app.sprkly/sprkly
REMOTE · SPRKLY.APP · SCANNED SEP 20
Schedule, publish and track social posts across TikTok, Instagram, Threads and YouTube Shorts.
Available components
How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →
Endpoint Security94
- The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
- Authorisation is enforced on tool calls, advertised via RFC 9728 protected-resource metadata. Discovery is public, which costs nothing: no tool can be invoked without a token. View diagnostics → Pass
- HTTPS is enforced; there's no plaintext access path. View diagnostics → Pass
- The HSTS (Strict-Transport-Security) header is present. View diagnostics → Pass
- DNSSEC check failed: this domain isn't protected by DNSSEC. See how to fix → View diagnostics → Fail
- The authorisation server offers only Dynamic Client Registration (RFC 7591), which MCP 2026-07-28 deprecated in favour of Client ID Metadata Documents. View diagnostics → Partial
Transport & Reachability100
- Verified streamable-http transport via a live MCP handshake. View diagnostics → Pass
Schema Quality & AI Usability80
- 100% of prompts and resources have a non-trivial description (not blank, and not just the item's name).Pass
- AI-judged instruction clarity (excellent).Pass
- Context-footprint check failed: tool/resource definitions use about 3137 tokens (~174/item across 18 items; 18 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management100
- No destabilizing schema changes in the last 30 days.Pass
Tool Coverage100
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 100% of tool parameters carry a description.Pass
Tool Safety100
- No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
- All 1 tool(s) whose name or description implies an irreversible operation declare an MCP destructiveHint annotation.Pass
- An AI judge read all 19 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
- Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
How do I install the app.sprkly/sprkly MCP server?
app.sprkly/sprkly is a hosted endpoint at https://sprkly.app/api/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.
remote · sprkly.app
claude mcp add --transport http app-sprkly-sprkly 'https://sprkly.app/api/mcp'
{
"mcpServers": {
"app-sprkly-sprkly": {
"url": "https://sprkly.app/api/mcp"
}
}
} {
"servers": {
"app-sprkly-sprkly": {
"type": "http",
"url": "https://sprkly.app/api/mcp"
}
}
} [mcp_servers.app-sprkly-sprkly] url = "https://sprkly.app/api/mcp"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"app-sprkly-sprkly": {
"type": "remote",
"url": "https://sprkly.app/api/mcp",
"enabled": true
}
}
} openclaw mcp add app-sprkly-sprkly --url 'https://sprkly.app/api/mcp' --transport streamable-http
mcp_servers:
app-sprkly-sprkly:
url: "https://sprkly.app/api/mcp" {
"McpServers": {
"app-sprkly-sprkly": {
"Transport": "http",
"Url": "https://sprkly.app/api/mcp"
}
}
} assistant mcp add app-sprkly-sprkly -t streamable-http -u 'https://sprkly.app/api/mcp'
{
"mcpServers": {
"app-sprkly-sprkly": {
"type": "http",
"url": "https://sprkly.app/api/mcp"
}
}
} The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 20 Sept 26 0
- Stability: 0.97 → pass security
- 19 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 93 to 97. That category is still filling its 30-day observation window: 28 days of observed history at the previous scan, 29 at this one. The score rises as the window fills, whether or not the server changes.
- 17 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 87 to 90. That category is still filling its 30-day observation window: 26 days of observed history at the previous scan, 27 at this one. The score rises as the window fills, whether or not the server changes.
- 15 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 80 to 83. That category is still filling its 30-day observation window: 24 days of observed history at the previous scan, 25 at this one. The score rises as the window fills, whether or not the server changes.
- 13 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 73 to 77. That category is still filling its 30-day observation window: 22 days of observed history at the previous scan, 23 at this one. The score rises as the window fills, whether or not the server changes.
- 11 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 67 to 70. That category is still filling its 30-day observation window: 20 days of observed history at the previous scan, 21 at this one. The score rises as the window fills, whether or not the server changes.
