Skip to main content
AgencyKey lets agencies work with connected OnlyFans accounts without sharing creator passwords with team members. This page explains how AgencyKey protects account access and agency data.

At a glance

OnlyFans login and sessions

You connect a creator through the AgencyKey desktop app and complete the normal OnlyFans login. AgencyKey does not store the creator’s OnlyFans password. After a successful login, OnlyFans issues session credentials. AgencyKey stores the session credentials required to operate the CRM on protected servers, encrypted at rest. In the standard AgencyKey team workflow, employees do not need to receive the creator’s password or handle session credentials. Each connected creator account uses a separate OnlyFans session. Activity in one creator account does not sign another creator out or switch the team into that creator’s workspace.

Session lifecycle

OnlyFans controls how long a session remains valid. A session may be invalidated when it expires, the creator changes their password, someone logs in from another device, 2FA settings change, or OnlyFans applies an additional security check. When that happens, AgencyKey marks the account as Disconnected. An authorized user must complete the OnlyFans login again to refresh the connection. See Reauthorization.

2FA and face verification

AgencyKey does not bypass OnlyFans security checks. If OnlyFans requests two-factor authentication, email or SMS confirmation, or face verification, you complete that step through the normal OnlyFans flow in the desktop app. Face verification continues through OnlyFans and its verification provider, Ondato; AgencyKey does not ask you to upload biometric data separately to the CRM.

Team access

Team members sign in with their own AgencyKey accounts. The Owner and users with the required administrative permissions decide which creators each person can access and which actions they can perform. A team member does not need the creator’s OnlyFans password or session credentials for the standard AgencyKey workflow. Use roles and permissions to grant only the access each person needs, and remove assignments when access is no longer required.

Data protection

AgencyKey encrypts data in transit with HTTPS/TLS and encrypts stored data at rest. Access controls and role-based permissions limit who can view or change agency data. For data categories, retention periods, legal rights, and privacy contacts, see the AgencyKey Privacy Policy.