TokPortal
NPM · TOKPORTAL-MCP · 2 COMPONENTS · SCANNED AUG 20
Managed TikTok/Instagram/YouTube accounts + video posting at scale, operated by human managers.
Available components
How this component scores in each security and reliability category. Every signal is checked automatically from public evidence about the published package, including repeated runs of it in an isolated sandbox, and we only credit what we can confirm. How we score →
Supply Chain Security98
- No malware found by supply-chain analysis.Pass
- No known CVEs affecting this package version or its production dependencies.Pass
- No install/post-install scripts declared.Pass
- 30 of 95 dependencies flagged as unhealthy. View diagnostics → Partial
Provenance & Transparency48
- Source repository is publicly reachable at the declared URL. View diagnostics → Pass
- Provenance check failed: no build-provenance attestation is published. See how to fix → View diagnostics → Fail
- Clear OSI-approved license (MIT).Pass
- Actively maintained (last published 1 days ago).Pass
- Publishes a security disclosure policy (SECURITY.md).Pass
Schema Quality & AI Usability67
- AI-judged instruction clarity (good).Pass
- Tool/resource definitions use about 9191 tokens (~101/item across 91 items; 91 tools + 0 resources), lean.Pass
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management0
- Stability not yet verified: not enough scan history yet (needs a 30-day window).Unverified
Tool Coverage100
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 100% of tool parameters carry a description.Pass
Capabilities100
- Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
Unverified: 1 category
A category scored 0 because we could not verify it: a data source with nothing on this package, evidence we could not reach, or a check we could not run. We only credit what we can confirm.
Add this component to your MCP client. Where a client-specific snippet is available, pick your client below and copy it straight into your config; otherwise use the connection detail shown.
npm · tokportal-mcp
claude mcp add com-tokportal-mcp -- npx -y tokportal-mcp
codex mcp add com-tokportal-mcp -- npx -y tokportal-mcp
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"com-tokportal-mcp": {
"type": "local",
"command": [
"npx",
"-y",
"tokportal-mcp"
],
"enabled": true
}
}
} openclaw mcp add com-tokportal-mcp --command npx --arg -y --arg tokportal-mcp
mcp_servers:
com-tokportal-mcp:
command: "npx"
args: ["-y", "tokportal-mcp"] {
"mcpServers": {
"com-tokportal-mcp": {
"command": "npx",
"args": [
"-y",
"tokportal-mcp"
]
}
}
} Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 19 Aug 26 +15
- Malware scan: unverified → pass ▲ security
- 18 Aug 26 52
First indexed and scored.
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 20 Aug 2026 · Analysed npm/tokportal-mcp@1.12.1
Provenance No attestation
The registry publishes no build provenance for this version, so there is nothing to verify.
| Result | No attestation |
|---|---|
| Ecosystem | npm |
Dependencies 95 packages
| Packages resolved | 95 |
|---|---|
| Stale | 30 |
| Tree resolution | Complete |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability.
tokportal_list_account_warming_sessions ~94
List Advanced Niche Warming sessions for an account. Lists Advanced Niche Warming sessions (newest first) for a saved account you own, including per-term tasks, per-term reports, proof links, and the aggregated session report when completed. Tasks unlock over 3 calendar days in the manager's timezone and, once created, do not expire.
| Name | Type | Req | Description |
|---|---|---|---|
| id | string | yes | Saved account ID. |
No output schema declared.
No examples provided.
tokportal_list_accounts ~101
List delivered accounts.
| Name | Type | Req | Description |
|---|---|---|---|
| banned | string | – | Filter by ban state. true returns only banned accounts (staff-validated or park-scan detected, matching the `banned` response field); false returns only non-banned accounts. |
| country | string | – | Filter by country code or country alias. |
| page | integer | – | Page number. |
| per_page | integer | – | Items per page. |
| platform | string | – | Filter by platform. |
No output schema declared.
No examples provided.
tokportal_list_analytics_account_comments ~66
List comments for an account post.
| Name | Type | Req | Description |
|---|---|---|---|
| id | string | yes | Saved account ID. |
| limit | integer | – | query parameter limit |
| postId | string | – | query parameter postId |
| trackedPostId | string | – | query parameter trackedPostId |
No output schema declared.
