# getUserAccessKey

Retrieve authenticated user access key. Required: authentication, confirmation. Returns: access key, metadata.

Agent View of the PolicyLayer registry record for `getUserAccessKey`. HTML page: https://policylayer.com/tools/ai-xpoz-social-insights/getuseraccesskey

## Facts

- Tool: `getUserAccessKey`
- Server: Social Media Search API — Twitter, Instagram, Reddit, TikTok (XPOZ) (`https://mcp.xpoz.ai/mcp`) — https://policylayer.com/tools/ai-xpoz-social-insights.md
- Homepage: https://github.com/xpozpublic/xpoz-mcp
- Risk category: Read (Low risk)
- Registry record: grade F, identity unverified
- Server auth posture: open
- Server CORS policy: *
- Server rate-limited: no
- Parameters: 3 (1 required)
- Recommended policy verdict: Allowed

## Parameters

| Parameter | Type | Required | Description |
| --- | --- | --- | --- |
| `feedback` | string | no | Optional. Any free-form feedback you want to share — about this tool, other tools, the platform overall, or anything else. Feedback does NOT have to be about th |
| `_requestId` | string | no |  |
| `confirmRetrieval` | boolean | yes | Must be true to retrieve key. Security confirmation required. |

Parameters from the server's own tool schema.

## Example call (MCP tools/call, JSON-RPC 2.0)

```json
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tools/call",
  "params": {
    "name": "getUserAccessKey",
    "arguments": {
      "confirmRetrieval": false
    }
  }
}
```

## Why getUserAccessKey is rated Low

While this tool retrieves data (Read category), it returns sensitive authentication credentials—an access key. This elevates severity to 'high' because compromised access keys could enable unauthorized access to the social media APIs and 1.5B+ posts, allowing lateral misuse of other tools on this server. It does not execute code, modify data, delete data, or move money, so Read is the correct category.

From the tool's own definition: "Tool name is 'getUserAccessKey' and description states it 'Retrieve[s] authenticated user access key' with 'Returns: access key, metadata.' The verb 'Retrieve' and return of credentials/keys indicates a Read operation that queries and returns authentication…"

## Use case

AI agents call getUserAccessKey to retrieve information from Social Media Search API — Twitter, Instagram, Reddit, TikTok (XPOZ) without modifying anything. It is typically the context-gathering step in research, monitoring, and reporting workflows, before the agent takes action elsewhere.

## Recommended policy (PolicyLayer)

Verdict: **Allowed**. Enforced by the PolicyLayer MCP gateway (https://policylayer.com/mcp-gateway) before a call reaches Social Media Search API — Twitter, Instagram, Reddit, TikTok (XPOZ):

```json
{
  "version": "1",
  "default": "deny",
  "tools": {
    "getUserAccessKey": {}
  }
}
```

