# Markaestro (npm · @markaestro/mcp)

Schedule, publish, and review social posts and analytics for a Markaestro brand.

- Trust score: 70/100 (medium)
- Registry status: active
- Liveness: live
- Owner verified: no
- Last scored: 2026-09-28

## Components

- remote · `markaestro.com`: 38/100, [markdown](https://verifymcp.io/servers/com-markaestro-mcp/api-public-v1-mcp.md), [page](https://verifymcp.io/servers/com-markaestro-mcp/api-public-v1-mcp)
- npm · `@markaestro/mcp`: 70/100 (this document), [markdown](https://verifymcp.io/servers/com-markaestro-mcp/markaestro-mcp.md), [page](https://verifymcp.io/servers/com-markaestro-mcp/markaestro-mcp)

## Channel facts

- Registry: `npm`
- Package: `@markaestro/mcp`
- Version: `0.3.3`
- Transport: `stdio`

## Trust breakdown

How this component scores in each security and reliability category. Every signal is checked automatically from public evidence about the published package, including repeated runs of it in an isolated sandbox, and we only credit what we can confirm. Scores are 0–100 per category. Scoring method: https://verifymcp.io/docs/scoring (what has changed: https://verifymcp.io/docs/scoring/changelog)

Scored 2026-09-28.

- **Supply Chain Security**: 98/100
  - No malware found by supply-chain analysis.
  - No known CVEs affecting this package version or its production dependencies.
  - No install/post-install scripts declared.
  - 31 of 92 dependencies flagged as unhealthy.
- **Provenance & Transparency**: 45/100
  - Source repository is publicly reachable at the declared URL.
  - Provenance check failed: no build-provenance attestation is published.
  - Clear OSI-approved license (MIT).
  - Actively maintained (last published 0 days ago).
  - Disclosure check failed: no security disclosure policy was found in the source repository.
- **Schema Quality & AI Usability**: 85/100
  - 100% of prompts and resources have a non-trivial description (not blank, and not just the item's name).
  - AI-judged instruction clarity (good).
  - Tool/resource definitions use about 3523 tokens (~100/item across 35 items; 34 tools + 1 resources), lean.
  - Usage-examples check failed: none of the tools include examples.
- **Stability & Change Management**: 0/100
  - Stability not yet verified: not enough scan history yet (needs a 30-day window).
- **Tool Coverage**: 82/100
  - 100% of tools have a non-trivial description (not blank, and not just the tool's name).
  - 47% of tool parameters carry a description.
- **Tool Safety**: 100/100
  - No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.
  - All 2 tool(s) whose name or description implies an irreversible operation declare an MCP destructiveHint annotation.
  - An AI judge read all 36 captured unit(s) of tool text and found none that tries to manipulate the model reading it.
- **Capabilities**: 100/100
  - Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.

**Unverified: 1 category.** A category scored 0 because we could not verify it: a data source with nothing on this package, evidence we could not reach, or a check we could not run. We only credit what we can confirm.

## Install

### How do I install the Markaestro MCP server?

Markaestro runs locally as an npm package, launched with npx -y @markaestro/mcp. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.

### Claude

```bash
claude mcp add com-markaestro-mcp -- npx -y @markaestro/mcp
```

### Cursor

```json
{
  "mcpServers": {
    "com-markaestro-mcp": {
      "command": "npx",
      "args": [
        "-y",
        "@markaestro/mcp"
      ]
    }
  }
}
```

### VS Code

```json
{
  "servers": {
    "com-markaestro-mcp": {
      "command": "npx",
      "args": [
        "-y",
        "@markaestro/mcp"
      ]
    }
  }
}
```

### Codex

```bash
codex mcp add com-markaestro-mcp -- npx -y @markaestro/mcp
```

### opencode

```json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "com-markaestro-mcp": {
      "type": "local",
      "command": [
        "npx",
        "-y",
        "@markaestro/mcp"
      ],
      "enabled": true
    }
  }
}
```

### OpenClaw

```bash
openclaw mcp add com-markaestro-mcp --command npx --arg -y --arg @markaestro/mcp
```

### Hermes

```yaml
mcp_servers:
  com-markaestro-mcp:
    command: "npx"
    args: ["-y", "@markaestro/mcp"]
```

### Netclaw

```json
{
  "McpServers": {
    "com-markaestro-mcp": {
      "Transport": "stdio",
      "Command": "npx",
      "Arguments": [
        "-y",
        "@markaestro/mcp"
      ]
    }
  }
}
```

### Vellum

```bash
assistant mcp add com-markaestro-mcp -t stdio -c npx -a -y @markaestro/mcp
```

### Other

```json
{
  "mcpServers": {
    "com-markaestro-mcp": {
      "command": "npx",
      "args": [
        "-y",
        "@markaestro/mcp"
      ]
    }
  }
}
```

## Changelog

Every change recorded for this component, newest first. Days that predate change tracking, or that we cannot explain, say so: "we were watching and nothing happened" and "we were not watching" are different claims.

