Know the connected accounts
Which social accounts the account holds, as identity only (never a token), each with the connectionId every post and queue call takes.
Connecting one is the platform's own sign-in, so a person has to click: the agent mints a one-time link for the platform and hands it over, and a post or job that needs an account it does not hold answers with that link. Track a handle by name without connecting it, sort accounts into groups, and read TikTok's creator info before each TikTok post, as TikTok requires. The rail's rules per platform, the limits it enforces before a post goes out, and who the credential belongs to (plan and credit balance) live beside it.
Ask in plain words
- "which accounts are connected"
- "give me a link to connect my TikTok"
- "how long can an X post be"
- "which plan am I on and how much credit is left"
From an agent host (MCP)
Server: https://shapelessai.com/mcp (add it to your host).
connections_list: Connected social accounts (identity only, no tokens), plusconnect: one clickable link per platform with no live account, andreconnecton an expired one. Hand the link to the human. Needs the read scope.connections_link: The one URL the human clicks to connect a social account on a platform (connections_list already carries one per missing platform). Lasts 15 minutes, works only signed in as this account; the platform's own OAuth follows in the browser, then the account shows in connections_list. Needs the write scope.platforms_list: Every platform the rail posts to: text limit, media rules, whether documentTitle is required, first-comment support, and the JSON Schema for its settings. Read it before posts_create. Works with any key (read scope or none).me: Who this credential belongs to: email, plan, credit balance. Needs the read scope.
From code (REST)
Bearer API key with the scope each call names (auth, OpenAPI).
GET /api/connections(read scope): Connected social accounts (identity only, never tokens).DELETE /api/connections(publish scope): Disconnect an account (?id=). Ends our ability to publish there, so it costs publish.POST /api/connections/link(write scope): The one URL the human opens to connect a social account: {platform}. Lasts 15 minutes, works only signed in as this account; the platform's own OAuth follows.PATCH /api/connections/{id}(write scope): Move an account into a group: {groupId} or null for ungrouped.GET /api/connections/{id}/tiktok-creator-info(read scope): TikTok's creator info for that connection: privacy levels, limits. Read it before every TikTok post; TikTok forbids caching it.POST /api/connections/tracked(write scope): Track an account by handle, no OAuth, never a publish target: {platform, handle, followers?}.GET /api/groups(read scope): Account groups.POST /api/groups(write scope): Create a group: {name, color?}.PATCH /api/groups(write scope): Reorder groups: {orderedIds}.PATCH /api/groups/{id}(write scope): Rename or recolor a group.DELETE /api/groups/{id}(write scope): Delete a group; its accounts become ungrouped.GET /api/platforms(no key): Every platform the rail posts to: limits, media rules, settings schema, first-comment support.GET /api/me(read scope): Who am I: account, plan, credit balance.
From a terminal (CLI)
shapeless connectionsshapeless platformsshapeless whoamishapeless loginshapeless logout
Example
Refusals
| Status | Meaning |
|---|---|
| 400 | Not a platform with oauth: true. |
