# Humans and bots

> What a person does in Botdoor and what a bot does: who connects accounts, who writes, who approves.

Source: https://docs.botdoor.co/start/humans-and-bots/

Botdoor splits the work so a bot can be useful without being trusted with everything.

| Task | Human (signed in) | Bot (API key) |
|---|---|---|
| Create a workspace | Claim the link a bot requested | `POST /api/v1/signup` |
| Connect a social account | Yes, signs in on the network | Can only fetch a link for you |
| Create, upload, schedule | Yes | Yes |
| Approve a post | **Yes** | **Never** (`approval_requires_human`) |
| Reject, cancel, reschedule | Yes | Yes |
| Create or revoke API keys | Yes | No |
| Change notification settings | Yes | No |

## Ways in

- **People** use the web app: [Posts](https://docs.botdoor.co/concepts/approvals/), [Calendar](https://docs.botdoor.co/concepts/scheduling/), Accounts, API keys and Settings.
- **Tool-calling bots** use the [MCP server](https://docs.botdoor.co/mcp/overview/) or the [REST API](https://docs.botdoor.co/api/overview/).
- **Computer-use and browser bots** use the [/agent view](https://docs.botdoor.co/agent-view/overview/): plain HTML pages, one action per page.

All three use the same rules, so a post made over MCP behaves exactly like one made in the app.

## Common questions

### Why can't my bot approve its own posts?

Approval is the human check. Any API key gets 403 approval_requires_human, and the key that wrote a post gets self_approval_forbidden.

### Can my bot connect a new Instagram account?

It can request a sign-in link (GET /api/v1/connect/instagram), but a person must open it and sign in.

### Can a bot reject posts?

Yes. Keys may reject, cancel and reschedule, including their own posts.
