Skip to content
verify mcp Beta VerifyMCP is currently in beta. If you notice any issues, get in touch and we’ll put it right.

iHatePosting

REMOTE · IHATEPOSTING.COM · 3 COMPONENTS · SCANNED OCT 4

Draft, check and schedule posts to your connected social accounts from Claude, ChatGPT or Cursor.

+4 this week 78 Trust /100

Recent critical change

Authorization (23 Sept 2026). See the changelog before you install this server.

Trust breakdown (7 categories)

How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →

Endpoint Security63
Transport & Reachability100
Schema Quality & AI Usability77
  • 100% of prompts and resources have a non-trivial description (not blank, and not just the item's name).Pass
  • AI-judged instruction clarity (excellent).Pass
  • Context-footprint check failed: tool/resource definitions use about 5246 tokens (~291/item across 18 items; 17 tools + 1 resources), over budget; trim descriptions and params. See how to fix → Fail
  • Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management77
  • Stability observed for 23 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage100
  • 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
  • 100% of tool parameters carry a description.Pass
Tool Safety100
  • No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
  • All 2 tool(s) whose name or description implies an irreversible operation declare an MCP destructiveHint annotation.Pass
  • An AI judge read all 18 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
  • Implements a current MCP spec version (2026-07-28).Pass
  • Supports UI / widget rendering.Pass
Install

How do I install the iHatePosting MCP server?

iHatePosting is a hosted endpoint at https://ihateposting.com/api/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.

remote · ihateposting.com

# add to Claude Code
claude mcp add --transport http com-ihateposting-mcp 'https://ihateposting.com/api/mcp'
// .cursor/mcp.json
{
  "mcpServers": {
    "com-ihateposting-mcp": {
      "url": "https://ihateposting.com/api/mcp"
    }
  }
}
// .vscode/mcp.json
{
  "servers": {
    "com-ihateposting-mcp": {
      "type": "http",
      "url": "https://ihateposting.com/api/mcp"
    }
  }
}
# ~/.codex/config.toml
[mcp_servers.com-ihateposting-mcp]
url = "https://ihateposting.com/api/mcp"
// opencode.json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "com-ihateposting-mcp": {
      "type": "remote",
      "url": "https://ihateposting.com/api/mcp",
      "enabled": true
    }
  }
}
# add to OpenClaw
openclaw mcp add com-ihateposting-mcp --url 'https://ihateposting.com/api/mcp' --transport streamable-http
# ~/.hermes/config.yaml
mcp_servers:
  com-ihateposting-mcp:
    url: "https://ihateposting.com/api/mcp"
// ~/.netclaw/config/netclaw.json
{
  "McpServers": {
    "com-ihateposting-mcp": {
      "Transport": "http",
      "Url": "https://ihateposting.com/api/mcp"
    }
  }
}
# add to Vellum
assistant mcp add com-ihateposting-mcp -t streamable-http -u 'https://ihateposting.com/api/mcp'
// mcp.json
{
  "mcpServers": {
    "com-ihateposting-mcp": {
      "type": "http",
      "url": "https://ihateposting.com/api/mcp"
    }
  }
}

The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.

Changelog

Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.

