Access Token
An access token is a credential an app sends with API requests to act on your behalf. It is issued through OAuth, limited to specific permissions and set to expire.
The expiring key an app uses to post or read on your behalf after you connect an account through OAuth.
Key Points
- ✓Access tokens are sent in the Authorization header as “Bearer <token>”
- ✓They carry specific permissions and expire; refresh tokens get new ones
- ✓LinkedIn access tokens are issued with a 60-day lifespan
- ✓An expired token is a common reason a scheduled post fails
An access token is a credential an app sends with API requests to act on your behalf. You get one through OAuth after you approve the app. It only allows what you approved, and it expires.
How access tokens are used
Most APIs expect the token in the Authorization header, written as Authorization: Bearer <token>. Anyone who holds a bearer token can use it, so it must be sent only over HTTPS and never shared. 1
Why tokens expire
Short lifetimes limit the damage if a token leaks. Many services also issue a refresh token, which the app uses to get a new access token without asking you again. LinkedIn currently issues access tokens with a 60-day lifespan and asks apps to refresh them before they expire. 2
Expired tokens and scheduled posts
If you schedule a post for next week and the account’s token expires before then, the post fails. Tokens also stop working when you change your password, remove the app or the network revokes access. A good scheduler warns you before this happens.
Access tokens in Publora
Publora stores the tokens for your connected accounts. The platform-connections endpoint of the Publora API reports a tokenStatus of valid, expiring_soon or expired for each account, with the time left, so an app or agent can ask you to reconnect before a scheduled post fails. 3
Publora and Access Token
The Publora API and MCP server publish and schedule posts to 10 networks from your own code or from AI assistants like Claude, ChatGPT and Cursor.
See the Publora API →Related Terms
- API Key
An API key is a secret string that identifies the app or person calling an API. It is sent with every request so the service knows who is asking.
- OAuth
OAuth is an open standard that lets you give an app limited access to your account on another service without sharing your password.
- OAuth for Agents
OAuth for Agents is an authorization framework enabling AI-powered marketing tools to securely access social media platforms using tokens instead of passwords, allowing automated posting, analytics, and campaign management.
- Publishing API
A programmatic interface that enables automated creation, uploading, and scheduling of content across social media platforms without manual intervention.
- Social Media Scheduler
A software tool that enables users to plan, create, and automatically publish content across multiple social media platforms at predetermined times, eliminating the need for manual posting.