Back to Browse

Replyatlas MCP Server

Developer ToolsModerate5.2MCP RegistryLocal
Free

Server data from the Official MCP Registry

Manage Instagram comment-to-DM automations, leads, analytics, conversations and broadcasts.

About

Manage Instagram comment-to-DM automations, leads, analytics, conversations and broadcasts.

Security Report

5.2
Moderate5.2Moderate Risk

ReplyAtlas MCP server is a well-scoped client for the ReplyAtlas REST API. It reads its API key from an environment variable, validates path IDs and API paths to block traversal, and gates message sends behind a confirm token. Main concerns are that REPLYATLAS_BASE_URL can redirect the bearer token to any host and that the confirm gate is driven by the model, so a prompt-injected model could still trigger sends; several referenced files were not provided for review. Supply chain analysis found 7 known vulnerabilities in dependencies (2 critical, 4 high severity). Package verification found 1 issue.

7 files analyzed · 12 issues found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Required

This plugin requests these system permissions. Most are normal for its category.

HTTP Network Access

Connects to external APIs or services over the internet.

env_vars

Check that this permission is expected for this type of plugin.

What You'll Need

Set these up before or after installing:

ReplyAtlas API key (mf_live_…), created in ReplyAtlas → Settings → API Keys on a plan with API access.Required

Environment variable: REPLYATLAS_API_KEY

Override the API base URL. Defaults to https://replyatlas.com.Optional

Environment variable: REPLYATLAS_BASE_URL

How to Install

Add this to your MCP configuration file:

{
  "mcpServers": {
    "io-github-ashishdesai0592-replyatlas": {
      "env": {
        "REPLYATLAS_API_KEY": "your-replyatlas-api-key-here",
        "REPLYATLAS_BASE_URL": "your-replyatlas-base-url-here"
      },
      "args": [
        "-y",
        "replyatlas-mcp"
      ],
      "command": "npx"
    }
  }
}

Documentation

View on GitHub

From the project's GitHub README.

ReplyAtlas MCP Server

Manage your ReplyAtlas account from Claude, Cursor or any Model Context Protocol client: Instagram comment-to-DM automations, leads, analytics, conversations and broadcasts.

ReplyAtlas auto-sends an Instagram DM to anyone who comments a keyword on your posts, Reels, Lives or story replies, using Instagram's official API. This server lets an AI assistant run that account for you: "create an automation that DMs my free guide to everyone who comments GUIDE", "who were my hottest leads this week?", "export leads tagged webinar".

Requires a ReplyAtlas plan with API access. Create an API key in ReplyAtlas → Settings → API Keys.

Install

No install needed. Your MCP client runs it with npx (Node.js 18+).

Claude Desktop (claude_desktop_config.json)

{
  "mcpServers": {
    "replyatlas": {
      "command": "npx",
      "args": ["-y", "replyatlas-mcp"],
      "env": { "REPLYATLAS_API_KEY": "mf_live_your_key_here" }
    }
  }
}

Cursor (~/.cursor/mcp.json)

{
  "mcpServers": {
    "replyatlas": {
      "command": "npx",
      "args": ["-y", "replyatlas-mcp"],
      "env": { "REPLYATLAS_API_KEY": "mf_live_your_key_here" }
    }
  }
}

Claude Code

claude mcp add replyatlas -e REPLYATLAS_API_KEY=mf_live_your_key_here -- npx -y replyatlas-mcp

Config

Env varRequiredDefaultNotes
REPLYATLAS_API_KEYyes—Your mf_live_… API key.
REPLYATLAS_BASE_URLnohttps://replyatlas.comOverride the API host.

On start the server calls /api/v1/me to check the key and exits with a clear message if the key is invalid or the plan has no API access.

Tools

AreaTools
Accountget_account, list_ig_accounts
Automationslist_automations, get_automation, create_automation, update_automation, delete_automation
Leadslist_leads, get_lead, list_tags, tag_lead, export_leads
Analyticsget_dashboard, get_analytics, list_dm_logs
Conversationslist_conversations, reply_to_conversation
Broadcastslist_broadcasts, create_broadcast, send_broadcast

Safety

Anything that messages real people is two-step. reply_to_conversation and send_broadcast first return a preview and a confirmToken; nothing is sent until the tool is called again with that token. The server only talks to the ReplyAtlas REST API over HTTPS with your API key. It never sees your Instagram password or tokens.

Development

pnpm install
pnpm test        # vitest
pnpm build       # tsup → dist/index.js

Links

License

MIT

Reviews

No reviews yet

Be the first to review this server!