All docs
Substack
Credential: Webhook, not a direct connector
There is no Substack connector, and that is a decision rather than an omission.
Why
Substack publishes no write API. Every tool that claims to post to Substack programmatically works
the same way: you hand it your substack.sid session cookie, and it replays that cookie against
Substack’s internal endpoints while pretending to be your browser.
That cookie is not a scoped API key. It is your logged-in session. Anything holding it can read your subscriber list, change your payment settings, send an email to everyone you have, or delete the publication. There is no permission model to narrow it and no revocation short of logging out everywhere.
BirchSeek asks for the narrowest credential each platform offers, and stores it sealed. Asking you for a credential that is equivalent to your whole account, to work around the absence of an API, would be the wrong trade — and it breaks without warning whenever Substack changes an internal endpoint.
What to do instead
Use the webhook connector. BirchSeek sends each approved article to an HTTPS endpoint you control, signed with HMAC-SHA256 so you can verify it came from us:
- Add a webhook connector and copy the signing secret (shown once).
- Point it at your own automation - n8n, a Cloudflare Worker, a small script.
- Verify the
X-BirchSeek-Signatureheader, then do whatever you like with the payload.
The payload carries the article as markdown - already ending in the ## Sources list that pairs
each verified claim with the page it was checked against - along with its title, slug, meta
description, tags, FAQ pairs and every citation as structured data. See
the webhook reference for the exact shape.
This keeps the Substack credential on your side of the line, where you can rotate it, scope it, and decide for yourself what risk you are comfortable with.
If Substack ships an API
If Substack releases a real write API with scoped tokens, a first-party connector becomes straightforward and we will add one. The publishing architecture already has a slot for it: every connector implements the same interface, so the work is one file plus a form.