Skip to content
verify mcp Beta VerifyMCP is currently in beta. If you notice any issues, get in touch and we’ll put it right.

TokPortal

NPM · TOKPORTAL-MCP · 2 COMPONENTS · SCANNED AUG 20

Managed TikTok/Instagram/YouTube accounts + video posting at scale, operated by human managers.

67 Trust /100
Trust breakdown (6 categories)

How this component scores in each security and reliability category. Every signal is checked automatically from public evidence about the published package, including repeated runs of it in an isolated sandbox, and we only credit what we can confirm. How we score →

Supply Chain Security98
  • No malware found by supply-chain analysis.Pass
  • No known CVEs affecting this package version or its production dependencies.Pass
  • No install/post-install scripts declared.Pass
  • 30 of 95 dependencies flagged as unhealthy. View diagnostics → Partial
Provenance & Transparency48
  • Source repository is publicly reachable at the declared URL. View diagnostics → Pass
  • Provenance check failed: no build-provenance attestation is published. See how to fix → View diagnostics → Fail
  • Clear OSI-approved license (MIT).Pass
  • Actively maintained (last published 1 days ago).Pass
  • Publishes a security disclosure policy (SECURITY.md).Pass
Schema Quality & AI Usability67
  • AI-judged instruction clarity (good).Pass
  • Tool/resource definitions use about 9191 tokens (~101/item across 91 items; 91 tools + 0 resources), lean.Pass
  • Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management0
  • Stability not yet verified: not enough scan history yet (needs a 30-day window).Unverified
Tool Coverage100
  • 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
  • 100% of tool parameters carry a description.Pass
Capabilities100
  • Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass

Unverified: 1 category

A category scored 0 because we could not verify it: a data source with nothing on this package, evidence we could not reach, or a check we could not run. We only credit what we can confirm.

Install

Add this component to your MCP client. Where a client-specific snippet is available, pick your client below and copy it straight into your config; otherwise use the connection detail shown.

npm · tokportal-mcp

# add to Claude Code
claude mcp add com-tokportal-mcp -- npx -y tokportal-mcp
# add to Codex CLI
codex mcp add com-tokportal-mcp -- npx -y tokportal-mcp
// opencode.json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "com-tokportal-mcp": {
      "type": "local",
      "command": [
        "npx",
        "-y",
        "tokportal-mcp"
      ],
      "enabled": true
    }
  }
}
# add to OpenClaw
openclaw mcp add com-tokportal-mcp --command npx --arg -y --arg tokportal-mcp
# ~/.hermes/config.yaml
mcp_servers:
  com-tokportal-mcp:
    command: "npx"
    args: ["-y", "tokportal-mcp"]
// mcp.json
{
  "mcpServers": {
    "com-tokportal-mcp": {
      "command": "npx",
      "args": [
        "-y",
        "tokportal-mcp"
      ]
    }
  }
}
Changelog

Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.

  • 19 Aug 26 +15
    • Malware scan: unverified → pass security
  • 18 Aug 26 52

    First indexed and scored.

Diagnostics

Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.

Captured 20 Aug 2026 · Analysed npm/tokportal-mcp@1.12.1

Provenance No attestation

The registry publishes no build provenance for this version, so there is nothing to verify.

Result No attestation
Ecosystem npm
Dependencies 95 packages
Packages resolved 95
Stale 30
Tree resolution Complete
MCP tools · 91 exposed · ~9,191 tokens

The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability.

Tool Tokens
tokportal_list_account_warming_sessions ~94

List Advanced Niche Warming sessions for an account. Lists Advanced Niche Warming sessions (newest first) for a saved account you own, including per-term tasks, per-term reports, proof links, and the aggregated session report when completed. Tasks unlock over 3 calendar days in the manager's timezone and, once created, do not expire.

NameTypeReqDescription
idstringyesSaved account ID.

No output schema declared.

No examples provided.

tokportal_list_accounts ~101

List delivered accounts.

NameTypeReqDescription
bannedstringFilter by ban state. true returns only banned accounts (staff-validated or park-scan detected, matching the `banned` response field); false returns only non-banned accounts.
countrystringFilter by country code or country alias.
pageintegerPage number.
per_pageintegerItems per page.
platformstringFilter by platform.

No output schema declared.

No examples provided.

tokportal_list_analytics_account_comments ~66

List comments for an account post.

NameTypeReqDescription
idstringyesSaved account ID.
limitintegerquery parameter limit
postIdstringquery parameter postId
trackedPostIdstringquery parameter trackedPostId

No output schema declared.

