Onlymonster API
Base URLs
Production:
https://omapi.onlymonster.ai
Rate limits
Token limit: 25 requests per second across all endpoints.
Endpoint limit: 15 requests per second per endpoint (default). Some endpoints override this — see the description on each endpoint.
Platform account limit: 1 request per second per platform account on selected endpoint groups — endpoints that apply it say so in their description.
Exceeding either limit returns
429 Rate limit exceeded.
API key permissions
Each API key carries the permissions chosen when it was created. A request to an endpoint the key is not permitted to call returns 403 with code: API_KEY_PERMISSION_DENIED and the missing permission in details.required_permission.
Permissions are independent of the key's account access: a request needs both. Keys created before permissions were introduced hold every permission. Each endpoint's description names its required permission.
accounts.view—GET /api/v0/accounts,GET /api/v0/accounts/{account_id}dashboard.view—GET …/transactions,GET …/chargebacksteam_metrics.view—GET /api/v0/users/metrics,GET /api/v0/memberstraffic_metrics.view—GET …/tracking-links,GET …/tracking-link-users,GET …/trial-links,GET …/trial-link-users,GET …/subscriptionsonlyfans.messages—GET /api/v0/accounts/{account_id}/fans,GET/POST …/chats/{chat_id}/messages,PATCH …/fans/{fan_id}onlyfans.collections—POST …/fans/{fan_id}/subscribeonlyfans.statements—GET /proxy/v0/…/statements/balances,GET/POST /proxy/v0/…/statements/payout-requestsauto_messages.view—GET …/auto-message-campaigns,GET …/auto-message-campaigns/{campaign_id}auto_messages.edit—POST …/auto-message-campaigns,PATCH …/auto-message-campaigns/{campaign_id}/status,POST …/auto-message-campaigns/{campaign_id}/unsendmedia_uploader.manage— All…/vault/…endpoints: folders, medias, thumbnails and media uploadssettings.view— Account session export (enabled per organisation)
Rate limit: 15 requests per second
Required permission: accounts.view
API token for authentication
Default Response
The API key lacks the permission this endpoint requires, or the request is outside what the organisation or the API key can access.
GET /api/v0/accounts HTTP/1.1
Host: omapi.onlymonster.ai
x-om-auth-token: YOUR_API_KEY
Accept: */*
{
"accounts": [
{
"id": 1,
"platform_account_id": "1",
"platform": "text",
"name": "text",
"email": "text",
"avatar": "text",
"username": "text",
"organisation_id": "1",
"subscribe_price": 1,
"subscription_expiration_date": "2026-01-01T00:00:00.000Z",
"custom_label": null
}
],
"nextCursor": "text"
}Rate limit: 1 request per second
A created broadcast is a real broadcast to its whole audience, not a draft. Without a schedule it is queued and goes out without further action; with one it waits for the hour it names. Use the status endpoint to pause it.
This endpoint is not idempotent, and a repeated create is a second broadcast to every fan it matches. A request that times out, or that answers 500 or 502, may still have created one: whether it exists is unknown, so list the account broadcasts before retrying and pause a duplicate at once. Listing the broadcasts needs priority_mass_messages.view in addition to priority_mass_messages.edit.
A schedule and an end are each a wall-clock date and whole hour plus the clock it is read on. An offset carried by the value is ignored. A schedule in the past goes out at once, an end before the schedule is accepted, and a broadcast whose end passes completes as sent whatever state it was in.
A broadcast reads its schedule back as the UTC instant plus the zone name, not as the wall clock it was stated on, and reads it back as null once it has been dispatched.
audience_filters[].options.lists[].name is required on every fan list and never published back: the reads carry identifiers alone.
Revoking or narrowing the key that created a broadcast does not stop it. Pause it through the status endpoint instead.
Required permission: priority_mass_messages.edit
API token for authentication
OnlyMonster account whose broadcasts are read.
12345Pattern: ^(0|[1-9]\d*)$Broadcast name. Required when the broadcast sends more than one message, and when its only message carries media but no text. A single text message sent without a name reads back with that text as its name.
\SWall-clock date and whole hour at which the broadcast goes out, read on the clock scheduled_at_timezone_mode names. An offset carried by the value is ignored, so the hour written is the hour used — the value is not moved to the instant an offset would name. Required together with scheduled_at_timezone_mode. A schedule in the past is accepted and goes out at once. Omit both to send as soon as the broadcast is queued.
One Priority Mass Messages broadcast of the account.
One Priority Mass Messages broadcast of the account.
Broadcast identifier.
4312Pattern: ^(0|[1-9]\d*)$OnlyMonster account the broadcast belongs to.
12345Pattern: ^(0|[1-9]\d*)$Broadcast name as the account owner set it. For a single-message broadcast created without a name, the text of that message, as the panel shows it. Null for a broadcast created without a name whose content could not be read.
State of the broadcast, as the panel shows it. Null for a broadcast holding a state this API does not name, which no broadcast created through it can reach.
Why the broadcast is paused: manual when a person paused it, send_errors when too many sends failed. Null when it is not paused.
How far the broadcast has got through its audience, from 0 to 100.
When the broadcast was created (ISO 8601 Zulu).
When the broadcast is due to go out (ISO 8601 Zulu). Null once it has been dispatched, and null for one that was never scheduled; a broadcast paused before its schedule came due keeps it.
IANA zone name the schedule was stated in, so a client can show it the way the panel does. Null whenever scheduled_at is null.
Europe/BerlinFans the broadcast resolved to. 0 until it has been prepared, and unaffected by what was delivered afterwards.
The request states something this endpoint cannot accept: a value outside its bounds, an audience no broadcast can be built from, a message whose price and paywall disagree, half a schedule pair, a time that is not a whole hour, or a fan list that does not exist. A refusal this endpoint decides itself carries no code.
The token is missing or invalid.
The API key lacks the permission this endpoint requires, or the request is outside what the organisation or the API key can access.
The token or per-endpoint rate limit was exceeded.
The request failed for a reason this API does not describe. The broadcast may still have been created: list the account broadcasts before retrying.
The broadcast could not be created or confirmed. Whether it exists is unknown — list the account broadcasts before retrying, and pause a duplicate at once.
POST /api/v0/accounts/{account_id}/priority-mass-message-campaigns HTTP/1.1
Host: omapi.onlymonster.ai
x-om-auth-token: YOUR_API_KEY
Content-Type: application/json
Accept: */*
Content-Length: 658
{
"name": null,
"scheduled_at": "2026-01-01T00:00:00.000Z",
"scheduled_at_timezone_mode": "utc",
"rules": {
"online_check_mode": "off",
"unsend_delay_sec": 3600,
"unsend_if_not_read_enabled": true,
"mimic_on_reply_enabled": true,
"end_at": "2026-01-01T00:00:00.000Z",
"end_at_timezone_mode": "utc"
},
"audience_filters": [
{
"kind": "subscribed_date",
"mode": "include",
"options": {
"from_at": "2026-01-01T00:00:00.000Z",
"to_at": "2026-01-01T00:00:00.000Z",
"from_days": 1,
"to_days": 1
}
}
],
"messages": [
{
"text": null,
"price_gross": 0,
"delay_sec": 1,
"attachments": [
{
"id": "text",
"type": "image",
"is_paid": true
}
],
"text_is_paid": true,
"tagged_platform_account_ids": [
"1"
]
}
],
"ANY_ADDITIONAL_PROPERTY": null
}{
"id": "4312",
"account_id": "12345",
"name": "text",
"status": null,
"pause_reason": null,
"progress_percent": 1,
"created_by": {
"type": "user",
"id": "42"
},
"created_at": "2026-01-01T00:00:00.000Z",
"scheduled_at": "2026-01-01T00:00:00.000Z",
"scheduled_at_timezone": "Europe/Berlin",
"rules": {
"online_check_mode": null,
"unsend_delay_sec": 1,
"unsend_if_not_read_enabled": true,
"unsend_if_not_replied_enabled": true,
"mimic_on_reply_enabled": true,
"end_at": "2026-01-01T00:00:00.000Z",
"end_at_timezone": "Europe/Berlin"
},
"audience_filters": [
{
"kind": "subscribed_date",
"mode": "include",
"options": {
"from_at": "2026-01-01T00:00:00.000Z",
"to_at": "2026-01-01T00:00:00.000Z"
}
}
],
"messages": [
{
"step": 0,
"text": "text",
"price_gross": 9.99,
"delay_sec": 1,
"attachments": [
{
"id": "1289402",
"type": "image",
"is_paid": true
}
],
"text_is_paid": true,
"tagged_platform_account_ids": [
"67890"
]
}
],
"targeted_recipients_count": 1,
"stats": {
"sent_messages_count": 1,
"unsent_messages_count": 1,
"replied_messages_count": 1,
"purchased_messages_count": 1,
"purchased_amount_gross": 1,
"reply_rate": 1,
"purchase_rate": 1
}
}Rate limit: 5 requests per second
The broadcast stops sending and the messages it delivered are taken back out of the fans' chats, as far as the platform's 24-hour recall window allows. A recall is possible within 24 hours of the broadcast's last status change.
