Provider API keys
Which platforms need a developer app, and how to configure them
Self-hosted only. This page describes configuration you do on your own Postiz instance. On Postiz Cloud it is already handled for you, so nothing here applies.
Postiz talks to each platform through that platform's own API, which usually means you have to register a developer app with them and give Postiz the resulting keys. This section covers that registration, one page per platform.
Looking for what a platform can actually carry, character limits, media rules and per-post settings? That is Posting rules by platform.
Ten platforms need no configuration at all
These providers take credentials that each user supplies in the Postiz dialog when they connect a channel. There is nothing for you to register and no environment variable to set. They are the quickest way to confirm a fresh install works.
| Platform | What the user provides |
|---|---|
| Bluesky | Service URL, handle, app password |
| Lemmy | Instance URL, username, password |
| Nostr | Private key |
| Medium | API key |
| Dev.to | API key |
| Hashnode | API key |
| WordPress | Site domain, username, application password |
| Listmonk | URL, username, password |
| Moltbook | Connects in-app, no credentials |
| Skool | Session cookies, via the browser extension |
Everything else needs a developer app
For the remaining platforms you register an app on the platform's developer portal, then set the keys as environment variables on your instance. Each page in this section walks through one platform.
Restart Postiz after changing environment variables. With Docker Compose,
run docker compose down then docker compose up -d. A plain restart won't
pick up a changed .env.
Variables prefixed NEXT_PUBLIC_ are baked into the frontend at build
time, so changing one needs a rebuild of the image, not just a restart.
These are your credentials with the platform, not Postiz credentials.
The keys on this page belong to a developer app you register with the platform. Nobody from Postiz will ever ask for them.
Keep them in your environment or a secret manager, never in a committed .env
file, and rotate them at the platform if they leak.
Redirect URIs
Every OAuth provider asks for a redirect URI. Postiz always uses the same shape:
{FRONTEND_URL}/integrations/social/{provider}So an instance at https://social.example.com connecting X uses
https://social.example.com/integrations/social/x. The provider identifier is
the one in the platform table, which is not always
the name you expect: Farcaster is wrapcast, Google My Business is gmb.
Keys that are shared between platforms
Three pairs of platforms share credentials, which trips people up:
- Instagram (Facebook Business) uses
FACEBOOK_APP_IDandFACEBOOK_APP_SECRET, the same app as Facebook Page. Only Instagram Standalone usesINSTAGRAM_APP_IDandINSTAGRAM_APP_SECRET. - LinkedIn Page uses the same
LINKEDIN_CLIENT_IDandLINKEDIN_CLIENT_SECRETas LinkedIn. - Google My Business falls back to the YouTube Google credentials if
GOOGLE_GMB_CLIENT_IDandGOOGLE_GMB_CLIENT_SECRETare not set.
Unconfigured platforms still appear in the list
Postiz shows every platform in the Add Channel dialog whether or not its keys are set. Clicking one you have not configured produces a failed connect rather than a helpful message, so if a platform will not connect on a fresh install, check its keys first.
Full variable list
Every provider variable, with defaults and notes, is in the Configuration reference.