API reference · Account

Export account data

GET /v1/account/export

GDPR data export. All data for the account (no secrets).

Request

Authenticate with a bearer API key. Agents calling over MCP authorise with OAuth instead and never handle the key.

curl -X GET https://api.postlake.dev/v1/account/export \
  -H "Authorization: Bearer $POSTLAKE_API_KEY"

Response

Success (200).

FieldTypeRequiredWhat it is
accountobjectYes
account.idstringYes
account.emailstringYes
profilesarrayYes
socialAccountsarrayYes
postsarrayYes
auditLogarrayYes
exportedAtstringYes

Example

{
  "account": {
    "id": "…",
    "email": "…"
  },
  "profiles": [
    "…"
  ],
  "socialAccounts": [
    "…"
  ],
  "posts": [
    "…"
  ],
  "auditLog": [
    "…"
  ],
  "exportedAt": "2026-08-16T07:00:00Z"
}

Limits

Reads are limited to 600 requests a minute per account. Every response carries X-RateLimit-Remaining and X-RateLimit-Reset, and a 429 includes Retry-After so a client can back off without guessing. Reads of network data (comments, followers, conversations) are metered in credits; reads of your own PostLake state are not.

Calling this from an agent

This operation is part of the REST surface. Agents working over the hosted MCP server reach the same product through tools instead, and authorise with OAuth so your API key is never pasted into a chat. See the MCP server.

Errors

Every failure uses one shape: a stable type, a granular code, the field at fault in param, and a plain-language fix. An agent can act on it without a person reading the message. See Errors and retries.

Retries are safe. Send the same Idempotency-Key and a call that already succeeded returns its original result rather than repeating it.

Common questions

How often can I call this?

Reads are rate limited per account and every response carries X-RateLimit-Remaining and X-RateLimit-Reset. On a 429 the Retry-After header tells you how long to wait.

What happens when it fails?

You get one error shape: a stable type, a granular code you can branch on, the offending field in param, and a fix written so an agent can correct itself rather than stop. Full list on Errors and retries.

Related