- 9 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 60 to 63. That category is still filling its 30-day observation window: 18 days of observed history at the previous scan, 19 at this one. The score rises as the window fills, whether or not the server changes.
- 7 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 53 to 57. That category is still filling its 30-day observation window: 16 days of observed history at the previous scan, 17 at this one. The score rises as the window fills, whether or not the server changes.
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 20 Sept 2026 · Probed https://sprkly.app/api/mcp
TLS valid
Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .
| Subject | Issuer | Valid from | Valid until | Key | Signature | Serial |
|---|---|---|---|---|---|---|
| CN=sprkly.app | CN=WE1,O=Google Trust Services,C=US | 18 Aug 2026 | 16 Nov 2026 | ECDSA 256 | ECDSA-SHA256 | 24ed82999365cd3013c755a8cdec3c27 |
| SANs: sprkly.app | ||||||
| CN=WE1,O=Google Trust Services,C=US (CA) | CN=GTS Root R4,O=Google Trust Services LLC,C=US | 13 Dec 2023 | 20 Feb 2029 | ECDSA 256 | ECDSA-SHA384 | 7ff31977972c224a76155d13b6d685e3 |
| CN=GTS Root R4,O=Google Trust Services LLC,C=US (CA) | CN=GlobalSign Root CA,OU=Root CA,O=GlobalSign nv-sa,C=BE | 15 Nov 2023 | 28 Jan 2028 | ECDSA 384 | SHA256-RSA | 7fe530bf331343bedd821610493d8a1b |
Background: What to check on a remote MCP endpoint →
DNSSEC insecure
Validation of sprkly.app. — Not signed
| Zone | DS | Keys | Algorithms | Outcome |
|---|---|---|---|---|
| . | trust_anchor | 20326, 38696 | 8, 8 | Verified |
| app. | present | 23684 | 8 | Verified |
| sprkly.app. | absent | Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation |
Authentication Enforced and verified
The endpoint asked for a token and published valid RFC 9728 metadata describing how to get one.
| Result | Enforced and verified |
|---|---|
| Enforced | On tool calls |
| HTTP status | 200 |
WWW-Authenticate challenge Bearer error="invalid_token", error_description="Missing bearer credentials", resource_metadata="https://sprkly.app/.well-known/oauth-protected-resource/api/mcp", scope="profile mcp:read mcp:write"
Bearer error="invalid_token", error_description="Missing bearer credentials", resource_metadata="https://sprkly.app/.well-known/oauth-protected-resource/api/mcp", scope="profile mcp:read mcp:write" | Header | Value |
|---|---|
| strict-transport-security | max-age=63072000; includeSubDomains; preload |
| x-content-type-options | nosniff |
| x-frame-options | DENY |
| referrer-policy | strict-origin-when-cross-origin |
| permissions-policy | camera=(), microphone=(), geolocation=() |
Protected resource metadata
| Document | https://sprkly.app/.well-known/oauth-protected-resource/api/mcp |
|---|---|
| Retrieved | Yes |
| Resource | https://sprkly.app/api/mcp |
| Authorisation server | https://sprkly.app |
Background: How OAuth 2.1 works in the 2026 MCP spec →
Transports 2 probes
| Transport | URL | Outcome | Status | Location |
|---|---|---|---|---|
| streamable-http | https://sprkly.app/api/mcp | Verified | 200 | |
| http (plaintext) | http://sprkly.app/api/mcp | HTTPS enforced | 301 | https://sprkly.app/api/mcp |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
sprkly_add_media_from_url Add media from a URL ~134
Download an image or video from a public link into sprkly and get a media_id back, for reuse across several posts. You usually do NOT need this: sprkly_schedule_post accepts a link directly in media_urls and pulls it into storage itself whenever the target platform requires that. Reach for this tool only when the user wants one media_id to attach to more than one post. Google Drive and Dropbox share links are converted automatically; the file must be shared publicly. Limit 50 MB.
| Name | Type | Req | Description |
|---|---|---|---|
| url | string | yes | Direct https link to the image or video file. Must be publicly reachable. |
No output schema declared.
