# API & SDK for social media > Direct answers on the REST API & TypeScript SDK: auth, scopes, validation, platform options, limits, errors & signed webhooks. ## [How to authenticate with the DunSocial API](https://www.dunsocial.com/hub/dunsocial-api-and-sdk-guides/how-to-authenticate-with-the-dunsocial-api.md) The two ways to authenticate: a session token for apps & a personal access token for scripts, plus the X-Workspace-Id header every workspace route needs. ## [Which PAT scopes should you grant for each automation job?](https://www.dunsocial.com/hub/dunsocial-api-and-sdk-guides/which-pat-scopes-should-you-grant-for-each-automation-job.md) Every DunSocial personal access token scope, & a least-privilege recommendation for common jobs like a release announcer, a content importer & a dashboard. ## [How to schedule a post with the DunSocial API](https://www.dunsocial.com/hub/dunsocial-api-and-sdk-guides/how-to-schedule-a-post-with-the-dunsocial-api.md) The POST /api/posts/schedule request: body fields, what comes back, the all-or-nothing validation rule, publish-now & X threads. ## [How to validate a social post before scheduling it with the API](https://www.dunsocial.com/hub/dunsocial-api-and-sdk-guides/how-to-validate-a-social-post-before-scheduling-it-with-the-api.md) Use POST /api/posts/validate to dry-run limits, media, platform options & the X cap. It returns HTTP 200 even when the post is invalid. ## [What platform options does the DunSocial API require?](https://www.dunsocial.com/hub/dunsocial-api-and-sdk-guides/what-platform-options-does-the-dunsocial-api-require.md) The metadata block each platform needs when you schedule or publish through the DunSocial API: Reddit, Instagram, Pinterest, TikTok, Discord & Slack. ## [What character limits does the DunSocial API enforce?](https://www.dunsocial.com/hub/dunsocial-api-and-sdk-guides/what-character-limits-does-the-dunsocial-api-enforce.md) The post length limit for each platform in the DunSocial API, including X Premium, & how to check a post before sending it. ## [How to upload media with the DunSocial API](https://www.dunsocial.com/hub/dunsocial-api-and-sdk-guides/how-to-upload-media-with-the-dunsocial-api.md) The three-step upload flow: request a presigned URL, PUT the file, then complete the asset. Includes size limits, alt text & deleting. ## [What rate limits does the DunSocial API have?](https://www.dunsocial.com/hub/dunsocial-api-and-sdk-guides/what-rate-limits-does-the-dunsocial-api-have.md) The per-endpoint rate limits in the DunSocial API, what a 429 looks like, the separate X posting cap & how to back off sensibly. ## [What do DunSocial API error codes mean?](https://www.dunsocial.com/hub/dunsocial-api-and-sdk-guides/what-do-dunsocial-api-error-codes-mean.md) Every HTTP status the DunSocial API returns, the JSON error shape, & which errors are worth retrying. ## [How to set up a DunSocial webhook endpoint](https://www.dunsocial.com/hub/dunsocial-api-and-sdk-guides/how-to-set-up-a-dunsocial-webhook-endpoint.md) Create a webhook endpoint in Settings or through the API, choose events, store the secret once & test deliveries. ## [How to verify a DunSocial webhook signature](https://www.dunsocial.com/hub/dunsocial-api-and-sdk-guides/how-to-verify-a-dunsocial-webhook-signature.md) Check the HMAC-SHA256 signature on every DunSocial webhook delivery using the raw body, the timestamp header & your endpoint secret. ## [How to use the DunSocial TypeScript SDK](https://www.dunsocial.com/hub/dunsocial-api-and-sdk-guides/how-to-use-the-dunsocial-typescript-sdk.md) Install dunsocial-sdk, create a client with a token & workspace id, & see which runtimes & scopes it works with. ## [How to schedule a post with the DunSocial TypeScript SDK](https://www.dunsocial.com/hub/dunsocial-api-and-sdk-guides/how-to-schedule-a-post-with-the-dunsocial-typescript-sdk.md) Schedule, publish, validate & wait for a post with the SDK, upload media in one call, & post X threads. ## [Where is the DunSocial OpenAPI spec?](https://www.dunsocial.com/hub/dunsocial-api-and-sdk-guides/where-is-the-dunsocial-openapi-spec.md) Where to find the machine-readable DunSocial API contract, what it covers, & how to use it to generate a client. ## About this document This is the Markdown representation of https://www.dunsocial.com/hub/dunsocial-api-and-sdk-guides. The HTML version of the same page is at the same URL. You can also request Markdown from any page by sending `Accept: text/markdown`. Machine-readable summary of the whole site: https://www.dunsocial.com/llms.txt ## Company - Product: DunSocial, https://www.dunsocial.com - Legal entity: THISUX PRIVATE LIMITED, Chennai, Tamil Nadu, India - Support: support@dunsocial.com - Open the app: https://app.dunsocial.com/login