PawTalk Developers
Open PawTalk Sign in
DEVELOPER PORTAL

Build on PawTalk

Bots with their own identity, "Sign in with PawTalk" for your site, and signed events for your servers - over a plain HTTPS + JSON API.

What you can build

🤖

Bots

A bot is its own account with a protected BOT label. Server managers install it and approve exactly what it may do. It never acts as a person.

🔑

Sign in with PawTalk

OAuth2 code flow for your website or app. People see what you ask for and approve it; you get a token for just that.

📨

Event delivery

Get installs, removals and new messages pushed to your HTTPS endpoint, signed with your app's Ed25519 key so you can prove it came from us.

🔗

Server webhooks

Server managers can create a webhook URL that posts into one channel - build notices, alerts, feeds - with a clear WEBHOOK label.

Scopes

A token only reaches what its scopes allow - and a bot only reaches servers that installed it.

Bot token scopes

  • identity.readRead the bot identity.
  • servers.readRead servers where the bot is a member.
  • roles.readRead server roles for rank mapping.
  • members.readRead a server member’s assigned roles.
  • roles.writeAssign and remove roles below the bot’s highest role.
  • channels.readRead channels the bot can access.
  • messages.readRead message history in channels the bot can access.
  • messages.writePost messages where the server has allowed the bot to speak.

OAuth2 scopes (people signing in)

  • identifyRead the signed-in PawTalk identity.
  • emailRead the account email address.
  • servers.readRead servers the account belongs to.

Permissions a server can approve for a bot

View channels Read message history Send messages Add reactions Attach files Embed links Manage messages Pin messages Create invites Kick members Ban members Manage roles Manage emoji

Server managers see this list when installing and can approve less. A bot never gets more than the server approved, and it can only manage roles below its own highest role.

Events

Privileged: presence updates, server member events and message content are off by default. Turn them on in your bot's settings when a feature really needs them - without message content, message.created tells you a message happened, not what it said.

What we expose

  • Your bot's own identity
  • Servers that installed your bot, their channels and roles
  • Messages in channels the server lets your bot read
  • A member's roles (with members.read)
  • For OAuth2: the signed-in person's public profile, and their email only with the email scope
  • Signed events for what you subscribed to

What we never expose

  • Passwords, two-factor codes, sessions or sign-in devices
  • IP addresses
  • Direct messages and group chats between people
  • Private channels a server hasn't opened to your bot
  • Anything from servers that haven't installed your bot
  • Staff tools, moderation notes, reports or account standing
  • Someone's email without their consent

What kind of code we allow

✅

Any language

Anything that speaks HTTPS and JSON - Node, Python, PHP, C#, Go, Rust. Your code runs on your own server; nothing runs inside PawTalk.

✅

Bot and OAuth tokens

Use your bot token (ptk_…) or an OAuth2 token someone approved. Keep them on your server, never in a web page or app people can download.

❌

No self-bots

Automating a person's account with their login, session or password is not allowed. Bots are bots.

❌

No scraping or injection

No scraping, no scripts injected into the PawTalk app, no modified clients, and no collecting data a server didn't give you.

A first request

curl https://paw-talk.xyz/api/v1/me \
  -H "Authorization: Bearer ptk_your_token_here"

Then list servers with GET /servers, their channels with GET /servers/{id}/channels, and post with POST /channels/{id}/messages.

Ready to build?

Sign in with your PawTalk account, create an app, and give it a bot.

Sign in