No examples provided.
sprkly_delete_scheduled_post Delete a scheduled post ~73
Remove a post from the queue. This is a soft delete. The user can restore it from the Deleted tab for 30 days. Posts that have already published cannot be deleted this way. Always confirm with the user before calling.
| Name | Type | Req | Description |
|---|---|---|---|
| post_id | string | yes | The scheduled post id to delete. |
No output schema declared.
No examples provided.
sprkly_draft_post Draft a post ~146
Compose a caption from a content hint and save it as a draft in sprkly, shaped to the tightest caption limit among the target platforms. Returns a draft id; the draft appears under /drafts for the user to review.
| Name | Type | Req | Description |
|---|---|---|---|
| content_hint | string | yes | What the post should be about: a topic, phrase, or key message. |
| name | string | – | Optional label for the draft. |
| platforms | array | – | Intended platforms, used to pick the caption length ceiling. |
| profile_ids | array | – | Optional accounts to pre-select on the draft. From sprkly_list_profiles. |
| tone | string | – | Voice for the draft. |
No output schema declared.
No examples provided.
sprkly_export_automation_template Export an auto reply template ~87
Download one Instagram auto reply as a shareable template. The file holds the trigger, the keyword and the message, and never a post id, a profile id or any account details, so it is safe to send to someone else. An auto reply that is still a draft has nothing published to export.
| Name | Type | Req | Description |
|---|---|---|---|
| automation_id | string | yes | The automation id to export. |
No output schema declared.
No examples provided.
sprkly_get_account_summary Get account summary ~41
Plan tier, trial state, connected account count, scheduled post counts by status, and the next three upcoming posts. Never returns tokens or secrets.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
sprkly_get_analytics Get post performance ~235
How the user's published posts actually performed: total views and engagement, week-on-week / month-on-month / year-on-year change, their best posting hour, weekday and content category, and the top posts behind those numbers. Every recommendation carries a `samples` count — say how thin the evidence is rather than presenting a one-post pattern as a finding. Every period-on-period percentage carries the post counts and raw totals it came from: quote those, because a big percentage off a tiny base is not a big change. `topPosts` is grouped by platform and ranked only inside each group; `relativeToPlatformBest` compares a post with others on its OWN platform and never across platforms, so use the absolute `value` and its `metric` label to weigh one platform against another. Instagram contributes likes and comments only, and Threads and Facebook produce no metrics at all, so read `coverage` before comparing platforms.
| Name | Type | Req | Description |
|---|---|---|---|
| days | integer | – | How many days back to analyse. Default 30. |
| profile_ids | array | – | Limit to these accounts. Omit for every account this connection can see. |
No output schema declared.
No examples provided.
sprkly_get_billing_summary Get billing summary ~43
Subscription status, current plan, period end, purchased handles and the last few billing events. No payment method details; the Stripe customer id is truncated.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
sprkly_get_post_approval_status Get approval status ~44
Whether a post is awaiting human review, approved or rejected, including reviewer notes and timestamps.
| Name | Type | Req | Description |
|---|---|---|---|
| post_id | string | yes | The scheduled post id. |
No output schema declared.
No examples provided.
sprkly_get_post_status Get post status ~100
Full detail for one post: status, targets, scheduled and published times, permalink, and the failure reason if it did not publish. Media comes back as mediaIds in slide order, not as links. Ids and profile ids are plumbing: talk to the user about accounts by handle and about posts by their caption, and do not read ids out unless they ask for one.
| Name | Type | Req | Description |
|---|---|---|---|
| post_id | string | yes | The scheduled post id. |
No output schema declared.
