Security

We never ask foryour password.

Every account you connect goes through that platform's own OAuth screen. You approve a specific set of permissions, the platform hands us a token, and you can take it back whenever you want — from our side or theirs.

How a connection is made

  1. 1

    You click connect

    From the Accounts panel, pick the network you want to add.
  2. 2

    The platform asks you, not us

    You land on the network's own authorisation page — their domain, their login, their consent screen listing exactly what is being granted.
  3. 3

    They hand us a scoped token

    We receive an access token limited to the permissions you approved. Your password never touches our servers, and there is nothing in our database that could be used to log in as you.
  4. 4

    You can revoke it either way

    Disconnect the account in SupaPush, or remove our app in the network's own security settings. Both immediately stop us being able to act.

What we ask for, and why

Permissions differ per network, but they fall into the same four groups. We request the narrowest set that makes the product work.

Read your profile

To show which account is connected, and to display the right avatar and handle in the dashboard.

Publish on your behalf

The core of the product — creating the post at the moment you scheduled it.

Read and write comments

For the unified inbox: listing comments on your posts, replying, and hiding spam.

Read insights

Reach, engagement and follower figures. Read-only, and only for accounts you connected.

What we do not do

Store passwords

There is no field for one. OAuth exists precisely so that a third party never needs your credentials.

Post without being asked

Nothing publishes that you or someone in your workspace did not schedule, queue or approve.

Share your tokens

Tokens are encrypted at rest, scoped to your workspace, and never exposed through the API or MCP surface.

If you use the API or an agent

API and MCP tokens are separate from your social connections. They authenticate to SupaPush, are scoped to one workspace, and can be revoked in Settings without touching the accounts themselves. Revoking a social connection, conversely, stops every route — dashboard, API and agent — from reaching that account.

Start posting from one calendar

Every plan includes a 7-day free trial. Connect real accounts, publish real posts, and stop whenever you like.

Get Started For Free