Back to Browse

Postpulse MCP Server

Developer ToolsUse Caution4.2MCP RegistryLocalRemote
Free

Server data from the Official MCP Registry

Social media scheduler for Instagram, Facebook, YouTube, TikTok, LinkedIn, X, Bluesky, and Telegram.

About

Social media scheduler for Instagram, Facebook, YouTube, TikTok, LinkedIn, X, Bluesky, and Telegram.

Remote endpoints: streamable-http: https://mcp.post-pulse.com

Security Report

4.2
Use Caution4.2High Risk

This MCP server implements OAuth 2.0 authentication properly with token verification middleware and scoped permissions for social media management. The codebase is well-structured with appropriate tool definitions and API client abstraction. However, there are several security and code quality concerns: excessive CORS permissions allowing any origin, missing input validation on critical parameters, insufficient error handling that could leak sensitive API responses, and potential token exposure in logging. The server's permissions appropriately match its stated purpose of multi-platform social media scheduling. Supply chain analysis found 5 known vulnerabilities in dependencies (0 critical, 5 high severity).

7 files analyzed · 15 issues found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Required

This plugin requests these system permissions. Most are normal for its category.

HTTP Network Access

Connects to external APIs or services over the internet.

env_vars

Check that this permission is expected for this type of plugin.

system_info

Check that this permission is expected for this type of plugin.

What You'll Need

Set these up before or after installing:

0.0.0.0Optional

Environment variable: HOST

3000Optional

Environment variable: PORT

PUBLIC_URLOptional
https://auth.post-pulse.com/Optional

Environment variable: POSTPULSE_AUTH_ISSUER

https://auth.post-pulse.com/.well-known/jwks.jsonOptional

Environment variable: POSTPULSE_AUTH_JWKS_URI

https://api.post-pulse.comOptional

Environment variable: POSTPULSE_AUDIENCE

https://api.post-pulse.comOptional

Environment variable: POSTPULSE_API_URL

REDIS_URLOptional

How to Install & Connect

Available as Local & Remote

This plugin can run on your machine or connect to a hosted endpoint. during install.

Documentation

View on GitHub

From the project's GitHub README.

PostPulse MCP Server

smithery badge

An MCP (Model Context Protocol) server that connects AI assistants to PostPulse — a social media management platform. Schedule posts, upload media, and manage accounts across Instagram, Facebook, YouTube, TikTok, Threads, LinkedIn, X (Twitter), Bluesky, and Telegram — all through natural language.

Features

  • Multi-platform posting — Schedule posts to 9 social media platforms from a single interface
  • Media management — Upload images and videos via URL or binary data for use in posts
  • Account management — List and manage all connected social media accounts
  • OAuth 2.0 authentication — Secure access via Auth0-based token verification
  • Streamable HTTP transport — Modern MCP transport protocol for reliable communication

Supported Platforms

PlatformPlacementsContent TypesRequirements
InstagramFeed, Reels, StoriesImage, VideoBusiness Account
FacebookFeed, Reels, StoriesImage, VideoPage
YouTubeVideo, ShortsVideoChannel
TikTokVideo, CarouselImage, VideoAccount
ThreadsPostImage, VideoAccount
LinkedInPostImage, VideoPersonal Account
X (Twitter)PostImage, VideoAccount
BlueskyPostImageAccount
TelegramMessageText, Image, VideoChannel/Chat

Quick Start

Hosted Server (Recommended)

PostPulse runs a hosted MCP server at https://mcp.post-pulse.com — no setup required. Point your MCP client to this URL and authenticate via OAuth.

Example MCP client configuration:

{
  "mcpServers": {
    "postpulse": {
      "url": "https://mcp.post-pulse.com"
    }
  }
}

Install via Smithery

You can also install through Smithery:

npx -y @smithery/cli install post-pulse/mcp-server --client claude

Self-Hosted

If you prefer to run the server yourself:

  1. Clone the repository:
git clone https://github.com/PostPulse/mcp-server-postpulse.git
cd mcp-server-postpulse
  1. Install dependencies and build:
npm install
npm run build
  1. Start the server:
npm start