This cannot be undone and it is not limited to broadcasts this API created. Any broadcast of the account can be recalled, including one a person built in the panel.
A 502 does not promise the broadcast is untouched, but no repeat recalls twice, so repeating the request is safe; read the broadcast if the answer stays 502. This differs from the Auto Messages recall, whose 502 asks the caller to read the campaign before repeating at all. Reading the broadcast needs priority_mass_messages.view in addition to priority_mass_messages.edit.
Required permission: priority_mass_messages.edit
API token for authentication
OnlyMonster account the broadcast belongs to.
12345Pattern: ^(0|[1-9]\d*)$Broadcast identifier.
4312Pattern: ^(0|[1-9]\d*)$The recall was applied: the broadcast stops sending and takes back what it can.
No content
The broadcast is not in a state a recall can start from: the wrong state, a paused broadcast that never started sending, or one whose last status change is more than 24 hours old. One code covers every cause; read the broadcast to tell which.
The token is missing or invalid.
The API key lacks the permission this endpoint requires, or the request is outside what the organisation or the API key can access.
The broadcast does not exist for this account.
The token or per-endpoint rate limit was exceeded.
The request failed for a reason this API does not describe. Repeating it is safe.
The recall did not complete. No broadcast is recalled twice by a repeat, so repeating the request is safe; read the broadcast if the answer stays 502. This differs from the Auto Messages recall, whose 502 asks the caller to read the campaign before repeating at all.
POST /api/v0/accounts/{account_id}/priority-mass-message-campaigns/{campaign_id}/unsend HTTP/1.1
Host: omapi.onlymonster.ai
x-om-auth-token: YOUR_API_KEY
Accept: */*
No content
Rate limit: 5 requests per second
A schedule reads back as null once the broadcast has been dispatched; a broadcast paused before its schedule came due keeps it.
Sent, unsent and purchased figures, and the purchased amount, count the first message of the broadcast only; replies are counted across every step. Because of that a sequence can report more replies than sends, and its reply_rate then reads null rather than a figure above 1.
A broadcast whose content could not be read is listed with messages: [] and every figure at zero, rather than failing the page.
Required permission: priority_mass_messages.view
API token for authentication
OnlyMonster account whose broadcasts are read.
12345Pattern: ^(0|[1-9]\d*)$Items per page (min: 1, max: 100, default: 50).
50Items to skip (default: 0).
0Include archived broadcasts in the page (default: false). Only archived is affected — every other state is always listed.
falseA page of the account Priority Mass Messages broadcasts, newest first.
A page of the account Priority Mass Messages broadcasts, newest first.
True when more broadcasts exist beyond this page.
The token is missing or invalid.
The API key lacks the permission this endpoint requires, or the request is outside what the organisation or the API key can access.
The token or per-endpoint rate limit was exceeded.
The request failed for a reason this API does not describe. Repeating it is safe.
The content of this page could not be read at all. The broadcasts exist and are unchanged, and repeating the request is safe. A single broadcast whose content is gone does not cause this — it is listed with messages: [] and its figures at zero instead.
GET /api/v0/accounts/{account_id}/priority-mass-message-campaigns HTTP/1.1
Host: omapi.onlymonster.ai
x-om-auth-token: YOUR_API_KEY
Accept: */*
{
"items": [
{
"id": "4312",
"account_id": "12345",
"name": "text",
"status": null,
"pause_reason": null,
"progress_percent": 1,
"created_by": {
"type": "user",
"id": "42"
},
"created_at": "2026-01-01T00:00:00.000Z",
"scheduled_at": "2026-01-01T00:00:00.000Z",
"scheduled_at_timezone": "Europe/Berlin",
"rules": {
"online_check_mode": null,
"unsend_delay_sec": 1,
"unsend_if_not_read_enabled": true,
"unsend_if_not_replied_enabled": true,
"mimic_on_reply_enabled": true,
"end_at": "2026-01-01T00:00:00.000Z",
"end_at_timezone": "Europe/Berlin"
},
"audience_filters": [
{
"kind": "subscribed_date",
"mode": "include",
"options": {
"from_at": "2026-01-01T00:00:00.000Z",
"to_at": "2026-01-01T00:00:00.000Z"
}
}
],
"messages": [
{
"step": 0,
"text": "text",
"price_gross": 9.99,
"delay_sec": 1,
"attachments": [
{
"id": "1289402",
"type": "image",
"is_paid": true
}
],
"text_is_paid": true,
"tagged_platform_account_ids": [
"67890"
]
}
],
"targeted_recipients_count": 1,
"stats": {
"sent_messages_count": 1,
"unsent_messages_count": 1,
"replied_messages_count": 1,
"purchased_messages_count": 1,
"purchased_amount_gross": 1,
"reply_rate": 1,
"purchase_rate": 1
}
}
],
"has_more": true
}Rate limit: 5 requests per second
A schedule reads back as null once the broadcast has been dispatched; a broadcast paused before its schedule came due keeps it.
Sent, unsent and purchased figures, and the purchased amount, count the first message of the broadcast only; replies are counted across every step. Because of that a sequence can report more replies than sends, and its reply_rate then reads null rather than a figure above 1.
A broadcast whose content could not be read is refused with 502 here, because that content is exactly what was asked for.
Required permission: priority_mass_messages.view
API token for authentication
OnlyMonster account the broadcast belongs to.
12345Pattern: ^(0|[1-9]\d*)$Broadcast identifier.
4312Pattern: ^(0|[1-9]\d*)$One Priority Mass Messages broadcast of the account.
One Priority Mass Messages broadcast of the account.
Broadcast identifier.
4312Pattern: ^(0|[1-9]\d*)$OnlyMonster account the broadcast belongs to.
12345Pattern: ^(0|[1-9]\d*)$Broadcast name as the account owner set it. For a single-message broadcast created without a name, the text of that message, as the panel shows it. Null for a broadcast created without a name whose content could not be read.
State of the broadcast, as the panel shows it. Null for a broadcast holding a state this API does not name, which no broadcast created through it can reach.
Why the broadcast is paused: manual when a person paused it, send_errors when too many sends failed. Null when it is not paused.
How far the broadcast has got through its audience, from 0 to 100.
When the broadcast was created (ISO 8601 Zulu).
When the broadcast is due to go out (ISO 8601 Zulu). Null once it has been dispatched, and null for one that was never scheduled; a broadcast paused before its schedule came due keeps it.
IANA zone name the schedule was stated in, so a client can show it the way the panel does. Null whenever scheduled_at is null.
Europe/BerlinFans the broadcast resolved to. 0 until it has been prepared, and unaffected by what was delivered afterwards.
The token is missing or invalid.
The API key lacks the permission this endpoint requires, or the request is outside what the organisation or the API key can access.
The broadcast does not exist for this account.
The token or per-endpoint rate limit was exceeded.
The request failed for a reason this API does not describe. Repeating it is safe.
This broadcast exists and is unchanged; only its content could not be read, and here it is exactly what was asked for. Repeating the request is safe. A temporary failure to read the content passes on a later repeat; content missing for good answers the same on every repeat.
