  4. Keep the 25 fresh Facebook Page and 25 linked-Instagram grants, connect the remaining intended pairs, then run one separately previewed and approved low-stakes proof.
  5. Build Outlook next, then add the secure Yahoo/iCloud worker and local Proton companion.

Never paste secrets into the site

Provider app secrets, bot tokens, app passwords, recovery codes, and cookies belong nowhere in the Account Ledger or notes. Official account OAuth sends you to the provider's own sign-in screen. Server credentials go directly into encrypted deployment secrets.

Open the full detailed checklist

Searches the provider cards below. Clear the field to show every account type.

Meta: one Page-pairing flow for Facebook and Instagram

Use Facebook Login for Business to select Pages you administer and discover the eligible Instagram Business or Creator account linked to each Page. Facebook personal profiles and Instagram consumer accounts are not supported.

The hardened owner-triggered Facebook Page and linked-Instagram publisher is deployed. Production currently has 25 fresh Facebook Page connections and 25 fresh linked-Instagram connections with their write scopes. This does not prove a post: no current release proof has run, nothing is scheduled or queued, and recurring posting remains off.

Your setup

  1. Create the Business app in Meta for Developers.
  2. Confirm Pages, Instagram accounts, and roles in Meta Business settings, then select the correct business portfolio.
  3. Link each Instagram professional account to the correct Facebook Page.
  4. Add this callback:
https://nwsqyuucwzihruszocge.supabase.co/functions/v1/meta-oauth

Discovery starts with pages_show_list, pages_read_engagement, and instagram_basic.

Before synchronized publishing

  • Facebook Page posting needs pages_manage_posts.
  • Instagram posting needs instagram_content_publish.
  • Comments and insights require separate permissions only when enabled.
  • Meta review/Advanced Access, business verification when requested, live tests, and duplicate-safe reconciliation must pass.

Instagram API with Facebook Login documentation

No account type matched that search.
Social publishing

X / Twitter

Requires provider app/review

The text-only, owner-triggered publisher is deployed, but all 27 X connection records are expired and none includes tweet.write. Fresh authorization, API credits as required, and an exact-account proof are still required; media upload remains disabled.

  • Owner: create a confidential Web App in the X Developer Console; callback: https://nwsqyuucwzihruszocge.supabase.co/functions/v1/twitter-oauth.
  • Posting: add tweet.write and reauthorize; media upload remains disabled in the first release.
  • Cost: X uses pay-per-use credits.

Instagram

Requires provider app/review

Eligible Business or Creator accounts can publish through Meta. The publisher is deployed and 25 fresh linked-Instagram connections have write scope, but posting remains preview/approval gated and no current-release provider proof has run.

  • Owner: convert to professional, link the Page, add assets to Meta Business, and complete app review.
  • Permission: instagram_content_publish; comments/insights are separate.
  • Official Meta Instagram workspace

Facebook Page

Requires provider app/review

Official automation is for Pages the signed-in member administers—not personal profiles. The publisher is deployed and 25 fresh Page connections have write scope, but posting remains preview/approval gated and no current-release provider proof has run.

TikTok

Requires provider app/review

MyPersonas implements only Upload-to-inbox with video.upload. Direct Post and unattended public scheduling are disabled; the owner finishes every uploaded draft in TikTok.

YouTube

Requires provider app/review

Uploads use YouTube Data API v3 and youtube.upload. The safe connector proof is a private upload to the exact bound channel.

LinkedIn

Requires provider app/review

Member posting uses Share on LinkedIn. Organization/Page posting needs a qualifying Page role and Community Management access.

  • Owner: create the app at LinkedIn Developers and associate the Page.
  • Permission: w_member_social for member posts; the portal's current approved organization scope is authoritative.

Bluesky

Requires connector build

No conventional app review, but MyPersonas still needs a security-complete OAuth connector and AT Protocol publisher.

