# Validate a post (dry run) > Markdown version of https://docs.postlake.dev/api/post-posts-validate . The canonical page for humans. > PostLake is the social media API for AI agents: https://postlake.dev/llms.txt `POST /v1/posts/validate` Runs the exact validation a publish would run, covering account resolution, media resolution and capability-registry rules, without touching any platform. Returns per-target errors (blocking) and warnings (advisory). Free to call before POST /v1/posts. ## Request Authenticate with a bearer API key. Agents calling over MCP authorise with OAuth instead and never handle the key. ```bash curl -X POST https://api.postlake.dev/v1/posts/validate \ -H "Authorization: Bearer $POSTLAKE_API_KEY" \ -H "Content-Type: application/json" \ -d '{"text":"…","profile":"…","platforms":["…"],"accounts":["…"]}' ``` ### Body | Field | Type | Required | What it is | | --- | --- | --- | --- | | `text` | string | Yes | | | `profile` | string | No | A profile name. Resolves to every account it owns. The simple way to address accounts; combine with `platforms` to narrow it. Provide `profile`, `accounts`, or both. | | `platforms` | array | No | Optional filter. Keeps only these networks from the resolved set. | | `accounts` | array of string | No | Connected account ids (acc_…). An alternative (or addition) to `profile`. | | `media` | array of string | No | | | `scheduledAt` | string | No | | | `timezone` | string | No | IANA timezone (e.g. Europe/London). Interprets a naive scheduledAt as wall time in that zone. Stored fire time is always UTC. | | `platformOptions` | object | No | | ## Response Validation result (`200`). | Field | Type | Required | What it is | | --- | --- | --- | --- | | `ok` | boolean | Yes | | | `targets` | array of object | Yes | | ### Example ```json { "ok": false, "targets": [ { "account": "…", "platform": "…", "ok": "…", "errors": "…", "warnings": "…", "issues": "…" } ] } ``` ## Calling this from an agent Agents do not call REST. They call tools. Over the hosted MCP server this operation is `validate_post`, and the agent authorises with OAuth so your API key is never pasted into a chat or seen by the model. You control what any one agent may do: which brands it may act for, which networks it may reach, how much a day, and whether it may spend credits bought up front. ## Errors Every failure uses one shape: a stable `type`, a granular `code`, the field at fault in `param`, and a plain-language `fix`. See https://docs.postlake.dev/errors.md . Retries are safe: send the same `Idempotency-Key` and a call that already succeeded returns its original result rather than repeating it. ## Common questions **Can an AI agent do this without the REST API?** Yes. Over MCP the same job is the validate_post tool. The agent authorises with OAuth, so no API key is pasted into a chat or seen by the model, and the answer comes back in the same normalised shape. **Is it safe to retry this call?** Yes. Send the same Idempotency-Key and a call that already succeeded returns its original result instead of repeating the work. That is what makes it safe to hand to an agent that retries on its own. **What happens when it fails?** You get one error shape: a stable type, a granular code you can branch on, the offending field in param, and a fix written so an agent can correct itself rather than stop. Full list on Errors and retries. ## Related - [Cancel scheduled post](https://docs.postlake.dev/api/delete-posts-by-id.md) `DELETE /v1/posts/{id}` - [List posts](https://docs.postlake.dev/api/get-posts.md) `GET /v1/posts` - [Get post](https://docs.postlake.dev/api/get-posts-by-id.md) `GET /v1/posts/{id}` - [Edit scheduled post](https://docs.postlake.dev/api/patch-posts-by-id.md) `PATCH /v1/posts/{id}`