GET /api/v0/accounts/{account_id}/priority-mass-message-campaigns/{campaign_id} HTTP/1.1
Host: omapi.onlymonster.ai
x-om-auth-token: YOUR_API_KEY
Accept: */*
{
"id": "4312",
"account_id": "12345",
"name": "text",
"status": null,
"pause_reason": null,
"progress_percent": 1,
"created_by": {
"type": "user",
"id": "42"
},
"created_at": "2026-01-01T00:00:00.000Z",
"scheduled_at": "2026-01-01T00:00:00.000Z",
"scheduled_at_timezone": "Europe/Berlin",
"rules": {
"online_check_mode": null,
"unsend_delay_sec": 1,
"unsend_if_not_read_enabled": true,
"unsend_if_not_replied_enabled": true,
"mimic_on_reply_enabled": true,
"end_at": "2026-01-01T00:00:00.000Z",
"end_at_timezone": "Europe/Berlin"
},
"audience_filters": [
{
"kind": "subscribed_date",
"mode": "include",
"options": {
"from_at": "2026-01-01T00:00:00.000Z",
"to_at": "2026-01-01T00:00:00.000Z"
}
}
],
"messages": [
{
"step": 0,
"text": "text",
"price_gross": 9.99,
"delay_sec": 1,
"attachments": [
{
"id": "1289402",
"type": "image",
"is_paid": true
}
],
"text_is_paid": true,
"tagged_platform_account_ids": [
"67890"
]
}
],
"targeted_recipients_count": 1,
"stats": {
"sent_messages_count": 1,
"unsent_messages_count": 1,
"replied_messages_count": 1,
"purchased_messages_count": 1,
"purchased_amount_gross": 1,
"reply_rate": 1,
"purchase_rate": 1
}
}Rate limit: 5 requests per second
The answer says which state the broadcast holds now, which is not always the one asked for: resuming a broadcast paused before its schedule came due answers scheduled, because it keeps that schedule.
A paused broadcast can be resumed for five days; after a further period it is archived automatically and can no longer be resumed. There is no manual archive.
Asking for a state the broadcast already holds is accepted and changes nothing. A change that fails for a reason that is not about the request answers a plain 502 with no code.
Required permission: priority_mass_messages.edit
API token for authentication
OnlyMonster account the broadcast belongs to.
12345Pattern: ^(0|[1-9]\d*)$Broadcast identifier.
4312Pattern: ^(0|[1-9]\d*)$State to move the broadcast to.
paused — the broadcast stops sending. Accepted from scheduled, queued and sending; pausing a paused broadcast changes nothing.
queued — the broadcast resumes. Accepted for a paused broadcast within the resume window, and for one already queued, which changes nothing.
The state the broadcast holds now. A resume answers queued, or scheduled when the broadcast was paused before its schedule came due and keeps it.
The state the broadcast holds now. A resume answers queued, or scheduled when the broadcast was paused before its schedule came due and keeps it.
The requested state is not one of the two, or the broadcast is in a state the change does not start from. One code covers both causes of a refused resume — a state a resume does not start from, and a broadcast paused longer than the resume window — and the message says which applied.
The token is missing or invalid.
The API key lacks the permission this endpoint requires, or the request is outside what the organisation or the API key can access.
The broadcast does not exist for this account.
The token or per-endpoint rate limit was exceeded.
The request failed for a reason this API does not describe. Repeating it is safe.
The change did not complete, for a reason that is not about the request. Read the broadcast to learn the state it holds before repeating.
PATCH /api/v0/accounts/{account_id}/priority-mass-message-campaigns/{campaign_id}/status HTTP/1.1
Host: omapi.onlymonster.ai
x-om-auth-token: YOUR_API_KEY
Content-Type: application/json
Accept: */*
Content-Length: 19
{
"status": "paused"
}{
"status": "paused"
}Rate limit: 15 requests per second
Required permission: accounts.view
API token for authentication
Big integer id as string
{"value":"1"}Pattern: ^(0|[1-9]\d*)$Default Response
The API key lacks the permission this endpoint requires, or the request is outside what the organisation or the API key can access.
GET /api/v0/accounts/{account_id} HTTP/1.1
Host: omapi.onlymonster.ai
x-om-auth-token: YOUR_API_KEY
Accept: */*
{
"account": {
"id": 1,
"platform_account_id": "1",
"platform": "text",
"name": "text",
"email": "text",
"avatar": "text",
"username": "text",
"organisation_id": "1",
"subscribe_price": 1,
"subscription_expiration_date": "2026-01-01T00:00:00.000Z",
"custom_label": null
}
}Rate limit: 15 requests per second
Required permission: traffic_metrics.view
API token for authentication
Name of the platform. Currently, only "onlyfans" is supported.
Big integer id as string
1Pattern: ^(0|[1-9]\d*)$Start of the subscription timestamp range (ISO 8601 Zulu).
2025-10-01T00:00:00.000ZEnd of the subscription timestamp range (ISO 8601 Zulu).
2025-10-31T23:59:59.999ZItems per page (min: 10, max: 1000, default: 100).
100Example: 100Pagination cursor returned from the previous request.
Default Response
Base64-encoded cursor for paginating subsequent results. Present only if additional pages exist.
The API key lacks the permission this endpoint requires, or the request is outside what the organisation or the API key can access.
GET /api/v0/platforms/{platform}/accounts/{platform_account_id}/subscriptions?start=2026-01-01T00%3A00%3A00.000Z&end=2026-01-01T00%3A00%3A00.000Z HTTP/1.1
Host: omapi.onlymonster.ai
x-om-auth-token: YOUR_API_KEY
Accept: */*
{
"items": [
{
"fan": {
"id": "1"
},
"price_gross": 1,
"regular_price_gross": 1,
"action": "text",
"type": "text",
"subscribed_at": "2026-01-01T00:00:00.000Z",
"expires_at": "2026-01-01T00:00:00.000Z"
}
],
"cursor": ""
}Rate limit: 1 request per second
Required permission: onlyfans.messages
API token for authentication
Big integer id as string
{"value":"1"}Pattern: ^(0|[1-9]\d*)$10000Default Response
The API key lacks the permission this endpoint requires, or the request is outside what the organisation or the API key can access.
GET /api/v0/accounts/{account_id}/fans HTTP/1.1
Host: omapi.onlymonster.ai
x-om-auth-token: YOUR_API_KEY
Accept: */*
{
"fan_ids": [
"text"
]
}Rate limit: 1 request per second per platform account (shared "proxy" group).
Required permission: onlyfans.statements
API token for authentication
Name of the platform. Currently, only "onlyfans" is supported.
Unique account identifier returned by the OnlyFans platform.
000000000Big integer id as string
1Pattern: ^(0|[1-9]\d*)$Default Response
Balance available for withdrawal. Balances accumulate creator earnings after the OnlyFans platform fee.
28.46Earnings not yet matured for withdrawal (see manualPayoutPendingDays).
416.38ISO 4217 currency code; all monetary values in this response are in major units.
USDMinimum available balance required to request a payout.
20Maximum amount withdrawable at this moment.
28.46Number of days a manual payout stays pending before it becomes available.
7Currently selected withdrawal period code.
manualThe API key lacks the permission this endpoint requires, or the request is outside what the organisation or the API key can access.
The account's OnlyFans session is disconnected or deauthorized. Reconnect the account in OnlyMonster and retry.
GET /proxy/v0/platforms/{platform}/accounts/{platform_account_id}/statements/balances HTTP/1.1
Host: omapi.onlymonster.ai
x-om-auth-token: YOUR_API_KEY
Accept: */*
{
"payoutAvailable": 28.46,
"payoutPending": 416.38,
"currency": "USD",
"minPayoutSumm": 20,
"maxPayoutSumm": 28.46,
"withdrawalPeriodOptions": [
{
"code": "manual",
"name": "text"
}
],
"manualPayoutPendingDays": 7,
"withdrawalPeriod": "manual"
}Rate limit: 1 request per second per platform account (shared "proxy" group).
Required permission: onlyfans.statements
API token for authentication
Name of the platform. Currently, only "onlyfans" is supported.
Unique account identifier returned by the OnlyFans platform.
000000000Big integer id as string
1Pattern: ^(0|[1-9]\d*)$Items per page (min: 1, max: 100, default: 10).
10Example: 10Number of items to skip.
0Example: 0Snapshot marker returned by a previous response. Pass it back to keep pagination consistent while new payout requests arrive; omit to paginate the live list with plain offsets.
1783602843Default Response
Snapshot marker for consistent pagination. Pass it as the "marker" query parameter of the next page request.
1783602843The API key lacks the permission this endpoint requires, or the request is outside what the organisation or the API key can access.
