Back to Browse

Markaestro Agents MCP Server

Developer ToolsModerate7.2MCP RegistryLocalRemote
Free

Server data from the Official MCP Registry

Schedule, publish, and review social posts and analytics for a Markaestro brand.

About

Schedule, publish, and review social posts and analytics for a Markaestro brand.

Remote endpoints: streamable-http: https://markaestro.com/api/public/v1/mcp

Security Report

7.2
Moderate7.2Low Risk

This is a well-structured MCP server for Markaestro's social media management API with properly scoped authentication, clear authorization controls, and reasonable security practices. The code demonstrates good defensive patterns (input validation via Zod, idempotency keys, proper error handling) and the server correctly enforces permission boundaries through API-level controls. Minor code quality observations around error handling breadth do not materially impact security. Supply chain analysis found 1 known vulnerability in dependencies (0 critical, 1 high severity). Package verification found 1 issue.

4 files analyzed · 5 issues found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Required

This plugin requests these system permissions. Most are normal for its category.

HTTP Network Access

Connects to external APIs or services over the internet.

env_vars

Check that this permission is expected for this type of plugin.

File System Read

Reads files on your machine. Normal for tools that analyze or process local data.

What You'll Need

Set these up before or after installing:

Workspace API key (mk_live_ or mk_test_) from Settings, API Access. Covers one brand or all brands in the workspace.Required

Environment variable: MARKAESTRO_API_KEY

Set to 1 to register only the reading tools.Optional

Environment variable: MARKAESTRO_READ_ONLY

How to Install & Connect

Available as Local & Remote

This plugin can run on your machine or connect to a hosted endpoint. during install.

Documentation

View on GitHub

From the project's GitHub README.

Markaestro for AI agents

Official agent tooling for Markaestro, the social publishing workspace. Agents schedule, publish, and review posts on Facebook, Instagram, TikTok, Threads, Pinterest, LinkedIn, and X, read brand and per-post analytics, and manage Intelligent Evergreen queues.

FolderWhat it is
plugin/Claude Code plugin: the skill plus the hosted MCP server
skills/markaestro/The markaestro Agent Skill, usable by any client that supports skills
mcp/@markaestro/mcp, the MCP server as a local stdio package

Connect

The hosted MCP server needs nothing installed and no key pasted. Add https://markaestro.com/api/public/v1/mcp to your client; the first tool call opens the browser to sign in, pick a workspace and brand, and click Allow (OAuth 2.1 with PKCE and dynamic client registration).

Claude Code

claude plugin marketplace add markaestro/markaestro-agents
claude plugin install markaestro@markaestro

Claude (claude.ai and Claude Desktop): open Customize, Connectors, click Add custom connector, paste https://markaestro.com/api/public/v1/mcp, leave the OAuth client fields empty, and click Add. Click Connect to sign in.

Cursor, ChatGPT, Grok, OpenClaw, Hermes, and other clients: step by step instructions for each are at markaestro.com/developers/agents.

Skill only (Claude Code, Cursor, Codex, Copilot, Gemini, and other agents that read skills; listed on skills.sh):

npx skills add markaestro/markaestro-agents

OpenClaw (listed on ClawHub):

clawhub install markaestro

Local package (reads media from your own disk; needs a workspace API key from Settings, API Access):

claude mcp add markaestro -e MARKAESTRO_API_KEY=mk_live_... -- npx -y @markaestro/mcp

Example prompts

  • "What did we post on Instagram last month, and which three posts got the most engagement?"
  • "Draft a LinkedIn post announcing our new cold brew and schedule it for Tuesday at 9am New York time. Don't publish anything else."
  • "When does our audience respond best? Put next week's three drafts in those slots."

Safety

  • The user scopes every connection at sign-in: one brand, or all brands in the workspace. A single-brand connection cannot reach any other brand; an all-brands connection names the brand on each post it creates.
  • Agents manage social media, not the account: no tool reaches account settings, billing, team members, API keys, webhooks, or channel connections, and none deletes a published post, takes one down from a platform, or archives an Evergreen queue. The key issued at the agent sign-in carries the same limits at the REST layer, so they hold whichever client holds the token.
  • create_post saves a draft unless scheduledAt is set. publish_post is the only tool that publishes immediately; scheduling (scheduledAt, bulk_posts, activating an Evergreen queue) sets up future publishes. The skill tells the agent to ask the user before publish_post and before activating an Evergreen queue.
  • Every tool declares readOnlyHint, destructiveHint, and openWorldHint explicitly, set from what it does: destructiveHint on tools that edit, remove, unschedule, or publish (update_post, delete_post, bulk_posts, publish_post, update_evergreen_queue, pause_evergreen_queue), and openWorldHint on tools that can change what appears on a platform, now or on a schedule. Clients that honor annotations, Claude among them, ask for confirmation before writes.
  • Connected agents are listed and revoked in Markaestro under Settings, API.

Privacy Policy

Markaestro processes the posts, media, and analytics the agent reads or writes for the brands the connection covers, and nothing from the conversation beyond each tool call's arguments. Section 7 of the Privacy Policy, "AI agents and connected apps", covers agent connections specifically; the policy as a whole explains what is collected, how it is used and retained, who it is shared with, and how to contact us. Terms of Service.

Support

Email support@markaestro.com, use the contact page, or open an issue in this repository. If a sign-in or tool call fails, include the requestId from the error; it lets support trace the call. Report security vulnerabilities privately to support@markaestro.com rather than in a public issue.

License

MIT. Copyright (c) 2026 Aethos Solutions LLC.

Reviews

No reviews yet

Be the first to review this server!