One sub-account token — posts land in your HighLevel blog.
HighLevel has a real blog API, and DraftSEO writes into it. Inside the sub-account that owns the blog you create a Private Integration, tick the blog and media permissions, and paste the token here. DraftSEO lists your blog sites, authors and categories, you pick one of each, and articles arrive as native HighLevel posts with their images in your own media library. One thing is worth knowing up front: HighLevel’s API cannot tell us which domain your blog is on, so you give us the address and we check it against your sitemap before charging you for the site.
| Connection | Sub-account Private Integration token — Settings → Other Settings → Private Integrations |
|---|---|
| Agency-level token | Cannot reach the blog API — every blog permission is sub-account only |
| Image hosting | Your HighLevel media library — uploaded before the post is written, never hot-linked |
| Article address | yourdomain.com/post/the-slug — /post/ is a fixed HighLevel path, whatever your blog home is called |
| Sitemap | You generate it once — Domain → XML Sitemap → tick blog home and blog post → generate |
| Video embeds | Sent as links — HighLevel’s editor rewrites pasted embed markup |
| Structured data | Not available — HighLevel supports no per-post custom code |
| Publish modes | Auto · draft · scheduled |
Who does what
Nothing, once the token is in and your sitemap is generated. Posts appear in the sub-account’s blog for your client to read. Want eyes on each one first? Send them as drafts and publish from HighLevel.
One connection is one blog on one domain — one site.
Setup
Switch into the sub-account that owns the blog. This matters more than anything else on the page: every blog and media permission HighLevel offers is sub-account only, so an agency-level token cannot reach the blog API at all and fails in a way that looks like a bad token.
~1 minute
Settings → Other Settings → Private Integrations → create one named DraftSEO. If you do not see the menu, switch Private Integrations on under Labs first. Tick every blog and media permission: Create Blog Posts, Update Blog Posts, View Blog Posts, View Blog List, View Blog Authors, View Blog Categories, Check Blog Slug and Write Medias. Copy the token — HighLevel shows it once.
~3 minutes
In HighLevel open the domain your blog runs on → XML Sitemap, tick the blog home and blog post entries, and press generate Sitemap. DraftSEO uses that file to confirm your blog address really is live before it charges you for the site — and Google uses it to find your articles. Skip it and you get the predictable problem: twenty published articles that search engines never see.
~2 minutes
Connect a site → GoHighLevel → paste the token, confirm the Sub-Account ID if we could not read it, then pick your blog, an author and a category. Give the public address of the blog — the domain your visitors use, not the HighLevel back-office address — and DraftSEO verifies it.
~2 minutes
FAQ
Because HighLevel’s API does not expose it. The blog endpoints return an id and a name; the location record holds the white-label CRM host rather than your website, and its website field is free text. One sub-account can also run several blogs on several domains, so the sub-account id is not a domain either. So you tell us the address, and we fetch its sitemap to prove it is real, that it is a HighLevel blog, and that posts actually go live there — rather than taking your word for it and billing you for a site that does not exist.
Two causes account for nearly all of it. First, the token was created at agency level: blog permissions are sub-account only, so it will never work, however carefully it was copied. Second, a permission is missing — HighLevel cannot add one to an existing integration, so create a new one with all eight ticked. DraftSEO also tries both API generations before it ever blames your token, because a version mismatch answers with the same error as a bad credential.
At yourdomain.com/post/the-slug. HighLevel keeps /post/ as a fixed path for every blog post, whatever your blog home page is called — we have seen a live blog whose home is /blog-4525 while its posts still sit under /post/. DraftSEO checks the address responds before recording it, so an article is never reported as live at a URL that 404s.
No, and neither can any other tool: HighLevel’s blog API has no delete endpoint, and archiving a post leaves its content reachable at its live address. Deleting an article inside DraftSEO removes it from your DraftSEO account only. To take a post down, do it in HighLevel.
Videos are sent as links rather than embeds, because HighLevel’s blog editor rewrites pasted embed markup and an embed that does not survive is worse than a link that works. Tables are sent as tables. Structured data is dropped — HighLevel supports no per-post custom code, so there is nowhere to put it. We would rather say so here than let it look like a bug.
The same post is updated, so its address never changes. DraftSEO reads the live post back first and merges onto it, and it verifies the article body HighLevel echoes against what was sent before calling the publish a success — HighLevel has an open issue where an update returns success and quietly keeps the old text, and we would rather catch that than report a publish that never landed.
We do not assert one. HighLevel’s own pricing pages disagree about which tier includes API access, so DraftSEO never claims a requirement it cannot stand behind — if your account refuses the integration, you will see what HighLevel actually said.
No card required. Sub-account integration. Images in your own media library.