Or with Docker:

docker build -t mcp-server-postpulse .
docker run -p 3000:3000 mcp-server-postpulse
Environment Variables
VariableDefaultDescription
HOST0.0.0.0Server bind address
PORT3000Server port
PUBLIC_URLPublic-facing URL (for OAuth metadata discovery)
POSTPULSE_AUTH_ISSUERhttps://auth.post-pulse.com/Auth0 issuer URL
POSTPULSE_AUTH_JWKS_URIhttps://auth.post-pulse.com/.well-known/jwks.jsonJWKS endpoint
POSTPULSE_AUDIENCEhttps://api.post-pulse.comAPI audience
POSTPULSE_API_URLhttps://api.post-pulse.comPostPulse API base URL
REDIS_URLRedis connection URL for session/event persistence (required)

Tools

list_accounts

List all connected social media accounts with their IDs, platforms, usernames, and display names. Use this as the first step to discover available accounts before scheduling posts or accessing chats.

Parameters: None

Returns: JSON array of account objects (id, platform, username, name).

list_chats

List publishing destinations for accounts that have sub-destinations. Facebook accounts publish to Pages, and Telegram accounts publish to channels or chats. Call this before scheduling posts to either platform — use the returned id as the facebookPageId or telegramChannelId in schedule_post.

Only supports FACEBOOK and TELEGRAM. Other platforms do not have sub-destinations and should be posted to directly.

Parameters:

NameTypeRequiredDescription
accountIdnumberYesAccount ID obtained from list_accounts
platformstringYesFACEBOOK or TELEGRAM

Returns: JSON array of destination objects (id, title, type, platform).

upload_media

Upload media files (images, videos) for use in scheduled posts. Supports two modes: importing from a public URL (with automatic processing) or uploading binary data directly as base64. Returns a media key to reference in schedule_post.

Parameters:

NameTypeRequiredDescription
mediaUrlstringNoPublic URL of the media file to import
mediaDatastringNoBase64-encoded media file content
mediaTypestringNoMIME type (e.g., image/jpeg, video/mp4). Required when using mediaData
mediaNamestringNoFilename for the uploaded media

Either mediaUrl or both mediaData and mediaType must be provided.

schedule_post

Schedule a social media post to one or more connected accounts. Supports platform-specific options like publication type (feed, reel, story), video titles, and topic tags. Posts are scheduled for a future time using ISO-8601 timestamps.

Parameters:

NameTypeRequiredDescription
accountIdnumberYesAccount ID from list_accounts
platformstringYesTarget platform: INSTAGRAM, FACEBOOK, TELEGRAM, YOUTUBE, TIKTOK, THREADS, LINKEDIN, X_TWITTER, BLUE_SKY
contentstringNoPost text/caption
mediaPathsstring[]NoMedia keys returned by upload_media
scheduledTimestringYesISO-8601 timestamp (e.g., 2025-01-15T10:00:00Z)
facebookPageIdstringYes (Facebook)Facebook Page ID from list_chats. Required when platform is FACEBOOK
telegramChannelIdstringYes (Telegram)Telegram Channel/Chat ID from list_chats. Required when platform is TELEGRAM
publicationTypestringNoFEED, REEL, or STORY (Instagram/Facebook, defaults to FEED)
titlestringNoVideo title (YouTube, TikTok)
topicTagstringNoTopic tag (Threads)

Resources

postpulse://accounts

An MCP resource providing the list of all connected social media accounts. Returns the same data as the list_accounts tool in JSON format.

Authentication

This server uses OAuth 2.0 with Auth0. OAuth metadata is discoverable at /.well-known/oauth-protected-resource and /.well-known/oauth-authorization-server.

Dynamic Client Registration (DCR)

MCP clients that support OAuth can register automatically via Dynamic Client Registration (RFC 7591). The server advertises a registration_endpoint in its OAuth metadata, so compliant clients (such as Claude Desktop, Cursor, etc.) will handle the entire OAuth flow — registration, authorization, and token exchange — without any manual setup from the user.

Pre-Registered Client Credentials

If you already have client credentials created through the PostPulse Developer Portal, you can configure your MCP client to use them directly instead of DCR. Pass your client_id and client_secret in the OAuth authorization code flow against the PostPulse authorization server.

Example Workflow

A typical interaction with the PostPulse MCP server:

  1. List accounts to find connected social media profiles
  2. Upload media (optional) to prepare images or videos
  3. Schedule a post with content, media, and a future publish time
User: "Schedule an Instagram reel for tomorrow at 9am with the video at https://example.com/video.mp4 and caption 'Check this out!'"

Reviews

No reviews yet

Be the first to review this server!