Authentication
Personal access tokens, scopes and workspace binding
Every request uses a personal access token (PAT) in the Authorization
header:
curl -H "Authorization: Bearer $VERBER_STUDIO_TOKEN" \
https://studio.verber.me/api/v1/meCreate a token
- In Studio, open Settings > Developer.
- Name the token, choose its scopes, optionally bind it to one workspace and set an expiry (30, 90 or 365 days, or none).
- Copy the token (
vst_…). It is shown once; Studio only keeps a hash.
Warning. Treat tokens like passwords. Store them in a secret manager or environment variable, never in source control. Revoke a leaked token in Settings > Developer; revocation is immediate.
Scopes
| Scope | Allows |
|---|---|
read | List and read workspaces, brand kit, products, campaigns, media, posts and credits (always included) |
write | Create and edit products, campaigns, the brand kit, draft posts and media uploads |
generate | Spend credits on AI image and copy generation |
publish | Schedule, queue and publish social posts |
Grant the smallest set that works. For AI agents, bind the token to one
workspace and leave out publish unless the agent should post on your behalf.
Workspace binding
A token bound to a workspace can only access that workspace. Workspace
endpoints still take the id in the path (/workspaces/{workspaceId}/…); MCP
tools default to the bound workspace when workspaceId is omitted.
Response format
Successful responses are { "data": …, "requestId": "…" }. Include the
requestId when you contact support. Errors are described in
Limits and errors.