  • Owner: authorize the correct account after client metadata and callback are live.
  • MyPersonas: PKCE, PAR, DPoP, refresh rotation, secure keys, record publishing, and revocation.
  • Official OAuth guide

Threads

Requires provider app/review

Threads publishing requires a Meta app, its own OAuth connector, review for production users, and threads_content_publish.

Snapchat

Requires provider app/review

The Public Profile API is allowlist-only. Personal Snapchat automation is not supported.

Reddit

Requires provider app/review

Devvit can submit as a user only after a clear, separate owner action. Reddit explicitly disallows unattended user actions.

  • Owner: create a Devvit project, request only submit permissions, publish, and complete approval.
  • Commercial use: may require a separate Reddit agreement.
  • User-action rules
Bots, memberships, live streams, and business messaging

Discord

Limited / special connector

The exact-channel webhook.incoming connector is deployed, but production has zero Discord credential and connection rows. Automating a normal user account is prohibited.

Telegram

Limited / special connector

Use a bot as an administrator in the intended channel or group; do not treat a personal Telegram login as normal web OAuth.

WhatsApp

Limited / special connector

WhatsApp Business Platform supports business customer messaging, not social-feed publishing or personal WhatsApp management.

  • Owner: create a WhatsApp Business Account/number, add Cloud API, configure webhooks, templates, review, and billing.
  • Official Cloud API collection

Patreon

Limited / special connector

The deployed connector reads the authorized identity, campaigns, and existing campaign posts, then offers an exact-preview handoff to Patreon's native editor. It does not implement member details, webhooks, Patreon Live, or provider-side post creation.

Twitch

Limited / special connector

The deployed connector covers channel details, eligible schedule segments, and announcements—not a general social-feed/video-upload publisher.

Kick

Limited / special connector

Kick's API covers channel updates, chat, events, rewards, moderation, and live information—not ordinary feed publishing.

Rumble

Manual staging only

No public upload API was located. Stage files and metadata here, then use Rumble's native uploader/scheduler.

  • Official upload guide
  • The documented Live Stream API is read/overlay data, not publishing authorization.
Email and inbox cleanup

Gmail

Connectable now

OAuth, report scans, exact approval plans, labels/archive/recoverable Trash, and Undo are implemented.

  • Owner: add each exact address under Google Auth test users, then press Connect Gmail.
  • Callback: https://nwsqyuucwzihruszocge.supabase.co/functions/v1/gmail-oauth.
  • Production: complete OAuth verification/security review as Google requires.

Outlook / Hotmail / Microsoft 365

Requires provider app/review

A delegated Microsoft Graph connector and Entra app must be built before a real Connect Outlook button can work.

  • Owner: register an app in Microsoft Entra for work and personal Microsoft accounts.
  • Start: Mail.Read; add Mail.ReadWrite only for approved cleanup. Do not add Mail.Send.

Yahoo Mail

Limited / special connector

Safe access needs a dedicated encrypted IMAP worker. Never put a Yahoo password or app password in the ledger.

  • Owner, after the worker exists: create a Yahoo app password and enter it only in encrypted secret entry.
  • IMAP: imap.mail.yahoo.com:993 with SSL.

iCloud Mail

Limited / special connector

Use Apple's supported third-party authorization when available, otherwise an app-specific password in the future encrypted worker.

  • Owner: enable 2FA and follow Apple's app-specific password instructions.
  • IMAP: imap.mail.me.com:993 with SSL.

Proton Mail

Limited / special connector

Requires a paid plan, Proton Bridge on a trusted always-on computer, and a local MyPersonas companion.

Email / Newsletter

Limited / special connector

This is a category, not a provider. Record the real service—such as Mailchimp, Kit, beehiiv, or another sender—so its official API can be evaluated.

  • Do not reuse a mailbox password as newsletter authorization.
  • Sending remains off until that provider's connector, consent, audience rules, and unsubscribe handling pass.
Websites, stores, reviews, and affiliate links

Wix

Requires provider app/review

Use the implemented Wix external app-install flow, then bind the exact site and author. A Wix sign-in elsewhere is not MyPersonas authorization.

