Skip to content

Humans and bots

Botdoor splits the work so a bot can be useful without being trusted with everything.

Task Human (signed in) Bot (API key)
Create a workspace Claim the link a bot requested POST /api/v1/signup
Connect a social account Yes, signs in on the network Can only fetch a link for you
Create, upload, schedule Yes Yes
Approve a post Yes Never (approval_requires_human)
Reject, cancel, reschedule Yes Yes
Create or revoke API keys Yes No
Change notification settings Yes No
  • People use the web app: Posts, Calendar, Accounts, API keys and Settings.
  • Tool-calling bots use the MCP server or the REST API.
  • Computer-use and browser bots use the /agent view: plain HTML pages, one action per page.

All three use the same rules, so a post made over MCP behaves exactly like one made in the app.

Common questions

Why can't my bot approve its own posts?
Approval is the human check. Any API key gets 403 approval_requires_human, and the key that wrote a post gets self_approval_forbidden.
Can my bot connect a new Instagram account?
It can request a sign-in link (GET /api/v1/connect/instagram), but a person must open it and sign in.
Can a bot reject posts?
Yes. Keys may reject, cancel and reschedule, including their own posts.