No examples provided.
tokportal_list_analytics_account_raw_snapshots ~90
List raw account analytics snapshots. Returns owner-scoped stored raw analytics payloads for a saved account. Full analytics tier only.
| Name | Type | Req | Description |
|---|---|---|---|
| from | string | – | query parameter from |
| id | string | yes | Saved account ID. |
| limit | integer | – | query parameter limit |
| source | string | – | query parameter source |
| to | string | – | query parameter to |
No output schema declared.
No examples provided.
tokportal_list_analytics_post_raw_snapshots ~91
List raw post analytics snapshots. Returns owner-scoped stored raw analytics payloads for a tracked post. Full analytics tier only.
| Name | Type | Req | Description |
|---|---|---|---|
| from | string | – | query parameter from |
| id | string | yes | Tracked post ID. |
| limit | integer | – | query parameter limit |
| source | string | – | query parameter source |
| to | string | – | query parameter to |
No output schema declared.
No examples provided.
tokportal_list_bundle_videos ~26
List bundle video slots.
| Name | Type | Req | Description |
|---|---|---|---|
| id | string | yes | Bundle ID. |
No output schema declared.
No examples provided.
tokportal_list_bundles ~92
List bundles.
| Name | Type | Req | Description |
|---|---|---|---|
| account_status | string | – | query parameter account_status |
| bundle_type | string | – | query parameter bundle_type |
| external_ref | string | – | query parameter external_ref |
| page | integer | – | Page number. |
| per_page | integer | – | Items per page. |
| platform | string | – | query parameter platform |
| status | string | – | Filter by bundle status. |
No output schema declared.
No examples provided.
tokportal_list_comment_task_verifications ~49
List comment task verification events. Lists verifier attempts for one owned task. This read remains available while TokPortal Coverage pauses task execution.
| Name | Type | Req | Description |
|---|---|---|---|
| id | string | yes | Comment task ID. |
No output schema declared.
No examples provided.
tokportal_list_comment_tasks ~99
List comment tasks. Lists owned comment tasks. execution_blocked and execution_block_reason identify tasks paused by inactive TokPortal Coverage; reads remain available while execution is paused.
| Name | Type | Req | Description |
|---|---|---|---|
| page | integer | – | Page number. |
| per_page | integer | – | Items per page. |
| saved_account_id | string | – | Filter by a user-owned saved account ID. |
| status | string | – | Filter by one status or a comma-separated list of statuses. |
No output schema declared.
No examples provided.
tokportal_list_countries ~15
List available countries.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
tokportal_list_credit_transactions ~68
List credit transactions.
| Name | Type | Req | Description |
|---|---|---|---|
| date_from | string | – | Filter transactions created on or after this date. |
| date_to | string | – | Filter transactions created before the day after this date. |
| page | integer | – | Page number. |
| per_page | integer | – | Items per page. |
No output schema declared.
No examples provided.
tokportal_list_platforms ~15
List available platforms.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
tokportal_list_webhook_deliveries ~72
List webhook deliveries.
| Name | Type | Req | Description |
|---|---|---|---|
| event_type | string | – | Filter by event type. |
| id | string | yes | Webhook endpoint ID. |
| page | integer | – | Page number. |
| per_page | integer | – | Items per page. |
| success | boolean | – | Filter by delivery success. |
No output schema declared.
No examples provided.
tokportal_list_webhook_endpoints ~61
List webhook endpoints.
| Name | Type | Req | Description |
|---|---|---|---|
| enabled | boolean | – | Filter by enabled state. |
| event | string | – | Filter endpoints subscribed to an event. |
| page | integer | – | Page number. |
| per_page | integer | – | Items per page. |
No output schema declared.