  • 4 Oct 26 0
    • Tool “reschedule_post” rewrote its description, which is the text the model reads security
    • Tool “retry_post” rewrote its description, which is the text the model reads security
    • Tool “update_post” rewrote its description, which is the text the model reads security
    • Tool “validate_post” rewrote its description, which is the text the model reads security
    • Tool “whoami” rewrote its description, which is the text the model reads security
    • Tool “create_post” rewrote its description, which is the text the model reads security
    • Tool “delete_post” rewrote its description, which is the text the model reads security
    • Tool “get_platform_rules” rewrote its description, which is the text the model reads security
    • Tool “get_post” rewrote its description, which is the text the model reads security
    • Tool “get_upload_ticket” rewrote its description, which is the text the model reads security
    • Tool “list_accounts” rewrote its description, which is the text the model reads security
    • Tool “list_posts” rewrote its description, which is the text the model reads security
    • Schema quality: 194 → 291 ▼ functional
    • Server version: 0.10.0 → 0.11.0 functional
    • “validate_post” added an optional parameter “options” cosmetic
    • “validate_post” added an optional parameter “overrides” cosmetic
    • “list_posts” reworded the description of “cursor” cosmetic
    • “list_posts” reworded the description of “from” cosmetic
    • “list_posts” reworded the description of “to” cosmetic
    • “reschedule_post” reworded the description of “scheduledDate” cosmetic
    • “validate_post” reworded the description of “scheduledTime” cosmetic
    • “reschedule_post” reworded the description of “scheduledTime” cosmetic
    • “update_post” reworded the description of “options” cosmetic
    • “update_post” reworded the description of “scheduledDate” cosmetic
    • “update_post” reworded the description of “scheduledTime” cosmetic
    • “validate_post” reworded the description of “action” cosmetic
    • “create_post” reworded the description of “action” cosmetic
    • “create_post” reworded the description of “options” cosmetic
    • “create_post” reworded the description of “scheduledDate” cosmetic
    • “create_post” reworded the description of “scheduledTime” cosmetic
    • Tool “get_upload_ticket” changed its title: Get a one-time upload ticket → Get a short-lived upload ticket cosmetic
  • 3 Oct 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 70 to 73. That category is still filling its 30-day observation window: 21 days of observed history at the previous scan, 22 at this one. The score rises as the window fills, whether or not the server changes.

  • 2 Oct 26 0
    • MCP protocol: Implements a current MCP spec version (2026-07-28). functional
    • MCP protocol version: 2025-11-25 → 2026-07-28 functional
    • Server version: 0.9.2 → 0.10.0 functional
  • 1 Oct 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 63 to 67. That category is still filling its 30-day observation window: 19 days of observed history at the previous scan, 20 at this one. The score rises as the window fills, whether or not the server changes.

  • 29 Sept 26 0
    • Tool “whoami” rewrote its description, which is the text the model reads security
    • Tool “list_accounts” rewrote its description, which is the text the model reads security
    • Server version: 0.9.1 → 0.9.2 functional
  • 28 Sept 26 +2
    • We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
  • 27 Sept 26 +1

    No change was recorded against any check on this day. Stability & Change Management went from 50 to 53. That category is still filling its 30-day observation window: 15 days of observed history at the previous scan, 16 at this one. The score rises as the window fills, whether or not the server changes.

  • 26 Sept 26 0
    • Server version: 0.5.0 → 0.6.0 functional
Diagnostics

Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.

Captured 4 Oct 2026 · Probed https://ihateposting.com/api/mcp

TLS valid

Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .

Subject Issuer Valid from Valid until Key Signature Serial
CN=ihateposting.com CN=YE1,O=Let's Encrypt,C=US 21 Sept 2026 20 Dec 2026 ECDSA 384 ECDSA-SHA384 68fbdb96334a94384b9ddf42fc2214eeac4
SANs: ihateposting.com
CN=YE1,O=Let's Encrypt,C=US (CA) CN=Root YE,O=ISRG,C=US 3 Sept 2025 2 Sept 2028 ECDSA 384 ECDSA-SHA384 5ddd70dd31f801c85c186a7a04b80afe
CN=Root YE,O=ISRG,C=US (CA) CN=ISRG Root X2,O=Internet Security Research Group,C=US 13 May 2026 2 Sept 2032 ECDSA 384 ECDSA-SHA384 872165fc34b6e5fba8add5b3705fb53a
CN=ISRG Root X2,O=Internet Security Research Group,C=US (CA) CN=ISRG Root X1,O=Internet Security Research Group,C=US 13 May 2026 2 Sept 2032 ECDSA 384 SHA256-RSA 6c8f1dc727c7117f7baf853ac980f9cd

Background: What to check on a remote MCP endpoint →

DNSSEC insecure

Validation of ihateposting.com. — Not signed

Zone DS Keys Algorithms Outcome
. trust_anchor 20326, 38696 8, 8 Verified
com. present 19718 13 Verified
ihateposting.com. absent Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation
Authentication No authorisation required

The endpoint answered without asking for a token. Anyone who knows the URL can reach it.

