Security
We never ask foryour password.
Every account you connect goes through that platform's own OAuth screen. You approve a specific set of permissions, the platform hands us a token, and you can take it back whenever you want — from our side or theirs.
How a connection is made
- 1
You click connect
From the Accounts panel, pick the network you want to add. - 2
The platform asks you, not us
You land on the network's own authorisation page — their domain, their login, their consent screen listing exactly what is being granted. - 3
They hand us a scoped token
We receive an access token limited to the permissions you approved. Your password never touches our servers, and there is nothing in our database that could be used to log in as you. - 4
You can revoke it either way
Disconnect the account in SupaPush, or remove our app in the network's own security settings. Both immediately stop us being able to act.
What we ask for, and why
Permissions differ per network, but they fall into the same four groups. We request the narrowest set that makes the product work.
Read your profile
Publish on your behalf
Read and write comments
Read insights
What we do not do
Store passwords
Post without being asked
Share your tokens
If you use the API or an agent
API and MCP tokens are separate from your social connections. They authenticate to SupaPush, are scoped to one workspace, and can be revoked in Settings without touching the accounts themselves. Revoking a social connection, conversely, stops every route — dashboard, API and agent — from reaching that account.
Start posting from one calendar
Every plan includes a 7-day free trial. Connect real accounts, publish real posts, and stop whenever you like.
Get Started For Free