No examples provided.
tokportal_list_webhook_events ~51
List webhook event catalog. Returns the supported webhook event types, delivery envelope, signature scheme, and example payloads. This endpoint is public so teams can inspect webhook contracts before creating an API key.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
tokportal_patch_bundle_video ~121
Patch video metadata or schedule. When this bundle resolves to a delivered saved account, the account must have active TokPortal Coverage or be permanently grandfathered. A due active period can renew automatically at the account's stored rate immediately before execution. If Coverage cannot renew, no task or media mutation starts.
| Name | Type | Req | Description |
|---|---|---|---|
| body | object | yes | JSON request body. |
| id | string | yes | Bundle ID. |
| idempotency_key | string | – | Optional Idempotency-Key header for safe retries. |
| position | integer | yes | 1-based video slot position. |
No output schema declared.
No examples provided.
tokportal_publish_all_bundle_videos ~103
Publish all configured videos on an active bundle. When this bundle resolves to a delivered saved account, the account must have active TokPortal Coverage or be permanently grandfathered. A due active period can renew automatically at the account's stored rate immediately before execution. If Coverage cannot renew, no task or media mutation starts.
| Name | Type | Req | Description |
|---|---|---|---|
| id | string | yes | Bundle ID. |
| idempotency_key | string | – | Optional Idempotency-Key header for safe retries. |
No output schema declared.
No examples provided.
tokportal_publish_bundle ~102
Publish a bundle. Publishes a fully configured bundle. When this bundle resolves to a delivered saved account, the account must have active TokPortal Coverage or be permanently grandfathered. A due active period can renew automatically at the account's stored rate immediately before execution. If Coverage cannot renew, no task or media mutation starts.
| Name | Type | Req | Description |
|---|---|---|---|
| id | string | yes | Bundle ID. |
| idempotency_key | string | – | Optional Idempotency-Key header for safe retries. |
No output schema declared.
No examples provided.
tokportal_publish_bundle_video ~110
Publish one video slot. When this bundle resolves to a delivered saved account, the account must have active TokPortal Coverage or be permanently grandfathered. A due active period can renew automatically at the account's stored rate immediately before execution. If Coverage cannot renew, no task or media mutation starts.
| Name | Type | Req | Description |
|---|---|---|---|
| id | string | yes | Bundle ID. |
| idempotency_key | string | – | Optional Idempotency-Key header for safe retries. |
| position | integer | yes | 1-based video slot position. |
No output schema declared.
No examples provided.
tokportal_reactivate_account_managed_subscription ~168
Reactivate TokPortal Coverage. Reactivates Coverage from an explicit GET snapshot. Reactivation is free while the current billing period is already paid or included; Coverage benefits and tasks remain paused until reactivation. At and after current_period_end, the endpoint accepts the effective lapsed state even if recorded_status has not yet been updated by the renewal worker, and charges exactly the projected unpaid periods without adding an extra period. The expected credits, period end, and lock version are checked atomically before any debit or task resume. Scheduled videos receive new future dates while preserving their cadence.
| Name | Type | Req | Description |
|---|---|---|---|
| body | object | yes | JSON request body. |
| id | string | yes | Saved account ID. |
| idempotency_key | string | – | Optional Idempotency-Key header for safe retries. |
No output schema declared.
No examples provided.
tokportal_refresh_account_analytics ~95
Refresh account analytics. Backward-compatible account analytics refresh path. Supports forced refresh and post import options. Refresh is blocked for revealed/detached, banned or inactive-Coverage accounts; permanently grandfathered accounts remain eligible.
| Name | Type | Req | Description |
|---|---|---|---|
| body | object | yes | JSON request body. |
| id | string | yes | Saved account ID. |
| idempotency_key | string | – | Optional Idempotency-Key header for safe retries. |
No output schema declared.
No examples provided.
tokportal_refresh_analytics_account ~91
Refresh analytics account. Refreshes an owner-scoped account through Analytics v2. Refresh is blocked for revealed/detached, banned or inactive-Coverage accounts; permanently grandfathered accounts remain eligible.
| Name | Type | Req | Description |
|---|---|---|---|
| body | object | yes | JSON request body. |
| id | string | yes | Saved account ID. |
| idempotency_key | string | – | Optional Idempotency-Key header for safe retries. |
No output schema declared.