Result No authorisation required
HTTP status 200
Header Value
strict-transport-security max-age=63072000; includeSubDomains; preload
content-security-policy frame-ancestors 'none'; base-uri 'self'; object-src 'none'; form-action 'self'
x-content-type-options nosniff
x-frame-options DENY
referrer-policy strict-origin-when-cross-origin
permissions-policy camera=(), microphone=(), geolocation=(), browsing-topics=()

Background: How OAuth 2.1 works in the 2026 MCP spec →

Transports 2 probes
Transport URL Outcome Status Location
streamable-http https://ihateposting.com/api/mcp Verified 200
http (plaintext) http://ihateposting.com/api/mcp HTTPS enforced 301 https://ihateposting.com/api/mcp
MCP tools · 17 exposed · ~5,221 tokens

The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →

Tool Tokens
create_post ~747

Create a social post on iHatePosting. action 'draft' saves it (the default when no date is given, and the safe choice); 'schedule' needs scheduledDate (YYYY-MM-DD) + scheduledTime (e.g. '9:00 AM' or '21:00'), the account owner's wall clock in their timezone — `ownerTimezone` from whoami, not yours or the user's device; 'now' publishes immediately to a real audience. A date with any action but 'schedule', or with no action, is refused rather than dropped. Every `scheduledAt` in the reply is UTC (it ends in Z); `scheduledLocal` beside it is the same moment as the owner's date, time and timezone — tell the user that one. Platforms with requirements — Pinterest a board, YouTube a title, TikTok and Instagram media — are set through `options` and `mediaIds`; call get_platform_rules for what each one needs, and validate_post to check before you commit. The reply lists every send it created, each naming its account (handle, displayName, nickname) AND carrying its own `postId` — tell the user what it says rather than what you asked for; they are not always the same. Its `warnings` name anything the post will not carry (images past a platform's cap, a signed-out account, a Pro-only option) — pass them on. A SCHEDULED (or 'now') multi-platform post is stored as one post per send, so that `postId` is what cancels or reschedules a single platform later without touching the others. A draft keeps every platform on ONE postId (every send in the reply shows the same one) until it is scheduled with update_post — deleting that draft deletes it for every platform.

NameTypeReqDescription
actionstring–'draft' saves it; 'schedule' posts at scheduledDate + scheduledTime; 'now' publishes to a real audience at once. Left out with no date it is 'draft'; left out WITH a date it is refused — say 'schedul…
mediaIdsarray–Media library ids from list_media or upload_media, in attach order
optionsobject–Per-platform options, by their exact names — e.g. { pinterest: { boardId: '...' }, youtube: { ytTitle: '...', ytMadeForKids: false, ytPrivacy: 'unlisted' }, instagram: { firstComment: '#more #tags' }…
overridesobject–Different text for one platform, e.g. { x: 'a shorter version' }
platformsarrayyesWhere it goes. Either a platform name — bluesky, x, linkedin, facebook, threads, mastodon, telegram, discord, tumblr, slack, instagram, pinterest, tiktok, youtube — which targets EVERY account you ha…
scheduledDatestring–YYYY-MM-DD, with action 'schedule' only — the owner's calendar day
scheduledTimestring–e.g. '9:00 AM' or '21:00', with action 'schedule' only — the owner's wall clock in `ownerTimezone` from whoami
textstringyesThe post text

No output schema declared.

No examples provided.

delete_post ~389

Delete a post from iHatePosting. ONE SEND AT A TIME: a SCHEDULED post going to several accounts is stored as one post PER SEND, so deleting one cancels only that platform and leaves the rest scheduled — pass the `postId` that create_post returned on that particular send, or the id of the row list_posts shows for it. There is no need to cancel a whole multi-platform post to drop one platform from it. A DRAFT IS DIFFERENT: until it is scheduled, a draft is ONE post holding every platform it is aimed at (all its sends share one postId), so deleting it removes every platform — to drop one platform from a draft, use update_post with the remaining accountIds instead. The reply's `platformsRemoved` names every platform the delete took; for one send of a group, `stillScheduled` lists the sends still going out and `otherSends` the rest of the group (already published or failed), each with its status; their `scheduledAt` is UTC (it ends in Z) and `scheduledLocal` is the same moment in the account owner's timezone — report that one. THIS DOES NOT UNPUBLISH ANYTHING: a post that has already gone out stays live on the network, and deleting it here only removes iHatePosting's record of it. For that reason a published post is refused unless you pass force: true, and you should only do that after telling the user in words that the platform post will remain. A post that is publishing at this moment is never deletable, forced or not — the worker is mid-flight on it. Deleting a scheduled post stops it going out.

