Skip to main content
Every REST API v1 request requires a levios API key. Send the key as a Bearer credential:
API v1 does not accept OAuth access tokens or levios browser sessions. OAuth is reserved for the MCP server. Keep API keys in server-side code or a secret manager. Do not expose them in a browser, mobile application, public repository, log, or support message.

Create an API key

Create and revoke keys in API key settings. When you create a key, choose its scopes and the Instagram accounts it can access. levios shows the full secret once, so store it before you leave the page. Send the key in the Bearer header:

Scopes and account access

A request must satisfy both the operation scope and the account access granted to the key. API v1 currently uses these operation scopes:
  • automations:read lists automations and reads one automation.
  • automations:write creates, updates, and deletes automations.
  • automations:activate activates or pauses an automation.
  • contacts:read_pii reads complete contact records.
  • contacts:write manages contact tags and assignments.
  • metrics:read reads account and automation metrics.
The account catalog has no operation-specific scope, but it still requires a valid API key. It returns only the accounts available to that key.

Authentication failures

The API returns 401 with api_unauthorized when it cannot accept the API key. A valid key without the required scope or account access returns 403. Do not use an error response to determine whether a key or account exists. Revoke and replace a key through levios settings if you suspect exposure. See Errors for the response envelope and correlation IDs.