API keys and scopes#
The Data API is authed with an API key: Authorization: Bearer sk_live_…. A key belongs to your account and carries scopes (posts:read, comments:read, …).
Authorization: Bearer sk_live_xxxxxxxxxxxx
# optionally target a specific linked connection:
X-Skool-Connection: <connectionId>
Write scopes and DMs#
Write scopes (posts:write, comments:write, dms:write) and dms:read are opt-in when minting: writes publish, delete and message as the connected Skool account, and the inbox is private.
Sent DMs cannot be deleted
POST /v1/dms is throttled per Skool connection to a human pace (about one message every 30–45 s, 20 per hour, 100 per day) and answers 429 rate_limited with Retry-After beyond that.OAuth connectors added before these scopes existed must be re-added to get them.
Multiple connections#
If you linked several Skool accounts, an unbound key can target one with the X-Skool-Connection header; a key bound to a connection always uses that one (a different header is a 403).
Rotation and revocation#
Rotate with POST /v1/keys/:id/rotate — the old key keeps working for a 24h grace window so you can swap without downtime. Revoke instantly with DELETE.