NameTypeReqDescription
forceboolean–Required to delete a post that already published. The platform post stays live — say so before using this.
postIdstringyesPost id from list_posts

No output schema declared.

No examples provided.

get_analytics ~159

How the posts actually performed: impressions, engagement and follower numbers per connected channel, plus the top posts. Use this to answer 'how did that do', 'which platform is working' or 'what should I post more of' — it reports what iHatePosting collected from each network, not an estimate. Some platforms report nothing (they are named in `unmeasuredPlatforms`), so a zero there means 'not measurable', not 'no reach'. If a plan ever gates a range, the answer says so in a sentence with `locked: true` rather than returning silently empty numbers.

NameTypeReqDescription
rangestring–How far back to look. '12m' is a year; 'all' is everything we have recorded.

No output schema declared.

No examples provided.

get_platform_rules ~128

What each platform will and will not accept: character limit, whether media is required, how many images, video formats and length, and EVERY per-platform option it takes — `options` per platform, each with its exact key, type, allowed values, default when left out, and whether it is required (e.g. Pinterest needs boardId, YouTube needs ytTitle and ytMadeForKids; YouTube's privacy is ytPrivacy, Instagram's first comment is firstComment). Call this BEFORE writing a post — it is the difference between composing something that publishes and something the platform rejects.

Input schema present but exposes no named parameters.

No output schema declared.

No examples provided.

get_post ~140

Everything about ONE post: the shared text, each platform's own copy and options, the attached media, and per-send status with the live URL or the error. list_posts gives you the id; this explains what actually happened to it. Read it before update_post so you change what is there rather than overwriting it. Its `scheduledAt` is UTC (it ends in Z); `scheduledLocal` is the same moment as the owner's date, time and timezone — the values to send back as scheduledDate/scheduledTime to keep the time, and the ones to tell the user.

NameTypeReqDescription
postIdstringyesPost id from list_posts

No output schema declared.

No examples provided.

get_upload_ticket ~52

Internal: issues a short-lived ticket (10 minutes, reused by the upload box for its own requests) that the upload box uses to list, preview, upload and delete files. The upload box calls this itself.

Input schema present but exposes no named parameters.

No output schema declared.

No examples provided.

list_accounts ~85

List the connected social accounts (platform, handle, health) available for posting. The response also names the iHatePosting account this connection acts for — if the accounts listed are not the ones you expect, check that `account.email` is the right person before assuming anything is missing. `account.timezone` is the owner's timezone, the zone every scheduled time is read in.

Input schema present but exposes no named parameters.

No output schema declared.

No examples provided.

list_media ~101

The images and videos already in the user's iHatePosting library, newest first, with the `id` that create_post's `mediaIds` wants. Call this whenever a platform needs a file — Instagram, Pinterest, TikTok and YouTube all do — to see whether what you need is already uploaded. Returns ids and dimensions only; there is no downloadable link, by design.

NameTypeReqDescription
limitinteger–How many of the newest assets to return

No output schema declared.

No examples provided.

list_pinterest_boards ~149

The Pinterest boards you can pin to, with the `id` that create_post's `options.pinterest.boardId` requires. Pinterest REFUSES a pin without a board, and a board id is an opaque number you cannot guess — call this before creating any Pinterest post. If several Pinterest accounts are connected, pass `accountId` from list_accounts, because boards belong to one account and pinning to another account's board fails. An empty list with no error means the account is connected and simply has no boards yet — make one in Pinterest first.

NameTypeReqDescription
accountIdstring–Which Pinterest account's boards, from list_accounts. Omit to use the most recently connected one.

No output schema declared.

