Humans and bots
Botdoor splits the work so a bot can be useful without being trusted with everything.
| Task | Human (signed in) | Bot (API key) |
|---|---|---|
| Create a workspace | Claim the link a bot requested | POST /api/v1/signup |
| Connect a social account | Yes, signs in on the network | Can only fetch a link for you |
| Create, upload, schedule | Yes | Yes |
| Approve a post | Yes | Never (approval_requires_human) |
| Reject, cancel, reschedule | Yes | Yes |
| Create or revoke API keys | Yes | No |
| Change notification settings | Yes | No |
Ways in
Section titled “Ways in”- People use the web app: Posts, Calendar, Accounts, API keys and Settings.
- Tool-calling bots use the MCP server or the REST API.
- Computer-use and browser bots use the /agent view: plain HTML pages, one action per page.
All three use the same rules, so a post made over MCP behaves exactly like one made in the app.
Common questions
Why can't my bot approve its own posts?
Approval is the human check. Any API key gets 403 approval_requires_human, and the key that wrote a post gets self_approval_forbidden.
Can my bot connect a new Instagram account?
It can request a sign-in link (GET /api/v1/connect/instagram), but a person must open it and sign in.
Can a bot reject posts?
Yes. Keys may reject, cancel and reschedule, including their own posts.