At a glance
OnlyFans login and sessions
You connect a creator through the AgencyKey desktop app and complete the normal OnlyFans login. AgencyKey does not store the creator’s OnlyFans password. After a successful login, OnlyFans issues session credentials. AgencyKey stores the session credentials required to operate the CRM on protected servers, encrypted at rest. In the standard AgencyKey team workflow, employees do not need to receive the creator’s password or handle session credentials. Each connected creator account uses a separate OnlyFans session. Activity in one creator account does not sign another creator out or switch the team into that creator’s workspace.Session lifecycle
OnlyFans controls how long a session remains valid. A session may be invalidated when it expires, the creator changes their password, someone logs in from another device, 2FA settings change, or OnlyFans applies an additional security check. When that happens, AgencyKey marks the account as Disconnected. An authorized user must complete the OnlyFans login again to refresh the connection. See Reauthorization.2FA and face verification
AgencyKey does not bypass OnlyFans security checks. If OnlyFans requests two-factor authentication, email or SMS confirmation, or face verification, you complete that step through the normal OnlyFans flow in the desktop app. Face verification continues through OnlyFans and its verification provider, Ondato; AgencyKey does not ask you to upload biometric data separately to the CRM.Team access
Team members sign in with their own AgencyKey accounts. The Owner and users with the required administrative permissions decide which creators each person can access and which actions they can perform. A team member does not need the creator’s OnlyFans password or session credentials for the standard AgencyKey workflow. Use roles and permissions to grant only the access each person needs, and remove assignments when access is no longer required.Data protection
AgencyKey encrypts data in transit with HTTPS/TLS and encrypts stored data at rest. Access controls and role-based permissions limit who can view or change agency data. For data categories, retention periods, legal rights, and privacy contacts, see the AgencyKey Privacy Policy.Related documentation
- CRM Account Security — set up 2FA and recovery codes
- Adding Accounts — connect a creator safely
- Reauthorization — restore a disconnected creator
- Data Sharing — choose how creator data contributes to shared features
- Configuring Permissions — control team access