No examples provided.

list_posts ~527

List posts with per-platform status (draft/scheduled/published/failed) and live URLs. Rows sharing a `batchId` are ONE submission the person made to several accounts — report them as one post going to N places, not as N posts. ALWAYS CHECK `total` IN THE REPLY: it is the number of rows matching your filter, and `returned` is how many you got. If they differ you are holding one page, not the answer — page on with `cursor` until `hasMore` is false before you count anything or tell anyone a number. `total` counts ROWS: a scheduled post to several accounts is one row per platform (sharing a `batchId`), while a draft is one row however many platforms it has — so `total` is the number of sends, and the number of posts the person made is the rows with distinct `batchId`s (a row without one is a post on its own). A post you move LATER while paging can come round again on a later page — skip ids you have already handled; none are skipped. Use `status` and `from`/`to` to ask the real question instead of counting a page: for "how many are scheduled" pass status 'scheduled' and read `total` (sends); for a month or a date range pass from/to, which match the SCHEDULED time — a bare date is that whole day on the account owner's calendar, in the owner's timezone (the reply's `timezone`, `ownerTimezone` from whoami). Each post's `scheduledAt` is UTC (it ends in Z); `scheduledLocal` is the same moment as the owner's date and time — report that one, and send it back unchanged to reschedule_post or update_post.

NameTypeReqDescription
cursorstring–`nextCursor` from the previous reply, exactly as given — with the same status/from/to. Keep going while `hasMore` is true.
fromstring–Earliest SCHEDULED time, 'YYYY-MM-DD' or an ISO timestamp. Inclusive; a bare date means that whole day in the account owner's timezone.
limitinteger–Posts per page, default 50, max 200.
statusstring–Only posts in this state. For a count, set this and read `total` — do not count the page.
tostring–Latest SCHEDULED time, same formats. Inclusive of that whole day, in the account owner's timezone, when given as a date.

No output schema declared.

No examples provided.

open_upload_widget ~187

Show the person their iHatePosting media box: they can upload an image or video from their own device, browse what is already in their library with every file previewable, see how much storage their plan leaves them, pick a file to use, or delete one. THIS IS THE ANSWER WHENEVER SOMEONE NAMES A FILE ON THEIR OWN COMPUTER — a path like C:\clips\launch.mp4 or ~/Movies/clip.mov is not something any tool here can read, and explaining that is not an answer: open this instead, in the same reply, and they pick the file from a picker right in the conversation. Also use it for anything they pasted or attached here. Do NOT try to send those bytes yourself — they would travel as your own output and arrive cut short. If the file already has a public address, use upload_media with `url` instead.

Input schema present but exposes no named parameters.

No output schema declared.

No examples provided.

reschedule_post ~314

Move a SCHEDULED post to a different date and time. ONE SEND AT A TIME: a scheduled post going to several accounts is stored as one post per send, so this moves just that platform and leaves the others where they are (an older row can still carry several platforms, and moves them together). A draft is refused: schedule a draft with update_post with action 'schedule', which checks each platform first and gives each its own post. Takes the post id from list_posts, plus scheduledDate (YYYY-MM-DD) and scheduledTime (e.g. '9:00 AM') read in the ACCOUNT OWNER'S timezone (`ownerTimezone` from whoami), not yours or the user's device. A post's `scheduledAt` is UTC (it ends in Z) — never copy its digits as a time; work from `scheduledLocal` (the owner's date and time) that list_posts and get_post give beside it, so 'an hour later' is an hour later. The reply's `scheduledLocal` is where the post now is. A post that has already published cannot be moved — its time is a record of what happened — and one that is publishing right now is refused until it finishes.

NameTypeReqDescription
postIdstringyesPost id from list_posts
scheduledDatestringyesYYYY-MM-DD, the owner's calendar day
scheduledTimestringyese.g. '9:00 AM' or '21:00', the owner's wall clock in `ownerTimezone`

No output schema declared.