The account's OnlyFans session is disconnected or deauthorized. Reconnect the account in OnlyMonster and retry.
GET /proxy/v0/platforms/{platform}/accounts/{platform_account_id}/statements/payout-requests HTTP/1.1
Host: omapi.onlymonster.ai
x-om-auth-token: YOUR_API_KEY
Accept: */*
{
"list": [
{
"invoiceId": "78266704",
"createdAt": "2025-10-05T20:44:34+00:00",
"amount": 1,
"currency": "USD",
"state": "approved",
"rejectReason": "text"
}
],
"marker": 1783602843
}Requests a withdrawal of the given amount from the account's available balance.
This action is irreversible: OnlyFans does not support idempotency for this request. Do not blindly retry on timeout — first check the payout requests list to see whether the request was created.
Rate limit: 1 request per second per platform account (shared "proxy" group).
This endpoint is in gradual rollout: it is enabled per organization, and organizations without access receive 403 Forbidden.
Required permission: onlyfans.statements
API token for authentication
Name of the platform. Currently, only "onlyfans" is supported.
Unique account identifier returned by the OnlyFans platform.
000000000Big integer id as string
1Pattern: ^(0|[1-9]\d*)$Amount to withdraw in USD major units, up to 2 decimal places. Must not exceed the available balance (see the balances endpoint).
20Default Response
Either an OnlyFans rejection returned as-is (the "error" object), or an om-api validation error ("message" + "code") — never both.
The API key lacks the permission this endpoint requires, or the request is outside what the organisation or the API key can access.
The account's OnlyFans session is disconnected or deauthorized. Reconnect the account in OnlyMonster and retry.
The payout audit trail could not be recorded, so the request was never sent to OnlyFans. Retrying is safe.
POST /proxy/v0/platforms/{platform}/accounts/{platform_account_id}/statements/payout-requests HTTP/1.1
Host: omapi.onlymonster.ai
x-om-auth-token: YOUR_API_KEY
Content-Type: application/json
Accept: */*
Content-Length: 24
{
"withdrawal_amount": 20
}{
"list": [
{
"state": "new",
"rejectReason": "text"
}
]
}Rate limit: 1 request per second
Required permission: onlyfans.messages
API token for authentication
Big integer id as string
{"value":"1"}Pattern: ^(0|[1-9]\d*)$100ID of the last message from previous page. Used for pagination
{"value":"asc"}Default Response
true if more messages are available beyond the returned page
The API key lacks the permission this endpoint requires, or the request is outside what the organisation or the API key can access.
GET /api/v0/accounts/{account_id}/chats/{chat_id}/messages HTTP/1.1
Host: omapi.onlymonster.ai
x-om-auth-token: YOUR_API_KEY
Accept: */*
{
"items": [
{
"id": 1,
"text": "text",
"from_user": 1,
"is_sent_by_me": true,
"created_at": "text",
"media": [
{
"id": 1,
"type": "text",
"can_view": true,
"is_ready": true,
"has_error": true,
"converted_to_video": true,
"created_at": "text",
"thumbnail_url": "text"
}
],
"media_count": 1,
"is_opened": true,
"is_new": true,
"price": 1,
"is_free": true,
"can_purchase": true,
"can_purchase_reason": "text",
"sender": {
"type": null,
"user_id": null
}
}
],
"has_more": true
}Rate limit: 1 request per second
The message text is scanned by the content-moderation service before being enqueued. Requests whose text matches restricted words or topics return 400 with code: "RESTRICTED_WORDS_DETECTED" and the matching words / topics in details.
Required permission: onlyfans.messages
API token for authentication
Big integer id as string
{"value":"1"}Pattern: ^(0|[1-9]\d*)$Default Response
Unique identifier for tracking this send by webhook
Default Response
The API key lacks the permission this endpoint requires, or the request is outside what the organisation or the API key can access.
POST /api/v0/accounts/{account_id}/chats/{chat_id}/messages HTTP/1.1
Host: omapi.onlymonster.ai
x-om-auth-token: YOUR_API_KEY
Content-Type: application/json
Accept: */*
Content-Length: 97
{
"text": null,
"price": 0,
"locked_text": false,
"media": [
{
"id": "text",
"type": "image",
"is_paid": true
}
]
}{
"send_id": "123e4567-e89b-12d3-a456-426614174000"
}Sets the custom name and the note the account owner keeps for a fan.
Both are private to the account owner: they are never shown to the fan and are not the fan's profile name on the platform.
Rate limit: 1 request per second
Required permission: onlyfans.messages
API token for authentication
Big integer id as string
{"value":"1"}Pattern: ^(0|[1-9]\d*)$Big integer id as string
{"value":"1"}Pattern: ^(0|[1-9]\d*)$At least one field must be present. Fields left out keep their current value.
Default Response
The API key lacks the permission this endpoint requires, or the request is outside what the organisation or the API key can access.
No fan with the given fan_id exists for this account on the platform.
The account's OnlyFans session is disconnected or deauthorized. Reconnect the account in OnlyMonster and retry.
PATCH /api/v0/accounts/{account_id}/fans/{fan_id} HTTP/1.1
Host: omapi.onlymonster.ai
x-om-auth-token: YOUR_API_KEY
Content-Type: application/json
Accept: */*
Content-Length: 61
{
"custom_name": "VIP Whale",
"note": "Prefers morning messages"
}{
"success": true
}Makes the account follow the fan on the platform and returns the resulting subscription. Subscribing to a fan the account already follows is not an error: the existing subscription is returned unchanged.
Rate limit: 1 request per second
Required permission: onlyfans.collections
API token for authentication
Big integer id as string
{"value":"1"}Pattern: ^(0|[1-9]\d*)$Big integer id as string
{"value":"1"}Pattern: ^(0|[1-9]\d*)$Default Response
Whether the account is subscribed to the fan.
Start of the account's subscription to the fan.
2026-09-11T09:31:50+00:00End of the account's subscription to the fan. Null when it has no end date.
2036-09-11T09:31:50+00:00Whether the subscription renews automatically.
Price of the subscription, paid by the account, in USD. 0 or null means free.
0The platform refused the subscription or the request failed validation.
The API key lacks the permission this endpoint requires, or the request is outside what the organisation or the API key can access.
No fan with the given fan_id exists for this account on the platform.
The account's OnlyFans session is disconnected or deauthorized. Reconnect the account in OnlyMonster and retry.
POST /api/v0/accounts/{account_id}/fans/{fan_id}/subscribe HTTP/1.1
Host: omapi.onlymonster.ai
x-om-auth-token: YOUR_API_KEY
Accept: */*
{
"fan": {
"id": "1"
},
"subscribed": true,
"subscribed_at": "2026-09-11T09:31:50+00:00",
"expires_at": "2036-09-11T09:31:50+00:00",
"auto_renew_enabled": null,
"price_gross": 0
}Rate limit: 15 requests per second
Required permission: traffic_metrics.view
API token for authentication
Name of the platform. Currently, only "onlyfans" is supported.
onlyfansPossible values: Unique account identifier returned by the OnlyFans platform.
000000000Start of the tracking link creation timestamp range (ISO 8601 Zulu).
2025-10-01T00:00:00.000ZEnd of the tracking link creation timestamp range (ISO 8601 Zulu).
2025-10-31T23:59:59.999ZItems per page (min:10 max:1000 default:100)
100base64-signed string
List of tracking links successfully retrieved for the specified platform account.
Base64-encoded cursor used for paginating subsequent results. Present only if additional pages exist.
dHN4The API key lacks the permission this endpoint requires, or the request is outside what the organisation or the API key can access.
GET /api/v0/platforms/{platform}/accounts/{platform_account_id}/tracking-links?start=2025-10-01T00%3A00%3A00.000Z&end=2025-10-31T23%3A59%3A59.999Z HTTP/1.1
Host: omapi.onlymonster.ai
x-om-auth-token: YOUR_API_KEY
Accept: */*
{
"items": [
{
"id": "1040071",
"name": "Tracking Link 1",
"subscribers": 939,
"url": "https://onlyfans.com/some-name/c16",
"is_active": true,
"clicks": 49166,
"created_at": "2024-06-16T20:47:37.000Z"
},
{
"id": "940779",
"name": "Tracking Link 2",
"subscribers": 1213,
"url": "https://onlyfans.com/some-name/c15",
"is_active": true,
"clicks": 75512,
"created_at": "2024-05-07T19:20:16.000Z"
}
],
"cursor": "dHN4"
}Rate limit: 15 requests per second
Required permission: traffic_metrics.view
API token for authentication
Name of the platform. Currently, only "onlyfans" is supported.
onlyfansPossible values: Unique account identifier returned by the OnlyFans platform.
