# What this key may do, and what it can spend > Markdown version of https://docs.postlake.dev/api/get-me-limits . The canonical page for humans. > PostLake is the social media API for AI agents: https://postlake.dev/llms.txt `GET /v1/me/limits` The account, the channels connected right now, and the credit balance with the plan's monthly allowance. Agents calling over MCP also get their own guardrails (allowed profiles and networks, daily cap, posts left today) through the whoami tool. Read this before planning a batch rather than discovering a limit by being refused. ## Request Authenticate with a bearer API key. Agents calling over MCP authorise with OAuth instead and never handle the key. ```bash curl -X GET https://api.postlake.dev/v1/me/limits \ -H "Authorization: Bearer $POSTLAKE_API_KEY" ``` ## Response Success (`200`). | Field | Type | Required | What it is | | --- | --- | --- | --- | | `account` | string | No | | | `email` | string | No | | | `name` | string | No | | | `credits` | object | No | | | `credits.total` | integer | No | | | `credits.monthly` | integer | No | | | `credits.pack` | integer | No | | | `credits.monthlyAllowance` | integer | No | | | `credits.plan` | string | No | | | `credits.blockedPlatforms` | array of string | No | | | `connected` | array of object | No | | ### Example ```json { "account": "…", "email": "…", "name": "…", "credits": { "total": 0, "monthly": 0, "pack": 0, "monthlyAllowance": 0, "plan": "…", "blockedPlatforms": [ "…" ] }, "connected": [ { "account": "…", "platform": "…", "handle": "…", "status": "…" } ] } ``` ## Calling this from an agent Agents do not call REST. They call tools. Over the hosted MCP server this operation is `whoami`, and the agent authorises with OAuth so your API key is never pasted into a chat or seen by the model. You control what any one agent may do: which brands it may act for, which networks it may reach, how much a day, and whether it may spend credits bought up front. ## Errors Every failure uses one shape: a stable `type`, a granular `code`, the field at fault in `param`, and a plain-language `fix`. See https://docs.postlake.dev/errors.md . Retries are safe: send the same `Idempotency-Key` and a call that already succeeded returns its original result rather than repeating it. ## Common questions **Can an AI agent do this without the REST API?** Yes. Over MCP the same job is the whoami tool. The agent authorises with OAuth, so no API key is pasted into a chat or seen by the model, and the answer comes back in the same normalised shape. **How often can I call this?** Reads are rate limited per account and every response carries X-RateLimit-Remaining and X-RateLimit-Reset. On a 429 the Retry-After header tells you how long to wait. **What happens when it fails?** You get one error shape: a stable type, a granular code you can branch on, the offending field in param, and a fix written so an agent can correct itself rather than stop. Full list on Errors and retries. ## Related - [Export account data](https://docs.postlake.dev/api/get-account-export.md) `GET /v1/account/export` - [Get audit log](https://docs.postlake.dev/api/get-audit.md) `GET /v1/audit` - [Read email preferences](https://docs.postlake.dev/api/get-email-preferences.md) `GET /v1/email-preferences` - [Get current account](https://docs.postlake.dev/api/get-me.md) `GET /v1/me`