No examples provided.

retry_post ~269

Send a failed post again. ONE SEND AT A TIME, usually: a post to several accounts is stored as one post per send, so a post id normally names a single platform and retrying it touches only that one. (An older row, or a draft, can still carry several — without targetId every failed platform on that row is retried; with one, only that send.) Only a send that FAILED is retried — one that published is left alone. But a send marked failed can already be live (a timeout after the network took the post), so after a timeout check the platform before retrying. A send our own checks SKIPPED is not retried — the answer says why, and update_post is the fix. If the cause was the account rather than the post (a revoked or paused connection) the answer says so, and retrying will not help until the user reconnects. The reply's `retried` counts what went back on the queue and `skipped` names every send it left behind, with the reason.

NameTypeReqDescription
postIdstringyesPost id from list_posts
targetIdstring–Retry ONE platform's send, if you already hold that send's id. Omit it to retry every failed send on the post.

No output schema declared.

No examples provided.

update_post ~690

Rewrite a draft or scheduled post. THIS REPLACES THE WHOLE POST, so read it with get_post first and send back the complete set — anything you leave out is removed, including platforms and per-platform options. Note the shape differs from create_post: this one wants `accountIds` (the ids from list_accounts, NOT platform names) and it requires `action`. Two limits: a post that has already published cannot be rewritten at all, and a post that goes to several platforms and was saved as a group keeps the platforms it has — send back that row's own accountIds and everything else is editable, but adding or swapping an account is refused with a sentence saying so, because it would publish some platforms twice. To change which platforms a group posts to, delete it and create it again. A draft is not a group: to drop one platform from a draft, send it back without that account. SCHEDULING A DRAFT that goes to several platforms (action 'schedule' or 'now') turns it into one post per platform: the reply's `rows` lists every `postId` with its platforms, and the id you sent now names only its first platform — use the others' ids to move, cancel or retry them. A post that is being published right now cannot be edited; the answer says so — wait for it to finish. Like create_post, its reply's `warnings` name anything the post will not carry — pass them on. TIMES: scheduledDate/scheduledTime are the owner's wall clock (`ownerTimezone` from whoami); to keep a scheduled post's time, send back get_post's `scheduledLocal.date` and `scheduledLocal.time` — never the digits of its UTC `scheduledAt`. A date with an action other than 'schedule' is refused. The reply's `scheduledAt` (UTC) and `scheduledLocal` say when it now goes out.

NameTypeReqDescription
accountIdsarrayyesThe FULL set of destination account ids, from list_accounts. Account IDS, not platform names. Anything omitted is removed from the post.
actionstringyes'draft' keeps it unscheduled, 'schedule' needs the date and time below, 'now' publishes to a real audience.
baseContentstringyesThe shared text. REQUIRED — it replaces what is there.
mediaIdsarray–Ids from list_media or upload_media, in attach order
optionsobject–Per-platform options, by their exact names — e.g. { pinterest: { boardId: '...' }, youtube: { ytTitle: '...', ytMadeForKids: false }, instagram: { firstComment: '#more #tags' } }. get_platform_rules…
overridesobject–Different text for one platform
postIdstringyesPost id from list_posts
scheduledDatestring–YYYY-MM-DD, the owner's calendar day (schedule only)
scheduledTimestring–e.g. '9:00 AM' or '21:00', the owner's wall clock in `ownerTimezone` (schedule only)

No output schema declared.

No examples provided.

upload_media ~476

Put an image or video into the library and get back an id for create_post. PREFER `url` — ALWAYS, including for a picture you just generated: we fetch it ourselves at full length, and it is the only thing that works for video or for anything more than a few kilobytes. We take whatever the link serves, so a CDN that will not name the type (application/octet-stream, as presigned S3, Drive and Dropbox links do) is fine. `base64` is a last resort for small files that exist at no address: it travels as your own output, a conversation truncates it, and the cut-off file is refused. Either way the API checks type, size and quota, then registers the file.

NameTypeReqDescription
altTextstring–Alt text. Worth writing — several networks publish it.
base64string–The file's bytes, base64. A data: prefix is stripped. LAST RESORT, and small files only. Everything here becomes YOUR OWN OUTPUT, and a long string of it gets cut short on the way — the file then arr…
filenamestring–e.g. 'launch-photo.jpg' — the library label. Optional with `url`, where the link's own name is used.
mimestring–e.g. 'image/jpeg', 'image/png', 'video/mp4'. Required with `base64`; with `url` the server's own content type decides.
urlstring–Public https link to the file ITSELF, not to a page showing it. We download it. Use this whenever the file has an address. A path on the person's own computer is NOT a link — nothing here can read th…

No output schema declared.