000000000Start of the collection timestamp range (ISO 8601 Zulu).
2025-10-01T00:00:00.000ZEnd of the collection timestamp range (ISO 8601 Zulu).
2026-10-31T23:59:59.999ZItems per page (min:1 max:750 default:100)
100base64-signed string
Filter results by a specific tracking link ID.
123List of tracking link users successfully retrieved for the specified platform account.
Base64-encoded cursor used for paginating subsequent results. Present only if additional pages exist.
dHN4The API key lacks the permission this endpoint requires, or the request is outside what the organisation or the API key can access.
GET /api/v0/platforms/{platform}/accounts/{platform_account_id}/tracking-link-users HTTP/1.1
Host: omapi.onlymonster.ai
x-om-auth-token: YOUR_API_KEY
Accept: */*
{
"items": [
{
"link_id": "1000001",
"fan": {
"id": "123456789",
"name": "John Doe",
"username": "johndoe"
},
"subscribed_at": "2025-10-15T10:30:00.000Z",
"collected_at": "2025-10-15T11:00:00.000Z"
}
],
"cursor": "dHN4"
}Rate limit: 15 requests per second
Required permission: traffic_metrics.view
API token for authentication
Name of the platform. Currently, only "onlyfans" is supported.
onlyfansPossible values: Unique account identifier returned by the OnlyFans platform.
000000000Start of the trial link creation timestamp range (ISO 8601 Zulu).
2025-10-01T00:00:00.000ZEnd of the trial link creation timestamp range (ISO 8601 Zulu).
2025-10-31T23:59:59.999ZItems per page (min:10 max:1000 default:100)
100base64-signed string
List of trial links successfully retrieved for the specified platform account.
Base64-encoded cursor used for paginating subsequent results. Present only if additional pages exist.
dHN4The API key lacks the permission this endpoint requires, or the request is outside what the organisation or the API key can access.
GET /api/v0/platforms/{platform}/accounts/{platform_account_id}/trial-links?start=2025-10-01T00%3A00%3A00.000Z&end=2025-10-31T23%3A59%3A59.999Z HTTP/1.1
Host: omapi.onlymonster.ai
x-om-auth-token: YOUR_API_KEY
Accept: */*
{
"items": [
{
"id": "10668344",
"name": "Trial Link 1",
"claims": 18,
"claims_limit": 0,
"url": "https://onlyfans.com/some-name/trial/bwmsqiakh3p1mvgec1gfutz6r26tbmav",
"duration_days": 3,
"expires_at": null,
"is_active": true,
"clicks": 20,
"created_at": "2025-10-06T14:16:01.000Z"
},
{
"id": "10611345",
"name": "Trial Link 2",
"claims": 0,
"claims_limit": 0,
"url": "https://onlyfans.com/some-name/trial/ndzgpob7tptoqargxapzpbgrxv0u8s6f",
"duration_days": 3,
"expires_at": null,
"is_active": true,
"clicks": 0,
"created_at": "2025-09-19T21:03:38.000Z"
}
],
"cursor": "dHN4"
}Rate limit: 15 requests per second
Required permission: traffic_metrics.view
API token for authentication
Name of the platform. Currently, only "onlyfans" is supported.
onlyfansPossible values: Unique account identifier returned by the OnlyFans platform.
000000000Start of the collected_at timestamp range filter (ISO 8601 Zulu).
2025-10-01T00:00:00.000ZEnd of the collected_at timestamp range filter (ISO 8601 Zulu).
2025-10-31T23:59:59.999ZItems per page (min:1 max:750 default:100)
100base64-signed string
Filter results to a specific trial link ID.
10668344List of trial link users successfully retrieved for the specified platform account.
Base64-encoded cursor for paginating subsequent results. Present only if additional pages exist.
dHN4The API key lacks the permission this endpoint requires, or the request is outside what the organisation or the API key can access.
GET /api/v0/platforms/{platform}/accounts/{platform_account_id}/trial-link-users HTTP/1.1
Host: omapi.onlymonster.ai
x-om-auth-token: YOUR_API_KEY
Accept: */*
{
"items": [
{
"link_id": "text",
"fan": {
"id": "text",
"name": "text",
"username": "text"
},
"subscribed_at": "2026-01-01T00:00:00.000Z",
"collected_at": "2026-01-01T00:00:00.000Z"
}
],
"cursor": "dHN4"
}Rate limit: 15 requests per second
Required permission: dashboard.view
API token for authentication
Name of the platform. Currently, only "onlyfans" is supported.
onlyfansPossible values: Unique account identifier returned by the OnlyFans platform.
000000000Start of the chargeback creation timestamp range (ISO 8601 Zulu).
2025-10-01T00:00:00.000ZEnd of the chargeback creation timestamp range (ISO 8601 Zulu).
2025-10-31T23:59:59.999ZItems per page (min:10 max:1000 default:100)
100base64-signed string
List of chargebacks successfully retrieved for the specified platform account.
Base64-encoded cursor used for paginating subsequent results. Present only if additional pages exist.
dHN4The API key lacks the permission this endpoint requires, or the request is outside what the organisation or the API key can access.
GET /api/v0/platforms/{platform}/accounts/{platform_account_id}/chargebacks?start=2025-10-01T00%3A00%3A00.000Z&end=2025-10-31T23%3A59%3A59.999Z HTTP/1.1
Host: omapi.onlymonster.ai
x-om-auth-token: YOUR_API_KEY
Accept: */*
{
"items": [
{
"id": "feab0694bd16cf2c83b372cede7fbe0b",
"amount": 1,
"fan": {
"id": "000000000"
},
"type": "Tip from",
"status": "undo",
"chargeback_timestamp": "2025-08-05T14:50:07.000Z",
"transaction_timestamp": "2025-08-05T12:01:42.000Z"
},
{
"id": "3760ed0c1770ff18a663b3123acfab31",
"amount": 16,
"fan": {
"id": "000000000"
},
"type": "Payment for message",
"status": "undo",
"chargeback_timestamp": "2025-07-31T09:05:13.000Z",
"transaction_timestamp": "2025-07-28T04:02:27.000Z"
}
],
"cursor": "dHN4"
}Rate limit: 15 requests per second
Required permission: dashboard.view
API token for authentication
Name of the platform. Supported values: "onlyfans", "fansly".
onlyfansPossible values: Big integer id as string
1Pattern: ^(0|[1-9]\d*)$Start of the transaction timestamp range (ISO 8601 Zulu).
2025-10-01T00:00:00.000ZEnd of the transaction timestamp range (ISO 8601 Zulu).
2025-10-31T23:59:59.999ZItems per page (min: 10, max: 1000, default: 100).
100Pagination cursor returned from the previous request.
Default Response
Base64-encoded cursor for paginating subsequent results. Present only if additional pages exist.
The request is invalid: the cursor is malformed or does not belong to this platform, a query parameter is out of range, or the platform is not served by this route. OnlyFans requests also return the rejection stats-service raised for them.
The API key lacks the permission this endpoint requires, or the request is outside what the organisation or the API key can access.
The token or per-endpoint rate limit was exceeded.
The statistics upstream failed, was unreachable, or rejected a request built by the API. Retry later.
The statistics upstream did not answer within the timeout. Retry later or narrow the window.
GET /api/v0/platforms/{platform}/accounts/{platform_account_id}/transactions?start=2026-01-01T00%3A00%3A00.000Z&end=2026-01-01T00%3A00%3A00.000Z HTTP/1.1
Host: omapi.onlymonster.ai
x-om-auth-token: YOUR_API_KEY
Accept: */*
{
"items": [
{
"id": "text",
"amount": 1,
"fan": {
"id": "1"
},
"type": "text",
"status": "text",
"timestamp": "2026-01-01T00:00:00.000Z"
}
],
"cursor": ""
}Rate limit: 15 requests per second
Required permission: team_metrics.view
API token for authentication
Start of the metrics timestamp range (ISO 8601 Zulu).