### 2026-09-28 (score 70, 0)

- [functional] We updated how we score, so this day's move reflects our rubric, not a change to the server

### 2026-09-27 (score 70, +32)

- [security improvement] Injection markers: unverified → pass
- [security] First check of Judged manipulation: pass
- [security] Stability: Stability not yet verified: not enough scan history yet (needs a 30-day window).
- [security] Tool safety: Tool safety not yet verified: we do not have a sandbox capture of the tool definitions this version of the package serves yet.
- [security] Stability: Stability not yet verified: we do not have a sandbox capture of the MCP schema this version of the package serves yet.
- [functional regression] Security disclosure: unverified → fail
- [functional improvement] Tool coverage: unverified → 100
- [functional improvement] MCP protocol: unverified → pass
- [functional improvement] Schema quality: unverified → 100
- [functional] First check of Schema quality: pass
- [functional] First check of Schema quality: fail
- [functional] First check of Tool coverage: 47
- [functional] First check of Destructive annotations: 100
- [functional] First check of Schema quality: good
- [functional] Capabilities: Protocol version not yet verified: we do not have a sandbox capture of the MCP handshake this version of the package performs yet.
- [functional] Tool coverage: Tool coverage not yet verified: we do not have a sandbox capture of the tool definitions this version of the package serves yet.
- [functional] Schema quality: Schema quality not yet verified: we do not have a sandbox capture of the MCP schema this version of the package serves yet.
- [functional] Package version: 0.3.2 → 0.3.3

### 2026-09-26 (score 38, 0)

- [functional regression] Security disclosure: fail → unverified

### 2026-09-25 (score 38, +10)

- [functional] We updated how we score, so this day's move reflects our rubric, not a change to the server

### 2026-09-24 (score 28)

First indexed and scored.

## MCP tools (34)

### `list_products` (~61 tokens)

List brands

List the brands (products) this connection can act on, with their connected channels: one brand for a single-brand connection, every brand in the workspace for an all-brands one. Call this first to learn each productId and which channels can be posted to.

### `list_destinations` (~67 tokens)

List destinations

List the publishable destinations (Facebook Page, Instagram account, TikTok account, ...) of a brand, with their ids and delivery modes. Use a destinationId on create_post only when a channel has more than one destination.

Input parameters:

- `productId` (string, required): Brand id from list_products

### `get_brand_profile` (~57 tokens)

Get a brand profile

A brand's description, website, categories, voice, and visual identity as set in Markaestro. Read it before writing captions so they sound like the brand. Read-only.

Input parameters:

- `productId` (string, required): Brand id from list_products

### `list_posts` (~125 tokens)

List posts

List posts, newest first. Filter by status: draft, scheduled, publishing, published, platform_action_required, failed, partial_failed. On an all-brands connection, pass productId to list one brand. Use cursor from a previous page to continue.

Input parameters:

- `cursor` (string)
- `limit` (integer): Default 25, max 100
- `productId` (string): Brand id from list_products. Required when this connection covers all brands in the workspace; a single-brand connection always uses its own brand and may omit it.
- `status` (string)

### `get_post` (~38 tokens)

Get a post

Fetch one post with its targets, status, media, schedule, publish results, and live URL when published.

Input parameters:

- `postId` (string, required)

### `update_post` (~170 tokens)

Edit a draft or scheduled post

Change a draft or scheduled post: its caption, its media, one channel's settings (settings.__type names the channel), or, for a scheduled post, its time. Omitted fields stay as they are. Every change is checked against the rules of every channel the post targets, and a scheduled post must still be publishable afterwards. Published and failed posts cannot be edited. Channels are fixed once a post exists; to post somewhere else, create a new post.

Input parameters:

- `caption` (string)
- `mediaAssetIds` (array): Replaces the post's media, in display order
- `postId` (string, required)
- `scheduledAt` (string): New time for a scheduled post
- `settings` (object): One channel's platform settings, with __type equal to that channel

### `create_post` (~306 tokens)

Create a post

Create a post for this brand. Without scheduledAt the post is saved as a DRAFT and nothing is published; with scheduledAt it is scheduled and the worker publishes it at that time. Pass either a single channel or a targets array (one entry per channel). Upload media first with upload_media and pass the asset ids. Read channel rules with get_channel_rules before posting.

