Back to Browse

Seenpaid MCP Server

Developer ToolsModerate6.0MCP RegistryLocal
Free

Server data from the Official MCP Registry

Open-source, self-hosted posting layer with an MCP server for AI agents. 25+ platforms.

About

Open-source, self-hosted posting layer with an MCP server for AI agents. 25+ platforms.

Security Report

6.0
Moderate6.0Moderate Risk

The codebase demonstrates solid security practices for a self-hosted MCP server with appropriate single-operator authentication, encrypted token storage, and input validation. However, there are moderate concerns around in-memory state management for OAuth, potential token exposure in error messages, and permission scope that could be more explicitly documented. The server's architecture and credential handling are generally sound, with proper separation of concerns and encrypted storage of sensitive tokens. Supply chain analysis found 2 known vulnerabilities in dependencies (0 critical, 1 high severity).

7 files analyzed · 10 issues found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Required

This plugin requests these system permissions. Most are normal for its category.

env_vars

Check that this permission is expected for this type of plugin.

HTTP Network Access

Connects to external APIs or services over the internet.

database

Check that this permission is expected for this type of plugin.

File System Read

Reads files on your machine. Normal for tools that analyze or process local data.

File System Write

Writes or modifies files on your machine. Check that this is expected for the tool.

process_spawn

Check that this permission is expected for this type of plugin.

How to Install

Add this to your MCP configuration file:

{
  "mcpServers": {
    "io-github-justinasrolando-cpu-seenpaid": {
      "args": [
        "-y",
        "seenpaid"
      ],
      "command": "npx"
    }
  }
}

Documentation

View on GitHub

From the project's GitHub README.

seenpaid

License: AGPL v3

Ask your AI agent which of your posts made money.

That question is answered by seenpaid.com — the hosted cloud product, which matches your Stripe sales back to the exact post that drove them. This repository is not that. This repository is the open posting layer underneath it: a self-hosted service that connects to 25 social and publishing platforms, queues and retries deliveries, and exposes itself to an AI agent over MCP (Model Context Protocol) so an agent can schedule posts on your behalf. Point an agent at your own instance, or point it at seenpaid.com if you also want the revenue answer — same MCP shape, different depth.

What this is

  • A BullMQ-backed publish pipeline: schedule a post once, it fans out to every connected platform as an independent, retried job.
  • 25 platform adapters behind one interface — OAuth, webhook, API-key, and paste-your-own-credentials flows, whichever each platform actually uses.
  • A REST API and a 3-tool MCP server, so both a script and an AI agent can drive it the same way.
  • Single-operator by design: one API key, no login screen, no multi-tenant concept. Deploy it, set a key, use it.

What this is NOT

  • No revenue attribution. This repo does not track clicks, match sales, or tell you which post earned anything. That's the hard, hosted part — seenpaid.com — and it's deliberately not in here.
  • No multi-user accounts, teams, or roles. One instance, one operator. If you need that, you're looking for the cloud product.
  • No billing, plans, or usage limits. There's nothing to meter — this is software you run, not a subscription.

If what you actually want is "which post made money," this repo alone can't answer that — connect your instance's data to seenpaid.com, or read SELF_HOST.md for the honest tradeoffs before you invest time self-hosting for that reason.

Quickstart

git clone <this-repo>
cd seenpaid
cp .env.example .env
# fill in API_KEY and TOKEN_ENCRYPTION_KEY (openssl rand -hex 32 for each)
docker compose up -d
docker compose exec api npm run db:migrate

The API is now listening on http://localhost:3001. Full walkthrough, including connecting a platform and your agent, in SELF_HOST.md.

The 3 MCP tools

Point an MCP-capable agent at POST /mcp (Bearer API_KEY) and it gets:

ToolWhat it does
list_accountsLists connected platform accounts — id, platform, handle, status
list_postsLists recent posts with status, schedule time, and target platforms
schedule_postSchedules or immediately publishes a post to one, several, or all connected accounts

That's the whole surface. There's no get_analytics or get_top_posts here — those exist only on the hosted seenpaid.com MCP server, because answering them requires the closed-source attribution engine this repo doesn't include.

See mcp-connector/README.md for a copy-pasteable client config.

Supported platforms

PlatformConnect method
X (Twitter)Bring-your-own OAuth 1.0a app keys
BlueskyApp password
LinkedInOAuth
InstagramOAuth (Meta)
FacebookOAuth (Meta)
TikTokOAuth
DiscordWebhook URL
TelegramBot token + channel
MastodonOAuth
NostrPrivate key (nsec/hex)
Dev.toAPI key
HashnodePersonal access token
MediumIntegration token
RedditOAuth
ThreadsOAuth
TumblrOAuth
PinterestOAuth
VKOAuth
SlackIncoming webhook URL
WordPressApplication password
GhostAdmin API key
LemmyInstance login
Generic webhookURL + optional signing secret
Micro.blogApp token
MatrixHomeserver + access token + room

Each adapter lives in src/platforms/. Only platforms you configure credentials for are usable — everything else fails cleanly with a clear error rather than blocking the rest of the app. Full env var list per platform in SELF_HOST.md.

Architecture

src/
  platforms/        25 adapters + registry — one publish()/OAuth interface
  domain/features/
    posts/          Create/list/cancel a post; fans out to per-platform jobs
    accounts/        Connect/list/disconnect a platform account
    media/           Presigned upload + optional free AI image generation
  jobs/              BullMQ queue + worker: the actual publish pipeline
  entry-points/
    api/             REST API (Express)
    mcp/             The 3-tool MCP server
  auth/              Single-operator API-key auth (see below)
  data-access/       Drizzle ORM schema, repositories, migrations

Auth model

This is intentionally not the multi-tenant JWT/RBAC system a SaaS product needs. Self-hosting means you're the only user, so auth here is one shared secret: set API_KEY in .env, send it as Authorization: Bearer <key> (or X-Api-Key: <key>) on every request. No signup, no login UI, no sessions, no password hashing. This mirrors how most single-operator self-hosted tools handle auth — one secret, checked on every request, nothing more to reason about.

If you need multiple users or role-based access on one instance (e.g. an agency running this for several clients), that's a deliberate scope cut — see CONTRIBUTING.md for how to propose it.

License

The core (everything except mcp-connector/) is licensed AGPL-3.0 — see LICENSE. The short version: you can self-host, modify, and redistribute freely, but if you run a modified version as a network service for others, you must offer them the modified source too. This exists to keep the project from being cloned into a closed-source competing service without the changes flowing back.

mcp-connector/ (just client-side config for connecting an agent) is MIT — see mcp-connector/LICENSE — so it's freely copyable into agent directories and other tooling without license friction.

Contributing

See CONTRIBUTING.md before opening a PR — it sets expectations on scope and response time.

Reviews

No reviews yet

Be the first to review this server!