Postify MCP
Draft, schedule and publish social media posts to your connected channels, and read post analytics, from your Postify calendar. Remote server with OAuth sign-in.
Размещённый MCP-сервер
npx add-mcp 'https://app.usepostify.com/api/mcp'Устанавливается в Claude Code, Codex, Cursor и другие
Документация
curl https://app.usepostify.com/v1/channels \
-H "Authorization: Bearer postify_live_XXXXXXXXXXXXXXXX"
{
"data": [
{
"id": "ch_9x2y3z0001",
"platform": "linkedin",
"handle": "acme-co",
"display_name": "Acme Co",
"status": "connected"
},
{
"id": "ch_9x2y3z0002",
"platform": "bluesky",
"handle": "acme.bsky.social",
"display_name": "Acme",
"status": "connected"
}
]
}
17 REST operations
OpenAPI 3.1
RFC 9457 errors
Rate-limit headers
Idempotency keys
Standard Webhooks
MCP server
curl -X POST https://app.usepostify.com/v1/posts \
-H "Authorization: Bearer postify_live_XXXXXXXXXXXXXXXX" \
-H "Idempotency-Key: $(uuidgen)" \
-H "Content-Type: application/json" \
-d '{
"variants": [
{
"channel_id": "ch_9x2y3z0001",
"body": "Shipping day 🚀 Our new analytics dashboard is live — see what actually lands with your audience."
}
],
"scheduled_at": "2026-08-01T09:00:00Z"
}'
Compose once,schedule anywhere
One request creates a post with a variant per channel — draft it, schedule it, or publish now. Send an Idempotency-Key and network retries can never double-post: replays return the recorded response verbatim.
- Cursor pagination, draft-11 rate-limit headers, and a request id on every response.
- Publish-now and delete stay locked behind the workspace owner's dangerous-operations toggle. createPost reference
Built for AI agents
Guardrails first: agents get real capability without uncontrolled blast radius.
Scoped keys
Keys carry only the scopes you mint them with — a read-only key can never write.
Plan quotas enforced server-side
API requests meter per plan with honest errors: 403 when a plan lacks the feature, 429 when the allowance is spent.
Dangerous ops off by default
Delete and publish-now answer 403 dangerous_ops_disabled until a workspace owner opts in — agents draft, humans approve.
SSRF-guarded webhooks
Delivery URLs are validated against private and cloud-metadata address space at creation and at every delivery.
Paste-prompt for your agent
Help me build against the Postify API. Read https://usepostify.com/llms.txt first — it indexes the guides and Markdown twins of every API page. Base URL: https://app.usepostify.com/v1, auth: Authorization: Bearer postify_live_… (I'll provide the key). Use Idempotency-Key on POST /v1/posts, honor Retry-After on 429, and note that delete/publish-now return 403 dangerous_ops_disabled until the workspace owner opts in.
Or connect the MCP server — 14 tools, OAuth 2.1
$ claude mcp add --transport http postify https://app.usepostify.com/api/mcp
Draft, schedule, and analyze by chat. Publish and delete tools stay off until the org owner enables them. Also see the AI surfaces page and llms.txt.
TypeScript SDK
@postify/sdk — a hand-written, thin, fully typed client over all 17 operations: typed problem errors, automatic Retry-After retries, auto idempotency keys, cursor auto-pagination, and a Standard Webhooks verifier. Open source and published on npm.
npm i @postify/sdk — or stay on plain fetch; every docs page ships copy-paste TypeScript either way.
OpenAPI 3.1, generated from the source of truth
The spec is generated from the same schemas the handlers validate with — it can't drift from reality. Browse it interactively or feed it straight to your codegen.
Every plan includes the API
API requests meter monthly, separate from your scheduled-posts quota. Burst limits are per key, per minute.
| Plan | API requests / month | Per-key burst / minute |
|---|---|---|
| Free | 1,000 | 30 |
| Starter | 10,000 | 60 |
| Team | 50,000 | 120 |
| Agency | 250,000 | 300 |
Two honest 429s: rate_limited (burst — retry after Retry-After) vs quota_exhausted (monthly allowance). See pricing for full plans.
Events pushed to you, signed
Subscribe to 5 event types — publishes, failures, channel health. Every delivery is Standard-Webhooks-signed, retried over ~31.7 hours, and guarded by a failure ladder that warns you before disabling a dead endpoint.