No examples provided.
tokportal_request_bundle_account_corrections ~107
Request account corrections. Moves an in-review account back to pending corrections with reviewer feedback.
| Name | Type | Req | Description |
|---|---|---|---|
| body | object | – | JSON request body. |
| comment | string | – | JSON body field. May be supplied here or inside body.comment. |
| fields | object | – | JSON body field. May be supplied here or inside body.fields. |
| id | string | yes | Bundle ID. |
| idempotency_key | string | – | Optional Idempotency-Key header for safe retries. |
No output schema declared.
No examples provided.
tokportal_request_bundle_video_corrections ~160
Request video corrections. When this bundle resolves to a delivered saved account, the account must have active TokPortal Coverage or be permanently grandfathered. A due active period can renew automatically at the account's stored rate immediately before execution. If Coverage cannot renew, no task or media mutation starts.
| Name | Type | Req | Description |
|---|---|---|---|
| body | object | – | JSON request body. |
| comment | string | – | JSON body field. May be supplied here or inside body.comment. |
| fields | object | – | JSON body field. May be supplied here or inside body.fields. |
| id | string | yes | Bundle ID. |
| idempotency_key | string | – | Optional Idempotency-Key header for safe retries. |
| position | integer | yes | 1-based video slot position. |
No output schema declared.
No examples provided.
tokportal_reset_bundle_video ~110
Reset one video slot. When this bundle resolves to a delivered saved account, the account must have active TokPortal Coverage or be permanently grandfathered. A due active period can renew automatically at the account's stored rate immediately before execution. If Coverage cannot renew, no task or media mutation starts.
| Name | Type | Req | Description |
|---|---|---|---|
| id | string | yes | Bundle ID. |
| idempotency_key | string | – | Optional Idempotency-Key header for safe retries. |
| position | integer | yes | 1-based video slot position. |
No output schema declared.
No examples provided.
tokportal_retrieve_account_verification_code ~385
Retrieve latest account verification code. Retrieving a verification code is the same irreversible first-access event as revealing credentials. Its policy is determined by this saved account's created_at timestamp against the immutable managed_pricing_new_customer_cutover_at value, never by the workspace action-pricing cohort or August 14 grace deadline. A saved account created before the cutoff permanently keeps the prior API contract: 0 credits, no new versioned acknowledgment body required, no TokPortal detachment, existing task access remains available, and support plus ban coverage end after access. A saved account created at or after the cutoff follows the managed policy: normally 150 credits, or the stored $10 legacy / $15 new per-30-day rate when Account Owning is already admin-approved. Managed access permanently detaches the account, makes it read-only, and ends TokPortal Coverage, task access, analytics updates, support, ban protection, replacement, refunds, compensation and credit restoration. For a new-policy account, missing explicit acceptance fails with 428 and returns the exact account-specific terms, price and policy version. A changed quote returns 409 before any debit or reveal. Reaching the Account Owning eligibility threshold only submits an admin review request; it never activates the agreement automatically. While approval is pending, reveal remains available for 150 credits on a post-cutoff account. Do not send Idempotency-Key: this response contains a verification secret and is never stored in the replay ledger. A request that includes the header is rejected before any ledger claim, reveal, debit, or inbox access with IDEMPOTENCY_KEY_NOT_ALLOWED_FOR_SENSITIVE_RESPONSE (400). After an uncertain transport result, fetch the safe account state before deciding whether to call this endpoint again without the header.
| Name | Type | Req | Description |
|---|---|---|---|
| body | object | – | JSON request body. |
| id | string | yes | Saved account ID. |
No output schema declared.
No examples provided.
tokportal_retry_webhook_delivery ~95
Retry a webhook delivery. Resends the stored webhook payload to the endpoint's current URL with a fresh TokPortal-Signature header. The event ID is preserved so receivers can keep idempotent processing.
| Name | Type | Req | Description |
|---|---|---|---|
| delivery_id | string | yes | Webhook delivery ID. |
| id | string | yes | Webhook endpoint ID. |
| idempotency_key | string | – | Optional Idempotency-Key header for safe retries. |
No output schema declared.