No examples provided.

tokportal_list_analytics_account_raw_snapshots ~90

List raw account analytics snapshots. Returns owner-scoped stored raw analytics payloads for a saved account. Full analytics tier only.

NameTypeReqDescription
fromstringquery parameter from
idstringyesSaved account ID.
limitintegerquery parameter limit
sourcestringquery parameter source
tostringquery parameter to

No output schema declared.

No examples provided.

tokportal_list_analytics_post_raw_snapshots ~91

List raw post analytics snapshots. Returns owner-scoped stored raw analytics payloads for a tracked post. Full analytics tier only.

NameTypeReqDescription
fromstringquery parameter from
idstringyesTracked post ID.
limitintegerquery parameter limit
sourcestringquery parameter source
tostringquery parameter to

No output schema declared.

No examples provided.

tokportal_list_bundle_videos ~26

List bundle video slots.

NameTypeReqDescription
idstringyesBundle ID.

No output schema declared.

No examples provided.

tokportal_list_bundles ~92

List bundles.

NameTypeReqDescription
account_statusstringquery parameter account_status
bundle_typestringquery parameter bundle_type
external_refstringquery parameter external_ref
pageintegerPage number.
per_pageintegerItems per page.
platformstringquery parameter platform
statusstringFilter by bundle status.

No output schema declared.

No examples provided.

tokportal_list_comment_task_verifications ~49

List comment task verification events. Lists verifier attempts for one owned task. This read remains available while TokPortal Coverage pauses task execution.

NameTypeReqDescription
idstringyesComment task ID.

No output schema declared.

No examples provided.

tokportal_list_comment_tasks ~99

List comment tasks. Lists owned comment tasks. execution_blocked and execution_block_reason identify tasks paused by inactive TokPortal Coverage; reads remain available while execution is paused.

NameTypeReqDescription
pageintegerPage number.
per_pageintegerItems per page.
saved_account_idstringFilter by a user-owned saved account ID.
statusstringFilter by one status or a comma-separated list of statuses.

No output schema declared.

No examples provided.

tokportal_list_countries ~15

List available countries.

Input schema present but exposes no named parameters.

No output schema declared.

No examples provided.

tokportal_list_credit_transactions ~68

List credit transactions.

NameTypeReqDescription
date_fromstringFilter transactions created on or after this date.
date_tostringFilter transactions created before the day after this date.
pageintegerPage number.
per_pageintegerItems per page.

No output schema declared.

No examples provided.

tokportal_list_platforms ~15

List available platforms.

Input schema present but exposes no named parameters.

No output schema declared.

No examples provided.

tokportal_list_webhook_deliveries ~72

List webhook deliveries.

NameTypeReqDescription
event_typestringFilter by event type.
idstringyesWebhook endpoint ID.
pageintegerPage number.
per_pageintegerItems per page.
successbooleanFilter by delivery success.

No output schema declared.

No examples provided.

tokportal_list_webhook_endpoints ~61

List webhook endpoints.

NameTypeReqDescription
enabledbooleanFilter by enabled state.
eventstringFilter endpoints subscribed to an event.
pageintegerPage number.
per_pageintegerItems per page.

No output schema declared.

No examples provided.

tokportal_list_webhook_events ~51

List webhook event catalog. Returns the supported webhook event types, delivery envelope, signature scheme, and example payloads. This endpoint is public so teams can inspect webhook contracts before creating an API key.

Input schema present but exposes no named parameters.

No output schema declared.

No examples provided.

tokportal_patch_bundle_video ~121

Patch video metadata or schedule. When this bundle resolves to a delivered saved account, the account must have active TokPortal Coverage or be permanently grandfathered. A due active period can renew automatically at the account's stored rate immediately before execution. If Coverage cannot renew, no task or media mutation starts.

NameTypeReqDescription
bodyobjectyesJSON request body.
idstringyesBundle ID.
idempotency_keystringOptional Idempotency-Key header for safe retries.
positionintegeryes1-based video slot position.

No output schema declared.

No examples provided.

tokportal_publish_all_bundle_videos ~103

Publish all configured videos on an active bundle. When this bundle resolves to a delivered saved account, the account must have active TokPortal Coverage or be permanently grandfathered. A due active period can renew automatically at the account's stored rate immediately before execution. If Coverage cannot renew, no task or media mutation starts.

NameTypeReqDescription
idstringyesBundle ID.
idempotency_keystringOptional Idempotency-Key header for safe retries.

No output schema declared.

