# Someone else's public posts > Markdown version of https://docs.postlake.dev/api/get-discover-profiles-by-handle-posts . The canonical page for humans. > PostLake is the social media API for AI agents: https://postlake.dev/llms.txt `GET /v1/discover/profiles/{handle}/posts` ## Request Authenticate with a bearer API key. Agents calling over MCP authorise with OAuth instead and never handle the key. ```bash curl -X GET https://api.postlake.dev/v1/discover/profiles/{handle}/posts \ -H "Authorization: Bearer $POSTLAKE_API_KEY" ``` ### Parameters | Field | Type | Required | What it is | | --- | --- | --- | --- | | `handle` | string | Yes | In the URL. | | `account` | string | Yes | Query string. | | `cursor` | string | No | Query string. | | `limit` | integer | No | Query string. 1-100 | ## Response Success (`200`). | Field | Type | Required | What it is | | --- | --- | --- | --- | | `items` | array | No | | | `cursor` | string | No | | | `problems` | array | No | | ### Example ```json { "items": [ "…" ], "cursor": "…", "problems": [ "…" ] } ``` ## Calling this from an agent Agents do not call REST. They call tools. Over the hosted MCP server this operation is `list_posts`, and the agent authorises with OAuth so your API key is never pasted into a chat or seen by the model. You control what any one agent may do: which brands it may act for, which networks it may reach, how much a day, and whether it may spend credits bought up front. ## Errors Every failure uses one shape: a stable `type`, a granular `code`, the field at fault in `param`, and a plain-language `fix`. See https://docs.postlake.dev/errors.md . Retries are safe: send the same `Idempotency-Key` and a call that already succeeded returns its original result rather than repeating it. ## Common questions **Can an AI agent do this without the REST API?** Yes. Over MCP the same job is the list_posts tool. The agent authorises with OAuth, so no API key is pasted into a chat or seen by the model, and the answer comes back in the same normalised shape. **How often can I call this?** Reads are rate limited per account and every response carries X-RateLimit-Remaining and X-RateLimit-Reset. On a 429 the Retry-After header tells you how long to wait. **What happens when it fails?** You get one error shape: a stable type, a granular code you can branch on, the offending field in param, and a fix written so an agent can correct itself rather than stop. Full list on Errors and retries. ## Related - [Find creators to work with](https://docs.postlake.dev/api/get-discover-creators.md) `GET /v1/discover/creators` - [Find a place to tag on a post](https://docs.postlake.dev/api/get-discover-places.md) `GET /v1/discover/places` - [Search public posts](https://docs.postlake.dev/api/get-discover-posts.md) `GET /v1/discover/posts` - [Look someone up](https://docs.postlake.dev/api/get-discover-profiles-by-handle.md) `GET /v1/discover/profiles/{handle}`