No examples provided.
sprkly_get_tiktok_posting_options Get TikTok posting options ~112
This creator's allowed TikTok privacy levels and interaction settings, fetched live from TikTok. You usually do NOT need this before scheduling: sprkly_schedule_post checks privacyLevel against this same list itself and, when it is wrong, returns the levels that would work. Call this only when the user asks what their options are, or you want to offer them a choice.
| Name | Type | Req | Description |
|---|---|---|---|
| profile_id | string | yes | The TikTok profile id to query, from sprkly_list_profiles. |
No output schema declared.
No examples provided.
sprkly_import_automation_template Import an auto reply template ~161
Read an auto reply template, and optionally set it up. With no profile_id NOTHING is written: the template is checked and handed back, which is the safe first call. With a profile_id the automation is created, and it goes live when the trigger can be satisfied. A keyword or every-comment trigger needs post_id as well; without one it saves as a draft that sends nothing until a post is chosen.
| Name | Type | Req | Description |
|---|---|---|---|
| post_id | string | – | The published post to watch. Needed for a keyword or every-comment trigger. |
| profile_id | string | – | The Instagram account to set it up on. Leave this out to only check the template. |
| template | object | yes | The template, as an object or as the file text. |
No output schema declared.
No examples provided.
sprkly_list_connected_social_accounts List connected accounts ~65
Every ACTIVE social account linked to this sprkly account: platform, handle, follower count, and whether it needs reconnecting. Disconnected/inactive accounts are never listed, so any profileId returned here is a valid posting target. Never returns access tokens.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
sprkly_list_profiles List posting targets ~36
The profile ids needed to target a post, with each one's platform and handle. Call this before sprkly_schedule_post.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
sprkly_list_scheduled_posts List scheduled posts ~80
The post queue, newest first, with a caption preview, targets, status and failure reason. Supports a status filter and cursor pagination.
| Name | Type | Req | Description |
|---|---|---|---|
| cursor | string | – | Pagination cursor. Pass the nextCursor value from a previous response. |
| limit | integer | – | Maximum posts to return. |
| status | string | – | Filter by status. |
No output schema declared.
No examples provided.
sprkly_request_post_approval Request human approval ~86
Submit a draft post for human review. Moves the post to pending_approval and returns an approval id to poll with sprkly_get_post_approval_status. Use this when the user wants a person to sign off before anything publishes.
| Name | Type | Req | Description |
|---|---|---|---|
| note | string | – | Optional context for the reviewer. |
| post_id | string | yes | The draft post id to submit. |
No output schema declared.
No examples provided.
sprkly_schedule_post Schedule a post ~817
Queue a post for publishing, in ONE call. Attach media by passing the user's link straight to media_urls: sprkly downloads it into storage itself for the platforms that need that, so no upload tool has to run first. Runs the same quota, duplicate-content and platform pre-flight checks as the sprkly app. Instagram and TikTok require media at submission time; YouTube and TikTok require a title, and TikTok also requires platform_meta.tiktok.privacyLevel — just send the level the user asked for and this tool names the allowed values if it is not one of them. It reads the real bytes of the media and the response says what will actually publish on each platform (a Reel, a 3-slide carousel, a photo set, a Page feed video) plus anything worth passing on: relay that to the user. Confirm the date, time and target accounts with the user first. If a target platform has more than one connected account and profile_ids is not given, the tool returns needsAccountChoice with the options instead of scheduling — put that choice to the user, then re-call.