No examples provided.

tokportal_publish_bundle ~102

Publish a bundle. Publishes a fully configured bundle. When this bundle resolves to a delivered saved account, the account must have active TokPortal Coverage or be permanently grandfathered. A due active period can renew automatically at the account's stored rate immediately before execution. If Coverage cannot renew, no task or media mutation starts.

NameTypeReqDescription
idstringyesBundle ID.
idempotency_keystringOptional Idempotency-Key header for safe retries.

No output schema declared.

No examples provided.

tokportal_publish_bundle_video ~110

Publish one video slot. When this bundle resolves to a delivered saved account, the account must have active TokPortal Coverage or be permanently grandfathered. A due active period can renew automatically at the account's stored rate immediately before execution. If Coverage cannot renew, no task or media mutation starts.

NameTypeReqDescription
idstringyesBundle ID.
idempotency_keystringOptional Idempotency-Key header for safe retries.
positionintegeryes1-based video slot position.

No output schema declared.

No examples provided.

tokportal_reactivate_account_managed_subscription ~168

Reactivate TokPortal Coverage. Reactivates Coverage from an explicit GET snapshot. Reactivation is free while the current billing period is already paid or included; Coverage benefits and tasks remain paused until reactivation. At and after current_period_end, the endpoint accepts the effective lapsed state even if recorded_status has not yet been updated by the renewal worker, and charges exactly the projected unpaid periods without adding an extra period. The expected credits, period end, and lock version are checked atomically before any debit or task resume. Scheduled videos receive new future dates while preserving their cadence.

NameTypeReqDescription
bodyobjectyesJSON request body.
idstringyesSaved account ID.
idempotency_keystringOptional Idempotency-Key header for safe retries.

No output schema declared.

No examples provided.

tokportal_refresh_account_analytics ~95

Refresh account analytics. Backward-compatible account analytics refresh path. Supports forced refresh and post import options. Refresh is blocked for revealed/detached, banned or inactive-Coverage accounts; permanently grandfathered accounts remain eligible.

NameTypeReqDescription
bodyobjectyesJSON request body.
idstringyesSaved account ID.
idempotency_keystringOptional Idempotency-Key header for safe retries.

No output schema declared.

No examples provided.

tokportal_refresh_analytics_account ~91

Refresh analytics account. Refreshes an owner-scoped account through Analytics v2. Refresh is blocked for revealed/detached, banned or inactive-Coverage accounts; permanently grandfathered accounts remain eligible.

NameTypeReqDescription
bodyobjectyesJSON request body.
idstringyesSaved account ID.
idempotency_keystringOptional Idempotency-Key header for safe retries.

No output schema declared.

No examples provided.

tokportal_request_bundle_account_corrections ~107

Request account corrections. Moves an in-review account back to pending corrections with reviewer feedback.

NameTypeReqDescription
bodyobjectJSON request body.
commentstringJSON body field. May be supplied here or inside body.comment.
fieldsobjectJSON body field. May be supplied here or inside body.fields.
idstringyesBundle ID.
idempotency_keystringOptional Idempotency-Key header for safe retries.

No output schema declared.

No examples provided.

tokportal_request_bundle_video_corrections ~160

Request video corrections. When this bundle resolves to a delivered saved account, the account must have active TokPortal Coverage or be permanently grandfathered. A due active period can renew automatically at the account's stored rate immediately before execution. If Coverage cannot renew, no task or media mutation starts.

NameTypeReqDescription
bodyobjectJSON request body.
commentstringJSON body field. May be supplied here or inside body.comment.
fieldsobjectJSON body field. May be supplied here or inside body.fields.
idstringyesBundle ID.
idempotency_keystringOptional Idempotency-Key header for safe retries.
positionintegeryes1-based video slot position.

No output schema declared.

No examples provided.

tokportal_reset_bundle_video ~110

Reset one video slot. When this bundle resolves to a delivered saved account, the account must have active TokPortal Coverage or be permanently grandfathered. A due active period can renew automatically at the account's stored rate immediately before execution. If Coverage cannot renew, no task or media mutation starts.

NameTypeReqDescription
idstringyesBundle ID.
idempotency_keystringOptional Idempotency-Key header for safe retries.
positionintegeryes1-based video slot position.

No output schema declared.