No examples provided.
tokportal_reveal_account_credentials ~402
Reveal delivered account credentials. The first credential or verification-code access is priced from this saved account's created_at timestamp against the immutable managed_pricing_new_customer_cutover_at value, never from the workspace action-pricing cohort or August 14 grace deadline. A saved account created before the cutoff permanently keeps the prior API contract: the reveal costs 0 credits, requires no new versioned acknowledgment body, and is irreversible; support and ban coverage end, but the account is not detached and existing TokPortal task access remains available. A saved account created at or after the cutoff follows the managed policy and requires the explicit versioned acknowledgment handshake: normally 150 credits, or the stored $10 legacy / $15 new per-30-day rate when Account Owning is already admin-approved. Crossing the Account Owning eligibility threshold only submits an admin review request and never activates it automatically. While approval is pending, reveal remains available for 150 credits on a post-cutoff account. Under the managed policy the charge is final and non-refundable, and reveal permanently detaches the account, makes it read-only, and ends TokPortal Coverage, all task access, analytics updates, support, ban protection, replacement, refunds, compensation and credit restoration. TokPortal is not responsible for later access, performance, reach, security, restrictions or bans. The debit or Account Owning activation, reveal marker and Coverage shutdown commit atomically. Previously revealed accounts are not charged a second time. Do not send Idempotency-Key: this response contains credentials and is never stored in the replay ledger. A request that includes the header is rejected before any ledger claim, reveal, debit, or secret access with IDEMPOTENCY_KEY_NOT_ALLOWED_FOR_SENSITIVE_RESPONSE (400). After an uncertain transport result, fetch the safe account state before deciding whether to call this endpoint again without the hea…
| Name | Type | Req | Description |
|---|---|---|---|
| body | object | – | JSON request body. |
| id | string | yes | Saved account ID. |
No output schema declared.
No examples provided.
tokportal_rewarm_account ~264
Order Advanced Niche Warming (rewarm) on a delivered account. Starts an Advanced Niche Warming session on a saved account: for each provided term the manager screen-records a session that opens on the account profile (handle visible), searches the term on the account's platform, watches videos from the results, engages with them (likes/saves) and leaves a comment. Every recording is verified before completion. The standard rate is 5 credits per term, charged per target and never per day (3-30 terms, multiples of 3). GET /credit-costs returns the effective rate; the announced legacy grace window closed on 2026-08-14T11:00:00Z. Requires active TokPortal Coverage, a routable active account manager backed by a non-cancelled support order, TikTok or Instagram, and no already-active warming session. A completed bundle remains eligible. Terms are split evenly over 3 calendar days in the manager's timezone; earlier-day tasks remain available until completed and sessions with tasks do not expire.
| Name | Type | Req | Description |
|---|---|---|---|
| body | object | yes | JSON request body. |
| id | string | yes | Saved account ID. |
| idempotency_key | string | – | Optional Idempotency-Key header for safe retries. |
No output schema declared.
No examples provided.
tokportal_test_webhook_endpoint ~62
Send a test webhook. Sends a signed webhook.test event to the endpoint and records the delivery result.
| Name | Type | Req | Description |
|---|---|---|---|
| id | string | yes | Webhook endpoint ID. |
| idempotency_key | string | – | Optional Idempotency-Key header for safe retries. |
No output schema declared.
No examples provided.
tokportal_unpublish_bundle ~44
Unpublish a bundle.
| Name | Type | Req | Description |
|---|---|---|---|
| id | string | yes | Bundle ID. |
| idempotency_key | string | – | Optional Idempotency-Key header for safe retries. |
No output schema declared.
No examples provided.
tokportal_unschedule_bundle_video ~112
Unschedule one video slot. When this bundle resolves to a delivered saved account, the account must have active TokPortal Coverage or be permanently grandfathered. A due active period can renew automatically at the account's stored rate immediately before execution. If Coverage cannot renew, no task or media mutation starts.
| Name | Type | Req | Description |
|---|---|---|---|
| id | string | yes | Bundle ID. |
| idempotency_key | string | – | Optional Idempotency-Key header for safe retries. |
| position | integer | yes | 1-based video slot position. |
No output schema declared.