Input parameters:

- `caption` (string): Post text. Required on linkedin.
- `channel` (string): Single channel. Mutually exclusive with targets.
- `deliveryMode` (string): direct_publish: official platform API. manual_reminder: a timed reminder for a person to post natively (default on facebook, instagram, tiktok). platform_inbox: TikTok inbox handoff. Required when sc…
- `destinationId` (string): For the single-channel form, when the brand has several destinations on that channel.
- `mediaAssetIds` (array): Asset ids from upload_media or list_media, in display order.
- `productId` (string): Brand id from list_products. Required when this connection covers all brands in the workspace; a single-brand connection always uses its own brand and may omit it.
- `scheduledAt` (string): Omit to save a draft.
- `settings` (object): Platform settings for the single-channel form; __type must equal channel.
- `targets` (array): Several channels at once, each with its own destination and delivery mode.

### `publish_post` (~73 tokens)

Publish a post now

Queue an immediate publish of a draft post. Returns a job run; poll get_job_run until status is succeeded or failed. For manual_reminder targets this queues a reminder for a person instead of calling the platform. The post goes public on the platform as soon as the run succeeds.

Input parameters:

- `postId` (string, required)

### `mark_post_posted` (~88 tokens)

Mark a post as posted

Record that a person has posted a manual-reminder or TikTok-inbox post natively, which moves it from platform_action_required to published. Only for posts in platform_action_required that the user has already posted themselves. Nothing is sent to any platform.

Input parameters:

- `externalUrl` (string): Link to the live post, if the user has it
- `postId` (string, required)

### `delete_post` (~77 tokens)

Delete a draft or cancel a post

Delete a draft, or cancel a scheduled, failed, or waiting-to-be-posted post before it reaches any platform. Published posts cannot be deleted or taken down from here: that stays with the user in Markaestro. Posts mid-publish cannot be deleted until the run settles.

Input parameters:

- `postId` (string, required): A Markaestro post id

### `bulk_posts` (~88 tokens)

Reschedule or restatus posts

Apply one action to up to 25 posts: reschedule (needs scheduledAt), or status (draft or scheduled). Per-post failures are reported individually. To remove posts, use delete_post on each draft.

Input parameters:

- `action` (string, required)
- `ids` (array, required)
- `scheduledAt` (string): Required for reschedule
- `status` (string): Required for the status action

### `create_posts` (~68 tokens)

Create several posts

Create up to 25 posts in one call, for example a week of scheduled content. Each item takes the same fields as create_post. Failures are per item: the response lists ok/error for each, and the successful ones are created even when others fail.

Input parameters:

- `posts` (array, required)

### `preview_evergreen_queue` (~44 tokens)

Preview Evergreen eligibility

Check whether a published post has mature measured performance and get a recommended Evergreen cadence. This does not create or schedule anything.

Input parameters:

- `sourcePostId` (string, required)

### `list_evergreen_queues` (~32 tokens)

List Evergreen queues

List this brand's Intelligent Evergreen queues and their activation evidence, cadence, next run, and status.

### `get_evergreen_queue` (~29 tokens)

Get an Evergreen queue

Get one Intelligent Evergreen queue including its caption variants.

Input parameters:

- `queueId` (string, required)

### `create_evergreen_queue` (~225 tokens)

Create an Evergreen queue

Create a draft Evergreen queue from an eligible published post. Creation does not activate it or schedule anything; activate_evergreen_queue does that separately.

Input parameters:

- `channels` (array)
- `contentConfirmed` (boolean): True records that the user has reviewed every caption variant and confirmed the captions are accurate and still true. Activating or resuming a queue requires this confirmation.
- `expiresAt` (string): ISO 8601 UTC timestamp, for example 2026-09-10T14:00:00Z
- `intervalDays` (integer)
- `localHour` (integer)
- `localMinute` (integer)
- `name` (string, required)
- `productId` (string): Brand id from list_products. Required when this connection covers all brands in the workspace; a single-brand connection always uses its own brand and may omit it.
- `reviewPolicy` (string)
- `scheduleMode` (string)
- `sourcePostId` (string, required)
- `timeZone` (string)
- `variants` (array, required)

### `update_evergreen_queue` (~175 tokens)

Update an Evergreen queue

Update a queue's cadence, review policy, expiry, name, or full caption-variant set. Pass the current version from get_evergreen_queue; a stale version is rejected so concurrent edits are not overwritten.

