What an assistant can and cannot do on your page
Before you hand a key to a program, it helps to know what the key opens. Here is the full list, and the shorter list of what stays with you.
With a key, an agent can
- Create pages on the account, up to the ten every account may have.
- Change anything on a page: name, bio, template, layout, colours, every block, published or not.
- Upload images from a URL and set them as the photo, the background or a link’s card.
- Import links from another link page or a photo and bio from Instagram.
- Read statistics: views, unique visitors, taps, per day and per link.
- Delete a page it has access to. The name is parked, not freed.
- Issue a new claim link for an account nobody has claimed yet.
With a key, an agent cannot
- Create or revoke API keys. Only a browser session — a person — can.
- Delete the account, change its e-mail or password.
- See or touch any other account’s pages. A wrong id is “not found”, never a hint.
- Publish an adult link without the 18+ label; the label is not a field it controls.
- Get around rate limits or the ten-page ceiling.
Before you claim the account
A page an assistant created without your e-mail lives on a provisional account. It is public, but the only way in is the assistant’s key. Nothing else exists yet: no e-mail, no password, no dashboard session. That is the moment to be careful with the claim link — it is the account. When you open it and set credentials, the key keeps working, and the dashboard lists it under *API keys* with the name of the program that made it.
What to keep and what to revoke
If you like having the page maintained by an assistant, keep the key. Every change it makes is visible in the editor, and the page can be read back as text at any time. If you asked for a one-off build, revoke the key after claiming; it takes one click and the page stays exactly as it is.