No examples provided.

tokportal_retrieve_account_verification_code ~385

Retrieve latest account verification code. Retrieving a verification code is the same irreversible first-access event as revealing credentials. Its policy is determined by this saved account's created_at timestamp against the immutable managed_pricing_new_customer_cutover_at value, never by the workspace action-pricing cohort or August 14 grace deadline. A saved account created before the cutoff permanently keeps the prior API contract: 0 credits, no new versioned acknowledgment body required, no TokPortal detachment, existing task access remains available, and support plus ban coverage end after access. A saved account created at or after the cutoff follows the managed policy: normally 150 credits, or the stored $10 legacy / $15 new per-30-day rate when Account Owning is already admin-approved. Managed access permanently detaches the account, makes it read-only, and ends TokPortal Coverage, task access, analytics updates, support, ban protection, replacement, refunds, compensation and credit restoration. For a new-policy account, missing explicit acceptance fails with 428 and returns the exact account-specific terms, price and policy version. A changed quote returns 409 before any debit or reveal. Reaching the Account Owning eligibility threshold only submits an admin review request; it never activates the agreement automatically. While approval is pending, reveal remains available for 150 credits on a post-cutoff account. Do not send Idempotency-Key: this response contains a verification secret and is never stored in the replay ledger. A request that includes the header is rejected before any ledger claim, reveal, debit, or inbox access with IDEMPOTENCY_KEY_NOT_ALLOWED_FOR_SENSITIVE_RESPONSE (400). After an uncertain transport result, fetch the safe account state before deciding whether to call this endpoint again without the header.

NameTypeReqDescription
bodyobjectJSON request body.
idstringyesSaved account ID.

No output schema declared.

No examples provided.

tokportal_retry_webhook_delivery ~95

Retry a webhook delivery. Resends the stored webhook payload to the endpoint's current URL with a fresh TokPortal-Signature header. The event ID is preserved so receivers can keep idempotent processing.

NameTypeReqDescription
delivery_idstringyesWebhook delivery ID.
idstringyesWebhook endpoint ID.
idempotency_keystringOptional Idempotency-Key header for safe retries.

No output schema declared.

No examples provided.

tokportal_reveal_account_credentials ~402

Reveal delivered account credentials. The first credential or verification-code access is priced from this saved account's created_at timestamp against the immutable managed_pricing_new_customer_cutover_at value, never from the workspace action-pricing cohort or August 14 grace deadline. A saved account created before the cutoff permanently keeps the prior API contract: the reveal costs 0 credits, requires no new versioned acknowledgment body, and is irreversible; support and ban coverage end, but the account is not detached and existing TokPortal task access remains available. A saved account created at or after the cutoff follows the managed policy and requires the explicit versioned acknowledgment handshake: normally 150 credits, or the stored $10 legacy / $15 new per-30-day rate when Account Owning is already admin-approved. Crossing the Account Owning eligibility threshold only submits an admin review request and never activates it automatically. While approval is pending, reveal remains available for 150 credits on a post-cutoff account. Under the managed policy the charge is final and non-refundable, and reveal permanently detaches the account, makes it read-only, and ends TokPortal Coverage, all task access, analytics updates, support, ban protection, replacement, refunds, compensation and credit restoration. TokPortal is not responsible for later access, performance, reach, security, restrictions or bans. The debit or Account Owning activation, reveal marker and Coverage shutdown commit atomically. Previously revealed accounts are not charged a second time. Do not send Idempotency-Key: this response contains credentials and is never stored in the replay ledger. A request that includes the header is rejected before any ledger claim, reveal, debit, or secret access with IDEMPOTENCY_KEY_NOT_ALLOWED_FOR_SENSITIVE_RESPONSE (400). After an uncertain transport result, fetch the safe account state before deciding whether to call this endpoint again without the hea…

NameTypeReqDescription
bodyobjectJSON request body.
idstringyesSaved account ID.

No output schema declared.

No examples provided.

tokportal_rewarm_account ~264

Order Advanced Niche Warming (rewarm) on a delivered account. Starts an Advanced Niche Warming session on a saved account: for each provided term the manager screen-records a session that opens on the account profile (handle visible), searches the term on the account's platform, watches videos from the results, engages with them (likes/saves) and leaves a comment. Every recording is verified before completion. The standard rate is 5 credits per term, charged per target and never per day (3-30 terms, multiples of 3). GET /credit-costs returns the effective rate; the announced legacy grace window closed on 2026-08-14T11:00:00Z. Requires active TokPortal Coverage, a routable active account manager backed by a non-cancelled support order, TikTok or Instagram, and no already-active warming session. A completed bundle remains eligible. Terms are split evenly over 3 calendar days in the manager's timezone; earlier-day tasks remain available until completed and sessions with tasks do not expire.

NameTypeReqDescription
bodyobjectyesJSON request body.
idstringyesSaved account ID.
idempotency_keystringOptional Idempotency-Key header for safe retries.

No output schema declared.

No examples provided.

tokportal_test_webhook_endpoint ~62

Send a test webhook. Sends a signed webhook.test event to the endpoint and records the delivery result.