No examples provided.

validate_post ~686

Check a post against every platform you plan to send it to, WITHOUT creating anything. Runs the same checks create_post runs, so the answer is what will really happen: platform rules ('X counts this as 1200/280 characters', 'YouTube needs a title', 'TikTok slideshows take JPEG or WebP photos'), whether each account is connected and signed in, AND the account's own limits — trial expiry, whether the plan includes X, and the monthly posting allowances. Pass the same `action`/`scheduledDate`/`scheduledTime` you will pass to create_post: a cap counts the month the post is DUE, so checking without them answers a different question — and with no action it checks what create_post would make of no action, a draft, which no limit applies to. scheduledDate/scheduledTime are the account owner's wall clock in their timezone (`ownerTimezone` from whoami), and a date with an action other than 'schedule' is refused, as create_post refuses it. Anything not tied to one platform comes back under the key "account". It takes create_post's own `platforms` (names), `options`, `overrides` and `mediaIds`, so hand it exactly what you will hand create_post. `ok` is false only when something would stop the post; an issue with severity 'warn' (an image that will be cropped, images past a platform's cap) is worth telling the user but does not. Free to call as often as you like; use it before create_post rather than discovering a problem after the post is spent.

NameTypeReqDescription
actionstring–What you will ask create_post for. Left out, it is read as create_post reads it: 'draft' when no date is given (a draft skips the limits, because it costs nothing), and refused when a date is given.…
mediaIdsarray–Media library ids from list_media or upload_media, in attach order
optionsobject–Per-platform options in create_post's shape, by their exact names — e.g. { youtube: { ytTitle: '...', ytMadeForKids: false } }. get_platform_rules lists every option per platform with its type and al…
overridesobject–Different text for one platform, as create_post takes it, e.g. { x: 'a shorter version' }. A target's own `contentOverride` wins.
platformsarray–Shorthand for targets. PLATFORM NAMES ONLY — an account id belongs in create_post, not here. Use this OR `targets`.
scheduledDatestring–YYYY-MM-DD, with action 'schedule'. The monthly limits count the month the post is DUE, so this changes the answer.
scheduledTimestring–e.g. '9:00 AM' or '21:00' (with action 'schedule'), the account owner's wall clock in `ownerTimezone` from whoami
targetsarray–Platforms with their per-platform options. Use this OR `platforms`.
textstringyesThe post text

No output schema declared.

No examples provided.

whoami ~122

Which iHatePosting login this connection acts for (email and account name), whether it connected by signing in or with an API key, and the account owner's timezone (`ownerTimezone`) — the zone every scheduledDate/scheduledTime you send is read in. Use this for any question about who the user is or which account is connected, and before working out a time like 'tomorrow at 9' or 'in two hours'. This is NOT a social media handle — the handles from list_accounts belong to the connected profiles, which may carry other people's names.

Input schema present but exposes no named parameters.

No output schema declared.

No examples provided.

Common questions

What is the iHatePosting MCP server?

iHatePosting is an MCP server listed in the public MCP registry as com.ihateposting/mcp. Draft, check and schedule posts to your connected social accounts from Claude, ChatGPT or Cursor. This page covers its hosted endpoint (https://ihateposting.com/api/mcp).

Is the iHatePosting MCP server safe to use?

iHatePosting scores 78 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.

What tools does the iHatePosting MCP server expose?

iHatePosting exposes 17 tools: open_upload_widget, get_upload_ticket, whoami, get_platform_rules, validate_post, and 12 more. Their descriptions and schemas cost roughly 5,221 tokens of context every time the server is loaded.

Does the iHatePosting MCP server require authentication?

No. We connected to iHatePosting without credentials and it answered, so anything it exposes is reachable by anyone who knows the address.

Is the iHatePosting MCP server still maintained?

iHatePosting is still listed as active in the MCP registry. We last reached this channel on 4 October 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.