2025-10-01T00:00:00.000ZEnd of the metrics timestamp range (ISO 8601 Zulu).
2025-10-31T23:59:59.999ZArray of creator IDs to filter metrics by.
Array of user IDs to filter metrics by.
Account group ID to filter metrics by.
Role ID to filter metrics by.
Offset for pagination.
0Limit for pagination (max 100).
100User metrics successfully retrieved.
The API key lacks the permission this endpoint requires, or the request is outside what the organisation or the API key can access.
GET /api/v0/users/metrics?from=2025-10-01T00%3A00%3A00.000Z&to=2025-10-31T23%3A59%3A59.999Z&offset=0&limit=100 HTTP/1.1
Host: omapi.onlymonster.ai
x-om-auth-token: YOUR_API_KEY
Accept: */*
{
"items": [
{
"user_id": 123,
"creator_ids": [
456,
789
],
"fans_count": 150,
"messages_count": 320,
"template_messages_count": 50,
"ai_generated_messages_count": 30,
"copied_messages_count": 10,
"media_messages_count": 100,
"paid_messages_count": 25,
"free_media_messages_count": 80,
"paid_messages_price_sum": 500.5,
"words_count_sum": 5000,
"typed_messages_count": 200,
"unsent_messages_count": 5,
"purchase_interval_avg": 3600,
"reply_time_avg": 120,
"posts_count": 45,
"deleted_posts_count": 2,
"work_time": 28800,
"break_time": 3600,
"sold_messages_count": 20,
"sold_messages_price_sum": 400,
"total_sold_messages_count": 50,
"total_sold_messages_price_sum": 1000,
"purchase_interval_min": 300,
"purchase_interval_max": 7200,
"sold_posts_count": 10,
"sold_posts_price_sum": 200,
"total_sold_posts_count": 25,
"tips_amount_sum": 150,
"total_tips_amount_sum": 300,
"chargedback_tips_amount_sum": 10,
"chargedback_posts_price_sum": 20,
"chargedback_posts_count": 1,
"chargedback_messages_price_sum": 15,
"chargedback_messages_count": 1,
"total_chargedback_tips_amount_sum": 25,
"total_chargedback_posts_price_sum": 40,
"total_chargedback_posts_count": 2,
"total_chargedback_messages_price_sum": 30,
"total_chargedback_messages_count": 2,
"internal_templates_count": 15
}
]
}Rate limit: 15 requests per second
Required permission: team_metrics.view
API token for authentication
Number of members to return (min: 1, max: 50).
20Number of members to skip for pagination.
0List of organisation members successfully retrieved.
The API key lacks the permission this endpoint requires, or the request is outside what the organisation or the API key can access.
GET /api/v0/members?limit=20&offset=0 HTTP/1.1
Host: omapi.onlymonster.ai
x-om-auth-token: YOUR_API_KEY
Accept: */*
{
"users": [
{
"id": 1,
"avatar": "https://example.com/avatar.jpg",
"name": "Alice Johnson",
"email": "alice@example.com",
"createdAt": "2025-01-15T09:00:00Z",
"customName": "text"
}
]
}Rate limit: 5 requests per second
Required permission: media_uploader.manage
API token for authentication
Big integer id as string
{"value":"1"}Pattern: ^(0|[1-9]\d*)$100Default Response
The API key lacks the permission this endpoint requires, or the request is outside what the organisation or the API key can access.
GET /api/v0/accounts/{account_id}/vault/folders HTTP/1.1
Host: omapi.onlymonster.ai
x-om-auth-token: YOUR_API_KEY
Accept: */*
{
"items": [
{
"id": 1,
"type": "text",
"name": "text",
"has_media": true,
"can_update": true,
"can_delete": true,
"videos_count": 1,
"photos_count": 1,
"gifs_count": 1,
"audios_count": 1
}
]
}Rate limit: 5 requests per second
Required permission: media_uploader.manage
API token for authentication
Big integer id as string
{"value":"1"}Pattern: ^(0|[1-9]\d*)$^[0-9]+$100allPossible values: Default Response
The API key lacks the permission this endpoint requires, or the request is outside what the organisation or the API key can access.
GET /api/v0/accounts/{account_id}/vault/folders/{folder_id}/medias HTTP/1.1
Host: omapi.onlymonster.ai
x-om-auth-token: YOUR_API_KEY
Accept: */*
{
"items": [
{
"id": 1,
"type": "text",
"can_view": true,
"is_ready": true,
"has_error": true,
"converted_to_video": true,
"created_at": "text",
"thumbnail_url": "text"
}
]
}Rate limit: 3 requests per second
Required permission: media_uploader.manage
API token for authentication
Big integer id as string
{"value":"1"}Pattern: ^(0|[1-9]\d*)$Default Response
The API key lacks the permission this endpoint requires, or the request is outside what the organisation or the API key can access.
GET /api/v0/accounts/{account_id}/vault/media/{media_id}/thumbnail HTTP/1.1
Host: omapi.onlymonster.ai
x-om-auth-token: YOUR_API_KEY
Accept: */*
binaryRate limit: 3 requests per second
Required permission: media_uploader.manage
API token for authentication
Big integer id as string
{"value":"1"}Pattern: ^(0|[1-9]\d*)$100Default Response
The API key lacks the permission this endpoint requires, or the request is outside what the organisation or the API key can access.
GET /api/v0/accounts/{account_id}/vault/medias/uploads HTTP/1.1
Host: omapi.onlymonster.ai
x-om-auth-token: YOUR_API_KEY
Accept: */*
{
"items": [
{
"id": "text",
"status": "uploaded",
"media_id": "text",
"metadata": {
"name": "text",
"size": 1,
"content_type": "text",
"duration": 1,
"key": "text",
"e_tag": "text",
"get_url": "text",
"export_type": "text",
"export_fan_id": "text",
"rf_guest": [
"text"
],
"rf_partner": [
"text"
],
"rf_tag": [
"text"
]
},
"created_at": "text",
"updated_at": "text"
}
],
"total": 1
}Rate limit: 3 requests per second
Required permission: media_uploader.manage
API token for authentication
Big integer id as string
{"value":"1"}Pattern: ^(0|[1-9]\d*)$^[\w. \-()]{1,255}$^(image|video|audio)/[a-zA-Z0-9.+-]+$Default Response
The API key lacks the permission this endpoint requires, or the request is outside what the organisation or the API key can access.
POST /api/v0/accounts/{account_id}/vault/medias/uploads/start HTTP/1.1
Host: omapi.onlymonster.ai
x-om-auth-token: YOUR_API_KEY
Content-Type: application/json
Accept: */*
Content-Length: 59
{
"name": "text",
"size": 1,
"content_type": "text",
"duration": 1
}{
"get_url": "text",
"put_url": "text",
"key": "text"
}Rate limit: 3 requests per second
Required permission: media_uploader.manage
API token for authentication
Big integer id as string
{"value":"1"}Pattern: ^(0|[1-9]\d*)$Default Response
The API key lacks the permission this endpoint requires, or the request is outside what the organisation or the API key can access.
POST /api/v0/accounts/{account_id}/vault/medias/uploads/finish HTTP/1.1
Host: omapi.onlymonster.ai
x-om-auth-token: YOUR_API_KEY
Content-Type: application/json
Accept: */*
Content-Length: 69
{
"key": "text",
"upload_id": "text",
"parts": [
{
"part": 1,
"e_tag": "text"
}
]
}{
"e_tag": "text"
}Rate limit: 3 requests per second
Required permission: media_uploader.manage
API token for authentication
Big integer id as string
{"value":"1"}Pattern: ^(0|[1-9]\d*)$^[\w. \-()]{1,255}$^(image|video|audio)/[a-zA-Z0-9.+-]+$Big integer id as string
1Big integer id as string
1Big integer id as string
1Default Response
The API key lacks the permission this endpoint requires, or the request is outside what the organisation or the API key can access.