WordPress

Choose the hosting route

WordPress.com and self-hosted WordPress need different authorization. A saved website URL is neither one.

  • Owner: identify the exact site, authorize only content writing, and select the author/byline when needed.
  • First proof: create and read back a Draft, then open WordPress Preview. Private, Publish, and Schedule are not part of this proof.
  • Open the exact WordPress readiness steps above

Website / Store

Limited / special connector

Record the actual host or CMS. WordPress, Shopify, Squarespace, Webflow, WooCommerce, and custom sites each need their own official route.

  • A saved URL is not authentication.
  • Domain, DNS, billing, checkout, legal, destructive, and major production changes stay owner-approved.

Etsy

Requires provider app/review

A Seller App can manage an eligible owner's shop; broader seller access requires Etsy review.

  • Owner: register at Etsy Developers with an active shop in good standing.
  • Start: listings_r and listings_w; add other scopes only for approved features.

Amazon / Affiliate

Limited / special connector

Amazon Associates plus the Creators API can provide approved product/link data. It does not authorize retail-account operation or social posting.

Yelp

Limited / special connector

Reply access is disabled by default and requires a claimed business plus Yelp Partner approval.

Trustpilot

Limited / special connector

Requires a Trustpilot for Business account and API module; multi-business integrations use the partner route.

LegalZoom

Limited / special connector

An official MCP path exists, but capability depends on the authorized service and documents. MyPersonas has no connector.

  • Default: inventory/manual only unless you choose a narrow document workflow.
  • Filings, signatures, purchases, account changes, and legal decisions remain owner-controlled.
  • Official LegalZoom MCP information

Fiverr

Manual staging only

No public general seller gig/order/message-management API was located.

Manual creator, private messaging, gaming, and other accounts

OnlyFans

Manual staging only

No public official developer/account-management API was located. Do not use passwords, cookies, session copying, scraping, auto-DMs, or unofficial login automation.

  • Safe workflow: stage media/caption/link, approve, open the media handoff, copy the package, open OnlyFans, publish in its signed-in interface, then mark posted.
  • Use a native scheduler only if the current signed-in interface offers it.
  • Draft replies only from message text you paste or explicitly supply.

Signal

Manual staging only

Signal has no supported hosted account-management API for this use and prohibits bulk/automated messaging.

  • Paste or supply message text for a draft, review it, and send it yourself.
  • Signal terms

Steam

Manual staging only

Steam Web APIs cover public data and approved publisher operations, not general consumer-account/social management.

PlayStation

Manual staging only

PlayStation Partners is for game development/publishing. Personal PSN account management stays manual.

Nintendo

Manual staging only

Nintendo's developer program is for game development/publishing. Consumer account management stays manual.

Epic Games

Manual staging only

Epic Online Services supports a developer's game integration, not a general Epic consumer-account manager.

Other

Manual staging only

Record the real provider and public account URL. MyPersonas will check for an official API, eligibility, review, pricing, and terms before enabling anything.

  • Until that review is complete, use the manual handoff and never store credentials in the record.

Manual posting handoff

Use this sequence for OnlyFans, Fiverr, Rumble, Signal, gaming accounts, and any provider without a live-tested write connector.

Stage
Caption, media, accessibility text, warning, disclosure, link, target, and time.
Approve
Review the exact package and approve or deny it in MyPersonas.
Handoff
Copy the package, open its media asset, and open the official provider.
Publish
Sign in and complete the action in the provider's own interface.
Record
Return to MyPersonas and mark the staged item posted or sent.

Automation that MyPersonas will not use

Important limits

Provider permissions, review rules, prices, rate limits, and product names change. Recheck the linked official source immediately before applying. A provider offering an API does not mean MyPersonas has implemented it.

Read the full provider-by-provider owner and Codex checklist.