Input parameters:

- `contentConfirmed` (boolean): True records that the user has reviewed every caption variant and confirmed the captions are accurate and still true. Activating or resuming a queue requires this confirmation.
- `expiresAt`
- `intervalDays` (integer)
- `localHour` (integer)
- `localMinute` (integer)
- `name` (string)
- `queueId` (string, required)
- `reviewPolicy` (string)
- `scheduleMode` (string)
- `timeZone` (string)
- `variants` (array)
- `version` (integer, required)

### `activate_evergreen_queue` (~66 tokens)

Activate an Evergreen queue

Activate a draft or paused queue. This schedules future public posts. The user must have confirmed the caption variants (contentConfirmed on create_evergreen_queue or update_evergreen_queue); otherwise this answers EVERGREEN_CONTENT_REVIEW_REQUIRED.

Input parameters:

- `queueId` (string, required)

### `pause_evergreen_queue` (~32 tokens)

Pause an Evergreen queue

Pause a queue and unschedule any pending occurrence generated by it.

Input parameters:

- `queueId` (string, required)

### `resume_evergreen_queue` (~33 tokens)

Resume an Evergreen queue

Resume a paused queue and compute its next occurrence from the current time.

Input parameters:

- `queueId` (string, required)

### `list_evergreen_runs` (~30 tokens)

List Evergreen runs

List the generated occurrences and evaluation outcomes for a queue.

Input parameters:

- `queueId` (string, required)

### `get_evergreen_analytics` (~50 tokens)

Get Evergreen analytics

Get source metrics, queue-lifetime metrics, tracked clicks, attributed conversions, and recent run outcomes. Unavailable provider metrics are null, not zero.

Input parameters:

- `queueId` (string, required)

### `get_analytics` (~304 tokens)

Get brand analytics

Performance over a window for the connection's brand, or on an all-brands connection for the workspace or the one brand named by productId: totals with the prior period for deltas, per-channel rollups, daily series, engagement breakdown, follower trend, top posts, posting-time heatmap, content-type averages, computed insights, and coverage. Covers the whole account: posts published through Markaestro and posts published directly on the platform (discovered from the connected account); coverage.bySource says how many of each. Read this before recommending what, when, or where to post. The window is clamped to the plan's history (the response reports maxDays). Unavailable provider metrics are null, not zero.

Input parameters:

- `channel` (string): Restrict every number to one channel
- `days` (integer): Preset window ending today (UTC); default 28
- `productId` (string): One brand, on an all-brands connection; omit for the whole workspace. A single-brand connection always reports its own brand.
- `since` (string): Explicit range start, YYYY-MM-DD (UTC); needs until
- `source` (string): Only posts published through Markaestro, or only posts published directly on the platform; omit for the whole account
- `tz` (integer): Viewer timezone offset in minutes east of UTC; shapes the heatmap only
- `until` (string): Explicit range end, YYYY-MM-DD (UTC), inclusive

### `list_post_analytics` (~308 tokens)

List post analytics

Every post in the window (the connection's brand, or on an all-brands connection the workspace or the brand named by productId) with its latest metrics (views, reach, likes, comments, shares, saves, clicks, engagements, engagement rate), one row per post, sorted. Includes posts published directly on the platform; each row's source says markaestro or native (canTakeDown is informational: taking a live post down is done by the user in Markaestro, not by delete_post). Use sort=engagements or sort=views to find what worked; sort=published_at (default) for a chronological read. Pair with get_post for the full caption and media of a Markaestro post (native posts have externalUrl instead).

Input parameters:

- `channel` (string)
- `days` (integer): Preset window ending today (UTC); default 28
- `limit` (integer): Default 100
- `productId` (string): One brand, on an all-brands connection; omit for the whole workspace. A single-brand connection always reports its own brand.
- `since` (string): Explicit range start, YYYY-MM-DD (UTC); needs until
- `sort` (string): Descending; default published_at
- `source` (string): Only posts published through Markaestro, or only posts published directly on the platform; omit for the whole account
- `until` (string): Explicit range end, YYYY-MM-DD (UTC), inclusive

### `get_post_analytics_history` (~123 tokens)

Get post analytics history

How one post earned its numbers over time: the metric snapshots taken 1h, 6h, 24h, 72h, 7d, 14d, 30d, 60d, and 90d after publish (a post published directly on the platform starts with a discovered snapshot), with the growth between stages, plus the current totals and whether polling is still active. Takes any id from get_analytics or list_post_analytics. Answers NOT_FOUND for posts outside this brand.