No examples provided.
tokportal_update_account_commenting_profile ~116
Update account commenting profile. Updates client-owned commenting/autopilot profile fields for a delivered account. The account must belong to the API key owner and must have active TokPortal Coverage, unless it is permanently grandfathered. Revealed/detached, banned, paused, lapsed and unrecoverable accounts are read-only.
| Name | Type | Req | Description |
|---|---|---|---|
| body | object | yes | JSON request body. |
| id | string | yes | Saved account ID. |
| idempotency_key | string | – | Optional Idempotency-Key header for safe retries. |
No output schema declared.
No examples provided.
tokportal_update_bundle ~69
Update bundle settings. Updates mutable bundle metadata such as title, external_ref, and auto_finalize_videos.
| Name | Type | Req | Description |
|---|---|---|---|
| body | object | yes | JSON request body. |
| id | string | yes | Bundle ID. |
| idempotency_key | string | – | Optional Idempotency-Key header for safe retries. |
No output schema declared.
No examples provided.
tokportal_update_current_user_settings ~72
Update safe workspace settings. Updates client-owned workspace profile fields used by Operator context. Does not expose auth, role, credit, staff, or manager settings.
| Name | Type | Req | Description |
|---|---|---|---|
| body | object | yes | JSON request body. |
| idempotency_key | string | – | Optional Idempotency-Key header for safe retries. |
No output schema declared.
No examples provided.
tokportal_update_webhook_endpoint ~57
Update a webhook endpoint.
| Name | Type | Req | Description |
|---|---|---|---|
| body | object | yes | JSON request body. |
| id | string | yes | Webhook endpoint ID. |
| idempotency_key | string | – | Optional Idempotency-Key header for safe retries. |
No output schema declared.
No examples provided.
tokportal_upload_image ~90
Create an image upload URL. Returns a short-lived signed upload URL and upload token. Do not send Idempotency-Key. The successful response contains a secret and is never stored in the replay ledger. A request with the header is rejected with IDEMPOTENCY_KEY_NOT_ALLOWED_FOR_SENSITIVE_RESPONSE (400) before any ledger claim or operation execution.
| Name | Type | Req | Description |
|---|---|---|---|
| body | object | yes | JSON request body. |
No output schema declared.
No examples provided.
tokportal_upload_image_direct ~101
Upload an image file directly. Uploads multipart/form-data directly through TokPortal and returns storage details. HEIF/HEIC may be converted to JPEG.
| Name | Type | Req | Description |
|---|---|---|---|
| bundle_id | string | yes | Multipart form field bundle_id. |
| file_path | string | yes | Local path to upload for multipart field file. |
| idempotency_key | string | – | Optional Idempotency-Key header for safe retries. |
| purpose | string | – | Multipart form field purpose. |
No output schema declared.
No examples provided.
tokportal_upload_image_from_url ~63
Import an image from URL. Fetches a public direct image URL and stores it permanently in TokPortal storage.
| Name | Type | Req | Description |
|---|---|---|---|
| body | object | yes | JSON request body. |
| idempotency_key | string | – | Optional Idempotency-Key header for safe retries. |
No output schema declared.
No examples provided.
tokportal_upload_video ~88
Create a video upload URL. Returns a short-lived presigned upload capability. Do not send Idempotency-Key. The successful response contains a secret and is never stored in the replay ledger. A request with the header is rejected with IDEMPOTENCY_KEY_NOT_ALLOWED_FOR_SENSITIVE_RESPONSE (400) before any ledger claim or operation execution.
| Name | Type | Req | Description |
|---|---|---|---|
| body | object | yes | JSON request body. |
No output schema declared.
No examples provided.
tokportal_upload_video_direct ~81
Upload a video file directly. Uploads multipart/form-data directly through TokPortal and returns the public video URL.
| Name | Type | Req | Description |
|---|---|---|---|
| bundle_id | string | yes | Multipart form field bundle_id. |
| file_path | string | yes | Local path to upload for multipart field file. |
| idempotency_key | string | – | Optional Idempotency-Key header for safe retries. |
No output schema declared.
No examples provided.