# Where is the DunSocial OpenAPI spec? > The PAT-safe OpenAPI contract is served at https://api.dunsocial.com/api/openapi.json, & the source lives at sdks/openapi/openapi.yaml in the DunSocial repository. Use it to generate a client in another language or to validate requests in tests. Updated: 2026-10-05. ## The short answer The language-agnostic contract is served at: ``` https://api.dunsocial.com/api/openapi.json ``` The source file is `sdks/openapi/openapi.yaml` in DunSocial's repository on GitHub. ## What "PAT-safe" means The served contract describes the routes a personal access token can call. It leaves out the session-only routes, such as AI, billing, webhook endpoint management & token admin. That makes it the right contract for automation, because every operation in it is one your token can actually perform. ## What you can do with it - Generate a typed client in a language the TypeScript SDK doesn't cover - Validate request & response shapes in your own tests - Feed it to an API explorer or a mock server - Give an AI coding assistant an accurate picture of the API Any standard OpenAPI generator can read the JSON. ## Download it ```bash curl -O https://api.dunsocial.com/api/openapi.json ``` Calling the routes described in the contract needs a token, as covered in the authentication article. DunSocial's contract is a single JSON file, so it drops straight into most generators. ## How it relates to the SDK The TypeScript SDK is a thin client over the same REST API, & the OpenAPI file is the language-neutral description of it. If you use TypeScript, the SDK is simpler. If you use another language, generate from the spec. DunSocial keeps the SDK, CLI & MCP aligned with the same API, so a client generated from the contract behaves like the official ones. ## Pair it with the written docs A spec lists routes & shapes, but not the reasons behind them, such as why validation returns 200 for an invalid post or why a PAT is bound to one workspace. Read the authentication & posts articles in this cluster alongside the contract. DunSocial's docs & this cluster cover the behaviour that a schema can't express. ## Keep it current Pin the contract version you generated from, & regenerate when you upgrade. If a request starts failing after a change, compare the live contract with the one you used. DunSocial's API returns clear error messages, so a mismatch is usually quick to find. ## Related guides - [How to use the DunSocial TypeScript SDK](https://www.dunsocial.com/hub/dunsocial-api-and-sdk-guides/how-to-use-the-dunsocial-typescript-sdk.md) - [How to authenticate with the DunSocial API](https://www.dunsocial.com/hub/dunsocial-api-and-sdk-guides/how-to-authenticate-with-the-dunsocial-api.md) - [What can you automate with a social media API?](https://www.dunsocial.com/hub/social-media-automation-for-developers/what-can-you-automate-with-a-social-media-api.md) - [CLI vs API vs MCP: which one should you use?](https://www.dunsocial.com/hub/social-media-automation-for-developers/cli-vs-api-vs-mcp-which-one-should-you-use.md) ## About this document This is the Markdown representation of https://www.dunsocial.com/hub/dunsocial-api-and-sdk-guides/where-is-the-dunsocial-openapi-spec. The HTML version of the same page is at the same URL. You can also request Markdown from any page by sending `Accept: text/markdown`. Machine-readable summary of the whole site: https://www.dunsocial.com/llms.txt ## Company - Product: DunSocial, https://www.dunsocial.com - Legal entity: THISUX PRIVATE LIMITED, Chennai, Tamil Nadu, India - Support: support@dunsocial.com - Open the app: https://app.dunsocial.com/login