## Other tools on Social Media Search API — Twitter, Instagram, Reddit, TikTok (XPOZ) (51)

- `removeTrackedItems` — Destructive — https://policylayer.com/tools/ai-xpoz-social-insights/removetrackeditems.md
- `cancelOperation` — Execute — https://policylayer.com/tools/ai-xpoz-social-insights/canceloperation.md
- `checkAccessKeyStatus` — Read — https://policylayer.com/tools/ai-xpoz-social-insights/checkaccesskeystatus.md
- `checkOperationStatus` — Read — https://policylayer.com/tools/ai-xpoz-social-insights/checkoperationstatus.md
- `countTweets` — Read — https://policylayer.com/tools/ai-xpoz-social-insights/counttweets.md
- `getAccountDetails` — Read — https://policylayer.com/tools/ai-xpoz-social-insights/getaccountdetails.md
- `getCreditsUsageHistory` — Read — https://policylayer.com/tools/ai-xpoz-social-insights/getcreditsusagehistory.md
- `getInstagramCommentsByPostId` — Read — https://policylayer.com/tools/ai-xpoz-social-insights/getinstagramcommentsbypostid.md
- `getInstagramPostInteractingUsers` — Read — https://policylayer.com/tools/ai-xpoz-social-insights/getinstagrampostinteractingusers.md
- `getInstagramPostsByIds` — Read — https://policylayer.com/tools/ai-xpoz-social-insights/getinstagrampostsbyids.md
- `getInstagramPostsByKeywords` — Read — https://policylayer.com/tools/ai-xpoz-social-insights/getinstagrampostsbykeywords.md
- `getInstagramPostsByUser` — Read — https://policylayer.com/tools/ai-xpoz-social-insights/getinstagrampostsbyuser.md
- `getInstagramUser` — Read — https://policylayer.com/tools/ai-xpoz-social-insights/getinstagramuser.md
- `getInstagramUserConnections` — Read — https://policylayer.com/tools/ai-xpoz-social-insights/getinstagramuserconnections.md
- `getInstagramUsersByKeywords` — Read — https://policylayer.com/tools/ai-xpoz-social-insights/getinstagramusersbykeywords.md
- `getRedditCommentById` — Read — https://policylayer.com/tools/ai-xpoz-social-insights/getredditcommentbyid.md
- `getRedditCommentsByKeywords` — Read — https://policylayer.com/tools/ai-xpoz-social-insights/getredditcommentsbykeywords.md
- `getRedditPostsByKeywords` — Read — https://policylayer.com/tools/ai-xpoz-social-insights/getredditpostsbykeywords.md
- `getRedditPostWithCommentsById` — Read — https://policylayer.com/tools/ai-xpoz-social-insights/getredditpostwithcommentsbyid.md
- `getRedditSubredditsByKeywords` — Read — https://policylayer.com/tools/ai-xpoz-social-insights/getredditsubredditsbykeywords.md
- `getRedditSubredditWithPostsByName` — Read — https://policylayer.com/tools/ai-xpoz-social-insights/getredditsubredditwithpostsbyname.md
- `getRedditUser` — Read — https://policylayer.com/tools/ai-xpoz-social-insights/getreddituser.md
- `getRedditUsersByKeywords` — Read — https://policylayer.com/tools/ai-xpoz-social-insights/getredditusersbykeywords.md
- `getTiktokCommentsByPostId` — Read — https://policylayer.com/tools/ai-xpoz-social-insights/gettiktokcommentsbypostid.md
- `getTiktokPostsByHashtags` — Read — https://policylayer.com/tools/ai-xpoz-social-insights/gettiktokpostsbyhashtags.md
- `getTiktokPostsByIds` — Read — https://policylayer.com/tools/ai-xpoz-social-insights/gettiktokpostsbyids.md
- `getTiktokPostsByKeywords` — Read — https://policylayer.com/tools/ai-xpoz-social-insights/gettiktokpostsbykeywords.md
- `getTiktokPostsBySound` — Read — https://policylayer.com/tools/ai-xpoz-social-insights/gettiktokpostsbysound.md
- `getTiktokPostsByUser` — Read — https://policylayer.com/tools/ai-xpoz-social-insights/gettiktokpostsbyuser.md
- `getTiktokUser` — Read — https://policylayer.com/tools/ai-xpoz-social-insights/gettiktokuser.md
- …and 21 more: https://policylayer.com/tools/ai-xpoz-social-insights.md

## For agents

This record is a snapshot. Live verdicts and the full registry:

- Check every server in your MCP config at once: `npx -y policylayer stack`
- Vet a server before you add it: install the mcp-precheck skill — `npx skills add https://policylayer.com` (skill text: https://policylayer.com/skill.md)
- Query the registry over MCP: endpoint `https://api.policylayer.com/mcp` — tools `check_mcp_server`, `check_mcp_stack`, `check_tool`, `search_registry`, `get_change_events`

---

Source: the PolicyLayer MCP registry — one continuously verified record per MCP server. Full record: https://policylayer.com/registry?q=ai-xpoz-social-insights · API: https://policylayer.com/registry/api · Policy library: https://policylayer.com/policies/ai-xpoz-social-insights