Input parameters:

- `postId` (string, required)

### `refresh_analytics` (~120 tokens)

Refresh analytics from the platforms

Pull live metrics from the platforms now instead of waiting for the next scheduled poll: posts in the window (optionally one channel, or one brand on an all-brands connection) and today's follower counts. The answer says how many posts were updated and how many remain, since a large window may take more than one refresh. Limited to a few calls a minute.

Input parameters:

- `channel` (string)
- `days` (integer): Window ending now; default 28
- `productId` (string): One brand, on an all-brands connection

### `suggest_post_times` (~88 tokens)

Suggest times to post

When this brand's audience responds best, learned by Markaestro Intelligence from the brand's own post history (not an industry table). timing is null until there is enough history; readiness says how much there is. Use it to pick scheduledAt. Needs a plan with Intelligence.

Input parameters:

- `productId` (string): Required on an all-brands connection; a single-brand connection uses its own brand

### `upload_media` (~101 tokens)

Upload media

Upload an image or video from a local file path, an http(s) URL, or a data: URL. Returns the media asset; pass its id in create_post mediaAssetIds. Counts against the workspace's monthly upload quota.

Input parameters:

- `contentType` (string): Inferred from the file extension or URL when omitted
- `fileName` (string)
- `source` (string, required): Local file path, http(s) URL, or data: URL

### `list_media` (~48 tokens)

List media

List uploaded media assets with their ids, type, dimensions, and how many posts reference them.

Input parameters:

- `cursor` (string)
- `limit` (integer)
- `type` (string)

### `get_media` (~37 tokens)

Get a media asset

Fetch one media asset: type, dimensions, processing state, thumbnail, and how many posts reference it.

Input parameters:

- `assetId` (string, required)

### `get_job_run` (~44 tokens)

Get a publish run

Check the status of a publish run returned by publish_post: queued, running, succeeded, or failed, with the message and details.

Input parameters:

- `runId` (string, required)

### `list_job_runs` (~59 tokens)

List publish runs

List recent publish runs, optionally filtered by status or by the post id (resourceId).

Input parameters:

- `cursor` (string)
- `limit` (integer)
- `resourceId` (string): A post id
- `status` (string)

### `get_channel_rules` (~39 tokens)

Channel rules

The per-channel media, caption, and delivery-mode rules the API enforces, plus the draft-then-publish model. Read before creating posts.

### `get_tiktok_posting_options` (~103 tokens)

Get TikTok posting options

The connected TikTok creator's live posting options: allowed privacy levels, whether comments, duets, and stitches can be enabled, and the longest video. TikTok requires a Direct Post to use these, so read them right before building one and pass the chosen privacyLevel in the tiktok settings. Test keys get a sandbox answer.

Input parameters:

- `productId` (string): On an all-brands connection, the brand whose TikTok account to ask about

## Diagnostics

Captured diagnostic sections: Provenance, Dependencies. The full working is on the page: https://verifymcp.io/servers/com-markaestro-mcp/markaestro-mcp#diagnostics

## Score history

- 2026-09-28: 70
- 2026-09-27: 70
- 2026-09-26: 38
- 2026-09-25: 38
- 2026-09-24: 28

## Common questions

### What is the Markaestro MCP server?

Markaestro is an MCP server listed in the public MCP registry as com.markaestro/mcp. Schedule, publish, and review social posts and analytics for a Markaestro brand. This page covers its npm package (@markaestro/mcp).

### Is the Markaestro MCP server safe to use?

Markaestro scores 70 out of 100 on VerifyMCP. We found no known CVEs affecting it as of 28 September 2026. It declares no install or post-install scripts. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.

### What tools does the Markaestro MCP server expose?

Markaestro exposes 34 tools: list_products, list_destinations, get_brand_profile, list_posts, get_post, and 29 more. Their descriptions and schemas cost roughly 3,308 tokens of context every time the server is loaded.

### Is the Markaestro MCP server still maintained?

Markaestro is still listed as active in the MCP registry. We last reached this channel on 28 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.

### What licence is the Markaestro MCP server under?

Markaestro declares the MIT licence, which is OSI-approved. That covers the source only, and says nothing about the cost of any service it calls.

## Links

- npm package: https://www.npmjs.com/package/@markaestro/mcp
- Socket report: https://socket.dev/npm/package/@markaestro/mcp
- Repository: https://github.com/markaestro/markaestro-agents
- Website: https://markaestro.com/developers/agents
- Changelog RSS feed: https://verifymcp.io/servers/com-markaestro-mcp/markaestro-mcp.xml
- Changelog JSON feed: https://verifymcp.io/servers/com-markaestro-mcp/markaestro-mcp.json
- HTML version of this page: https://verifymcp.io/servers/com-markaestro-mcp/markaestro-mcp