NameTypeReqDescription
idstringyesWebhook endpoint ID.
idempotency_keystringOptional Idempotency-Key header for safe retries.

No output schema declared.

No examples provided.

tokportal_unpublish_bundle ~44

Unpublish a bundle.

NameTypeReqDescription
idstringyesBundle ID.
idempotency_keystringOptional Idempotency-Key header for safe retries.

No output schema declared.

No examples provided.

tokportal_unschedule_bundle_video ~112

Unschedule one video slot. When this bundle resolves to a delivered saved account, the account must have active TokPortal Coverage or be permanently grandfathered. A due active period can renew automatically at the account's stored rate immediately before execution. If Coverage cannot renew, no task or media mutation starts.

NameTypeReqDescription
idstringyesBundle ID.
idempotency_keystringOptional Idempotency-Key header for safe retries.
positionintegeryes1-based video slot position.

No output schema declared.

No examples provided.

tokportal_update_account_commenting_profile ~116

Update account commenting profile. Updates client-owned commenting/autopilot profile fields for a delivered account. The account must belong to the API key owner and must have active TokPortal Coverage, unless it is permanently grandfathered. Revealed/detached, banned, paused, lapsed and unrecoverable accounts are read-only.

NameTypeReqDescription
bodyobjectyesJSON request body.
idstringyesSaved account ID.
idempotency_keystringOptional Idempotency-Key header for safe retries.

No output schema declared.

No examples provided.

tokportal_update_bundle ~69

Update bundle settings. Updates mutable bundle metadata such as title, external_ref, and auto_finalize_videos.

NameTypeReqDescription
bodyobjectyesJSON request body.
idstringyesBundle ID.
idempotency_keystringOptional Idempotency-Key header for safe retries.

No output schema declared.

No examples provided.

tokportal_update_current_user_settings ~72

Update safe workspace settings. Updates client-owned workspace profile fields used by Operator context. Does not expose auth, role, credit, staff, or manager settings.

NameTypeReqDescription
bodyobjectyesJSON request body.
idempotency_keystringOptional Idempotency-Key header for safe retries.

No output schema declared.

No examples provided.

tokportal_update_webhook_endpoint ~57

Update a webhook endpoint.

NameTypeReqDescription
bodyobjectyesJSON request body.
idstringyesWebhook endpoint ID.
idempotency_keystringOptional Idempotency-Key header for safe retries.

No output schema declared.

No examples provided.

tokportal_upload_image ~90

Create an image upload URL. Returns a short-lived signed upload URL and upload token. Do not send Idempotency-Key. The successful response contains a secret and is never stored in the replay ledger. A request with the header is rejected with IDEMPOTENCY_KEY_NOT_ALLOWED_FOR_SENSITIVE_RESPONSE (400) before any ledger claim or operation execution.

NameTypeReqDescription
bodyobjectyesJSON request body.

No output schema declared.

No examples provided.

tokportal_upload_image_direct ~101

Upload an image file directly. Uploads multipart/form-data directly through TokPortal and returns storage details. HEIF/HEIC may be converted to JPEG.

NameTypeReqDescription
bundle_idstringyesMultipart form field bundle_id.
file_pathstringyesLocal path to upload for multipart field file.
idempotency_keystringOptional Idempotency-Key header for safe retries.
purposestringMultipart form field purpose.

No output schema declared.

No examples provided.

tokportal_upload_image_from_url ~63

Import an image from URL. Fetches a public direct image URL and stores it permanently in TokPortal storage.

NameTypeReqDescription
bodyobjectyesJSON request body.
idempotency_keystringOptional Idempotency-Key header for safe retries.

No output schema declared.

No examples provided.

tokportal_upload_video ~88

Create a video upload URL. Returns a short-lived presigned upload capability. Do not send Idempotency-Key. The successful response contains a secret and is never stored in the replay ledger. A request with the header is rejected with IDEMPOTENCY_KEY_NOT_ALLOWED_FOR_SENSITIVE_RESPONSE (400) before any ledger claim or operation execution.

NameTypeReqDescription
bodyobjectyesJSON request body.

No output schema declared.

No examples provided.

tokportal_upload_video_direct ~81

Upload a video file directly. Uploads multipart/form-data directly through TokPortal and returns the public video URL.

NameTypeReqDescription
bundle_idstringyesMultipart form field bundle_id.
file_pathstringyesLocal path to upload for multipart field file.
idempotency_keystringOptional Idempotency-Key header for safe retries.

No output schema declared.

No examples provided.