POST /api/v0/accounts/{account_id}/vault/medias/uploads/export HTTP/1.1
Host: omapi.onlymonster.ai
x-om-auth-token: YOUR_API_KEY
Content-Type: application/json
Accept: */*
Content-Length: 214
{
"name": "text",
"size": 1,
"content_type": "text",
"duration": 1,
"key": "text",
"e_tag": "text",
"get_url": "https://example.com",
"export_type": "post",
"export_fan_id": "text",
"rf_guest": [
"1"
],
"rf_partner": [
"1"
],
"rf_tag": [
"1"
]
}{
"id": "text",
"status": "uploaded",
"media_id": "text",
"metadata": {
"name": "text",
"size": 1,
"content_type": "text",
"duration": 1,
"key": "text",
"e_tag": "text",
"get_url": "text",
"export_type": "text",
"export_fan_id": "text",
"rf_guest": [
"text"
],
"rf_partner": [
"text"
],
"rf_tag": [
"text"
]
},
"created_at": "text",
"updated_at": "text"
}Rate limit: 3 requests per second
Required permission: media_uploader.manage
API token for authentication
Big integer id as string
{"value":"1"}Pattern: ^(0|[1-9]\d*)$Default Response
The API key lacks the permission this endpoint requires, or the request is outside what the organisation or the API key can access.
POST /api/v0/accounts/{account_id}/vault/medias/uploads/{upload_id}/retry HTTP/1.1
Host: omapi.onlymonster.ai
x-om-auth-token: YOUR_API_KEY
Accept: */*
{
"id": "text",
"status": "uploaded",
"media_id": "text",
"metadata": {
"name": "text",
"size": 1,
"content_type": "text",
"duration": 1,
"key": "text",
"e_tag": "text",
"get_url": "text",
"export_type": "text",
"export_fan_id": "text",
"rf_guest": [
"text"
],
"rf_partner": [
"text"
],
"rf_tag": [
"text"
]
},
"created_at": "text",
"updated_at": "text"
}Rate limit: 3 requests per second
Required permission: media_uploader.manage
API token for authentication
Big integer id as string
{"value":"1"}Pattern: ^(0|[1-9]\d*)$^https?://(www\.)?onlyfans\.com/Default Response
The API key lacks the permission this endpoint requires, or the request is outside what the organisation or the API key can access.
POST /api/v0/accounts/{account_id}/vault/medias/uploads/fans/verify HTTP/1.1
Host: omapi.onlymonster.ai
x-om-auth-token: YOUR_API_KEY
Content-Type: application/json
Accept: */*
Content-Length: 19
{
"fan_link": "text"
}{
"fan_id": "text"
}Rate limit: 5 requests per second
Required permission: auto_messages.view
API token for authentication
OnlyMonster account whose campaigns are read.
12345Pattern: ^(0|[1-9]\d*)$Items per page (min: 1, max: 100, default: 50).
50Items to skip (default: 0).
0Include archived campaigns in the page (default: false). Only archived is affected — paused, unsending and unsent campaigns are always returned.
falseA page of the account Auto Messages campaigns.
A page of the account Auto Messages campaigns.
True when more campaigns exist beyond this page.
The API key lacks the permission this endpoint requires, or the request is outside what the organisation or the API key can access.
The campaigns exist and are unchanged; only their content could not be read. Repeating the request is safe.
GET /api/v0/accounts/{account_id}/auto-message-campaigns HTTP/1.1
Host: omapi.onlymonster.ai
x-om-auth-token: YOUR_API_KEY
Accept: */*
{
"items": [
{
"id": "4312",
"account_id": "12345",
"name": "text",
"trigger": "welcome_message",
"action": "send_message",
"status": "active",
"created_by": {
"type": "user",
"id": "42"
},
"created_at": "2026-01-01T00:00:00.000Z",
"rules": {
"send_delay_interval": {
"min_sec": 1,
"range_sec": 1
},
"send_after_expire_min": 1,
"send_before_expire_min": 1,
"unsend_delay_sec": 1,
"unsend_if_not_read_enabled": true,
"unsend_if_not_replied_enabled": true,
"retry_after_unsend_min": 1,
"end_at": "2026-01-01T00:00:00.000Z",
"mimic_on_reply_enabled": true
},
"audience_filters": [
{
"kind": "purchased_from_organisation",
"mode": "include",
"options": {
"from_at": "2026-01-01T00:00:00.000Z",
"to_at": "2026-01-01T00:00:00.000Z"
}
}
],
"messages": [
{
"step": 0,
"text": "text",
"price_gross": 9.99,
"delay_sec": 1,
"attachments": [
{
"id": "1289402",
"type": "image",
"is_paid": true
}
],
"text_is_paid": true,
"tagged_platform_account_ids": [
"67890"
]
}
],
"targeted_sends_count": 1,
"first_message_stats": {
"sent_messages_count": 1,
"unsent_messages_count": 1,
"replied_messages_count": 1,
"purchased_messages_count": 1,
"purchased_amount_gross": 1,
"reply_rate": 1,
"purchase_rate": 1
},
"follow_up_message_stats": [
{
"step": 1,
"sent_messages_count": 1,
"unsent_messages_count": 1,
"replied_messages_count": 1,
"purchased_messages_count": 1,
"purchased_amount_gross": 1,
"reply_rate": 1,
"purchase_rate": 1
}
]
}
],
"has_more": true
}Rate limit: 5 requests per second
The campaign starts running as soon as it is created: it begins matching fans the moment this request is answered. There is no way to stage one — use the status endpoint to pause it.
An empty audience_filters targets every fan that fires the trigger. Campaigns here are trigger-driven and send one message per fan event, so this is the ordinary shape of a welcome campaign rather than a broadcast.
audience_filters[].options.lists[].name is accepted and never published back: a name is required for each fan list, while the read endpoints carry identifiers alone.
This endpoint is not idempotent. A request that times out may still have created a running campaign. Before retrying, list the account campaigns and look for one already there; a duplicate can be stopped with the status endpoint. Listing the campaigns needs auto_messages.view in addition to auto_messages.edit.
Required permission: auto_messages.edit
API token for authentication
OnlyMonster account whose campaigns are read.
12345Pattern: ^(0|[1-9]\d*)$Campaign name. Required for a sequence and for a message that carries media but no text.
\SOne Auto Messages campaign of the account.
One Auto Messages campaign of the account.
Campaign identifier.
4312Pattern: ^(0|[1-9]\d*)$OnlyMonster account the campaign belongs to.
12345Pattern: ^(0|[1-9]\d*)$Campaign name as the account owner set it. Null when the campaign has none.
What the campaign does when the trigger fires.
send_message — sends the messages listed in messages.
start_mimic — opens a Mimic chat instead of sending; such a campaign has no messages.
Null when this version of the API does not name the action. Such a campaign reports no
messages either, since what its content means depends on what it does with it.
send_messagePossible values: When the campaign was created (ISO 8601 Zulu).
Dispatches the campaign has made since it was created. Cumulative: a fan targeted twice counts twice, and the figure never decreases.
The request states something this endpoint cannot accept: a value outside its bounds, a schedule member belonging to another trigger, content on a campaign that sends none, or a fan list that does not exist.
The API key lacks the permission this endpoint requires, or the request is outside what the organisation or the API key can access.
The campaign could not be created or confirmed. Whether the campaign was created is unknown — list the account campaigns before retrying.