| Name | Type | Req | Description |
|---|---|---|---|
| all_accounts | boolean | – | Explicitly post to EVERY connected account on every listed platform, skipping the needsAccountChoice question. Only pass true when the user has said they want all accounts. |
| caption | string | – | Post caption, max 2200 characters. |
| category | string | – | Optional content category, e.g. "fitness". |
| media_id | string | – | Id of a single media file already uploaded to sprkly. Shorthand for a one-item media_ids. |
| media_ids | array | – | Ids of media files already uploaded to sprkly, in slide order. Array order is the published order. Use these when the user already has media in sprkly, or when one file is going on several posts; for… |
| media_urls | array | – | Publicly reachable image or video URLs to attach, in slide order. Pass links through for ANY platform. Instagram and Threads fetch them directly; for TikTok, YouTube and Facebook sprkly downloads the… |
| platform_meta | object | – | Platform-specific publishing options, keyed by platform. |
| platforms | array | – | Platforms to publish to. A platform with exactly one connected account is targeted directly; one with several makes the tool answer needsAccountChoice so the user can pick. |
| profile_ids | array | – | Specific accounts to publish to, from sprkly_list_profiles. When given, this list IS the target set — platforms are not fanned out. |
| scheduled_time | string | – | ISO 8601 timestamp to publish at. Must be in the future. If omitted the post goes out on the next publisher run, about a minute from now — there is no smart slot-picking, so pass an explicit time unl… |
| title | string | – | Post title. Required for YouTube (max 100 characters) and TikTok (max 150 characters). |
No output schema declared.
No examples provided.
sprkly_update_scheduled_post Reschedule or edit a post ~170
Change the caption, publish time, target accounts or attached media on a post that has not published yet. Only posts with status "scheduled" can be edited.
| Name | Type | Req | Description |
|---|---|---|---|
| caption | string | – | Replacement caption, max 2200 characters. |
| media_id | string | – | Replacement sprkly media file id. Shorthand for a one-item media_ids. |
| media_ids | array | – | Replacement media, in slide order. Replaces the whole set, it does not append — pass every slide you want the post to keep. |
| post_id | string | yes | The scheduled post id. |
| profile_ids | array | – | Replacement target accounts. Platforms are re-derived from them. |
| scheduled_time | string | – | New ISO 8601 publish time. Must be in the future. |
No output schema declared.
No examples provided.
sprkly_validate_post_policy Validate against platform rules ~163
Check a caption against each target platform's posting rules before scheduling: caption length, media requirements, hashtag ceilings, whether links are clickable, required YouTube titles, and PII or prohibited-content warnings. Pure analysis. Writes nothing.
| Name | Type | Req | Description |
|---|---|---|---|
| caption | string | yes | The caption to check. |
| hashtags | array | – | Hashtags posted alongside the caption, if they are not already in it. |
| mediaUrlsCount | integer | – | How many images or videos will be attached. Instagram and TikTok require at least one. |
| platformMeta | object | – | Platform-specific publishing options, keyed by platform. |
| platforms | array | yes | Target platforms to check against. |
| title | string | – | Post title. Required for YouTube, max 100 characters. |
No output schema declared.
No examples provided.
What is the app.sprkly/sprkly MCP server?
app.sprkly/sprkly is an MCP server listed in the public MCP registry as app.sprkly/sprkly. Schedule, publish and track social posts across TikTok, Instagram, Threads and YouTube Shorts. This page covers its hosted endpoint (https://sprkly.app/api/mcp).
Is the app.sprkly/sprkly MCP server safe to use?
app.sprkly/sprkly scores 94 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.
What tools does the app.sprkly/sprkly MCP server expose?
app.sprkly/sprkly exposes 18 tools: sprkly_add_media_from_url, sprkly_delete_scheduled_post, sprkly_draft_post, sprkly_export_automation_template, sprkly_get_account_summary, and 13 more. Their descriptions and schemas cost roughly 2,593 tokens of context every time the server is loaded.
Does the app.sprkly/sprkly MCP server require authentication?
Yes. app.sprkly/sprkly asked us for credentials when we connected, so you will need to authorise it in your MCP client before it can do anything.
Is the app.sprkly/sprkly MCP server still maintained?
app.sprkly/sprkly is still listed as active in the MCP registry. We last reached this channel on 20 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.