The page owner creates an API key in /admin → Settings → AI agent access.
Guides / Overview
AI agent guideGetting started with the MyReach API
Connect an agent to a page with one owner-created key. Read and update that page using the same API the MyReach dashboard uses.
https://myreach.topStart with these steps
Store the key in a server-side secret. The key is shown once and can be revoked by its owner.
Send it as Authorization: Bearer mr_live_… with each request.
Start with GET /api/auth/whoami, then read /api/store before editing.
First connection
Verify the key and confirm its page scope. Never ask the page owner to paste a key into a public chat or browser form.
curl https://myreach.top/api/auth/whoami \ -H "Authorization: Bearer mr_live_YOUR_KEY"
Authentication model
Agent keys are scoped to one page. Owners use their signed-in dashboard session for account-level actions. An agent key cannot create, list, or revoke keys.
Authorization: Bearer mr_live_…Use for page-scoped agent endpoints.
mr_sessionUsed by the page owner in their signed-in browser.
Create and manage API keys
- Open the owner dashboard at
/admin. - Choose Settings, then AI agent access.
- Name the key so its purpose is clear, then generate and copy it.
- Revoke it from the same screen when no longer needed.
Accounts & sign-in
Owners sign in with a magic link or a configured provider. AgentID is the agent-native sign-in option. Use the API reference for account endpoints.
Requests & responses
Send JSON with Content-Type: application/json for writes. Successful requests return JSON. Errors include a clear error message and an HTTP status.
Errors
400invalid request or missing fields401missing, invalid, or revoked credentials404unknown page resource409conflicting or unavailable resource429request limit reached
Create a page
Page creation belongs to the owner. An agent can guide the owner through signup, then use a key after the owner grants page access.
Update page content
Read the current store, change only the requested fields, and send the updated JSON to the store endpoint. Preserve fields the owner did not ask you to change.
curl https://myreach.top/api/store \ -H "Authorization: Bearer mr_live_YOUR_KEY"
Security
- Keep keys in a server-side secret store.
- Never log full key values or include them in browser code.
- Use one key per agent or integration and revoke keys when access ends.
Limits
Write endpoints can be rate-limited. When a request returns 429, wait before retrying and avoid tight loops.