POST /api/v0/accounts/{account_id}/auto-message-campaigns HTTP/1.1
Host: omapi.onlymonster.ai
x-om-auth-token: YOUR_API_KEY
Content-Type: application/json
Accept: */*
Content-Length: 713
{
"trigger": "welcome_message",
"action": "send_message",
"name": null,
"rules": {
"send_delay_interval": {
"min_sec": 60,
"range_sec": 120
},
"send_after_expire_min": 1440,
"send_before_expire_min": 1440,
"unsend_delay_sec": 1,
"unsend_if_not_read_enabled": true,
"unsend_if_not_replied_enabled": true,
"retry_after_unsend_min": 1440,
"end_at": null,
"mimic_on_reply_enabled": true
},
"audience_filters": [
{
"kind": "purchased_from_organisation",
"mode": "include",
"options": {
"from_at": "2026-01-01T00:00:00.000Z",
"to_at": "2026-01-01T00:00:00.000Z",
"from_days": 1,
"to_days": 1
}
}
],
"messages": [
{
"text": null,
"price_gross": 0,
"delay_sec": 1,
"attachments": [
{
"id": "text",
"type": "image",
"is_paid": true
}
],
"text_is_paid": true,
"tagged_platform_account_ids": [
"1"
]
}
]
}{
"id": "4312",
"account_id": "12345",
"name": "text",
"trigger": "welcome_message",
"action": "send_message",
"status": "active",
"created_by": {
"type": "user",
"id": "42"
},
"created_at": "2026-01-01T00:00:00.000Z",
"rules": {
"send_delay_interval": {
"min_sec": 1,
"range_sec": 1
},
"send_after_expire_min": 1,
"send_before_expire_min": 1,
"unsend_delay_sec": 1,
"unsend_if_not_read_enabled": true,
"unsend_if_not_replied_enabled": true,
"retry_after_unsend_min": 1,
"end_at": "2026-01-01T00:00:00.000Z",
"mimic_on_reply_enabled": true
},
"audience_filters": [
{
"kind": "purchased_from_organisation",
"mode": "include",
"options": {
"from_at": "2026-01-01T00:00:00.000Z",
"to_at": "2026-01-01T00:00:00.000Z"
}
}
],
"messages": [
{
"step": 0,
"text": "text",
"price_gross": 9.99,
"delay_sec": 1,
"attachments": [
{
"id": "1289402",
"type": "image",
"is_paid": true
}
],
"text_is_paid": true,
"tagged_platform_account_ids": [
"67890"
]
}
],
"targeted_sends_count": 1,
"first_message_stats": {
"sent_messages_count": 1,
"unsent_messages_count": 1,
"replied_messages_count": 1,
"purchased_messages_count": 1,
"purchased_amount_gross": 1,
"reply_rate": 1,
"purchase_rate": 1
},
"follow_up_message_stats": [
{
"step": 1,
"sent_messages_count": 1,
"unsent_messages_count": 1,
"replied_messages_count": 1,
"purchased_messages_count": 1,
"purchased_amount_gross": 1,
"reply_rate": 1,
"purchase_rate": 1
}
]
}Rate limit: 5 requests per second
Required permission: auto_messages.view
API token for authentication
OnlyMonster account the campaign belongs to.
12345Pattern: ^(0|[1-9]\d*)$Campaign identifier.
4312Pattern: ^(0|[1-9]\d*)$One Auto Messages campaign of the account.
One Auto Messages campaign of the account.
Campaign identifier.
4312Pattern: ^(0|[1-9]\d*)$OnlyMonster account the campaign belongs to.
12345Pattern: ^(0|[1-9]\d*)$Campaign name as the account owner set it. Null when the campaign has none.
What the campaign does when the trigger fires.
send_message — sends the messages listed in messages.
start_mimic — opens a Mimic chat instead of sending; such a campaign has no messages.
Null when this version of the API does not name the action. Such a campaign reports no
messages either, since what its content means depends on what it does with it.
send_messagePossible values: When the campaign was created (ISO 8601 Zulu).
Dispatches the campaign has made since it was created. Cumulative: a fan targeted twice counts twice, and the figure never decreases.
The API key lacks the permission this endpoint requires, or the request is outside what the organisation or the API key can access.
The campaign does not exist for this account.
The campaign exists and is unchanged; only its content could not be read. Repeating the request is safe but may not help: the content can be missing for good, and then every repeat answers the same.
GET /api/v0/accounts/{account_id}/auto-message-campaigns/{campaign_id} HTTP/1.1
Host: omapi.onlymonster.ai
x-om-auth-token: YOUR_API_KEY
Accept: */*
{
"id": "4312",
"account_id": "12345",
"name": "text",
"trigger": "welcome_message",
"action": "send_message",
"status": "active",
"created_by": {
"type": "user",
"id": "42"
},
"created_at": "2026-01-01T00:00:00.000Z",
"rules": {
"send_delay_interval": {
"min_sec": 1,
"range_sec": 1
},
"send_after_expire_min": 1,
"send_before_expire_min": 1,
"unsend_delay_sec": 1,
"unsend_if_not_read_enabled": true,
"unsend_if_not_replied_enabled": true,
"retry_after_unsend_min": 1,
"end_at": "2026-01-01T00:00:00.000Z",
"mimic_on_reply_enabled": true
},
"audience_filters": [
{
"kind": "purchased_from_organisation",
"mode": "include",
"options": {
"from_at": "2026-01-01T00:00:00.000Z",
"to_at": "2026-01-01T00:00:00.000Z"
}
}
],
"messages": [
{
"step": 0,
"text": "text",
"price_gross": 9.99,
"delay_sec": 1,
"attachments": [
{
"id": "1289402",
"type": "image",
"is_paid": true
}
],
"text_is_paid": true,
"tagged_platform_account_ids": [
"67890"
]
}
],
"targeted_sends_count": 1,
"first_message_stats": {
"sent_messages_count": 1,
"unsent_messages_count": 1,
"replied_messages_count": 1,
"purchased_messages_count": 1,
"purchased_amount_gross": 1,
"reply_rate": 1,
"purchase_rate": 1
},
"follow_up_message_stats": [
{
"step": 1,
"sent_messages_count": 1,
"unsent_messages_count": 1,
"replied_messages_count": 1,
"purchased_messages_count": 1,
"purchased_amount_gross": 1,
"reply_rate": 1,
"purchase_rate": 1
}
]
}Rate limit: 5 requests per second
Asking for the state the campaign is already in is accepted and does not change the campaign, but it is not free: the change is carried out again, which is how a change that did not complete is retried. If the answer is 502, repeat the same request to complete the change; after a 204 there is nothing to repeat. Every request, a repeat included, counts toward the rate limit.
Required permission: auto_messages.edit
API token for authentication
OnlyMonster account the campaign belongs to.
12345Pattern: ^(0|[1-9]\d*)$Campaign identifier.
4312Pattern: ^(0|[1-9]\d*)$State to move the campaign to.
active — the campaign reacts to its trigger again.
paused — the campaign stops reacting and keeps what it already queued.
archived — the campaign stops for good and its pending queue is cleared.
The status was changed and the change was confirmed.
No content
The requested state is not one of the three, or the campaign is recalling what it sent and cannot change state at all.
The API key lacks the permission this endpoint requires, or the request is outside what the organisation or the API key can access.
The campaign does not exist for this account.
The change did not complete. Repeating the request is safe and is how the change is retried. On a stop the campaign already reads as stopped and starts no new sends; messages already on their way may still be delivered.
PATCH /api/v0/accounts/{account_id}/auto-message-campaigns/{campaign_id}/status HTTP/1.1
Host: omapi.onlymonster.ai
x-om-auth-token: YOUR_API_KEY
Content-Type: application/json
Accept: */*
Content-Length: 19
{
"status": "active"
}No content
Rate limit: 5 requests per second
The campaign stops sending, its queue is cleared, and the messages it delivered within the last 24 hours are taken back out of the fans' chats. Anything older stays: the platform allows no recall beyond that window.
This cannot be undone and it is not limited to campaigns this API created. Any campaign of the account can be recalled, including one a member built in the panel.
Unlike a status change, repeating this request is not always safe: a campaign that is already recalling refuses it. If the answer is 502, read the campaign before repeating — recalling or recalled means the recall started and finishes on its own, while active or paused means it never started and only a repeat performs it. Reading the campaign needs auto_messages.view in addition to auto_messages.edit.
Required permission: auto_messages.edit
API token for authentication
OnlyMonster account the campaign belongs to.
12345Pattern: ^(0|[1-9]\d*)$Campaign identifier.
4312Pattern: ^(0|[1-9]\d*)$The recall was accepted: the campaign stops sending and takes back what it can.
No content
The campaign is not in a state a recall can start from: it is already recalling, or it is archived, or it opens a Mimic chat and sends nothing of its own. One code covers every cause; read the campaign to tell which.
The API key lacks the permission this endpoint requires, or the request is outside what the organisation or the API key can access.
The campaign does not exist for this account.
Unlike a status change, this answer is not an invitation to repeat the request blindly: the campaign stops sending the moment the recall is accepted, before the recall itself is confirmed, so a repeat against a campaign that did start meets the recall branch and is refused. Read the campaign to tell the two apart. Recalling or recalled means it started, and it is finished without further requests. Active or paused means the request never reached the campaign, and repeating it is the only way the recall happens.
POST /api/v0/accounts/{account_id}/auto-message-campaigns/{campaign_id}/unsend HTTP/1.1
Host: omapi.onlymonster.ai
x-om-auth-token: YOUR_API_KEY
Accept: */*
No content
Last updated
Was this helpful?
