PostLake
REMOTE · API.POSTLAKE.DEV · SCANNED SEP 20
Post, schedule, reply and measure across X, LinkedIn, Instagram, TikTok, YouTube, Threads, Bluesky
Available components
How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →
Endpoint Security86
- The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
- The endpoint enforces authorisation, advertised via RFC 9728 protected-resource metadata. View diagnostics → Pass
- HTTPS enforcement could not be verified: the plaintext port answered with HTTP 405, which proves neither a plaintext path nor enforcement. View diagnostics → Unverified
- The HSTS (Strict-Transport-Security) header is present. View diagnostics → Pass
- DNSSEC check failed: this domain isn't protected by DNSSEC. See how to fix → View diagnostics → Fail
- The authorisation server supports Client ID Metadata Documents, the current MCP client-registration mechanism. View diagnostics → Pass
Transport & Reachability0
- Transport blocked by authentication: the endpoint requires auth we don't have to verify streamable-http. See how to fix → View diagnostics → Unverified
Schema Quality & AI Usability0
- Schema blocked by authentication: the endpoint requires auth we don't have to read it. See how to fix → Unverified
Stability & Change Management0
- Stability not yet verified: not enough scan history yet (needs a 30-day window).Unverified
Tool Coverage0
- Tool coverage blocked by authentication: the endpoint requires auth we don't have to read its tools.Unverified
Tool Safety0
- Tool safety blocked by authentication: the endpoint requires auth we don't have to read its tools.Unverified
Capabilities0
- Capabilities blocked by authentication: the endpoint requires auth we don't have to read them. See how to fix → Unverified
Unverified: 6 categories
Categories scored 0 because we could not verify them: authentication we do not have, an unreachable endpoint, or not enough scan history. We only credit what we can confirm. Claim this server and supply a read-only token to verify it and lift the score.
How do I install the PostLake MCP server?
PostLake is a hosted endpoint at https://api.postlake.dev/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.
remote · api.postlake.dev
claude mcp add --transport http dev-postlake-social 'https://api.postlake.dev/mcp'
{
"mcpServers": {
"dev-postlake-social": {
"url": "https://api.postlake.dev/mcp"
}
}
} {
"servers": {
"dev-postlake-social": {
"type": "http",
"url": "https://api.postlake.dev/mcp"
}
}
} [mcp_servers.dev-postlake-social] url = "https://api.postlake.dev/mcp"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"dev-postlake-social": {
"type": "remote",
"url": "https://api.postlake.dev/mcp",
"enabled": true
}
}
} openclaw mcp add dev-postlake-social --url 'https://api.postlake.dev/mcp' --transport streamable-http
mcp_servers:
dev-postlake-social:
url: "https://api.postlake.dev/mcp" {
"McpServers": {
"dev-postlake-social": {
"Transport": "http",
"Url": "https://api.postlake.dev/mcp"
}
}
} assistant mcp add dev-postlake-social -t streamable-http -u 'https://api.postlake.dev/mcp'
{
"mcpServers": {
"dev-postlake-social": {
"type": "http",
"url": "https://api.postlake.dev/mcp"
}
}
} The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 26 Aug 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 13 Aug 26 0
- Endpoint reachability: reachable → behind authorisation ▼ security
- Stability: 0.07 → unverified ▼ security
- Transport: pass → unverified ▼ security
- Authorization: The endpoint enforces authorisation, advertised via RFC 9728 protected-resource metadata. security
- Capabilities: fail → unverified ▼ functional
- Tool coverage: 100 → unverified ▼ functional
- 11 Aug 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 10 Aug 26 0
- Transport: unverified → pass ▲ security
- Authorization: Authorisation is enforced on tool calls, advertised via RFC 9728 protected-resource metadata. Discovery is public, which costs nothing: no tool can be invoked without a token. security
- MCP protocol: unverified → fail ▼ functional
- Tool coverage: unverified → 100 ▲ functional
- First check of Schema quality: fail functional
- First check of Schema quality: excellent functional
- First check of Schema quality: fail functional
- First check of Tool coverage: 100 functional
- 7 Aug 26 0
- Authorization: partial → pass ▲ security
- 31 Jul 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 30 Jul 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 27 Jul 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 20 Sept 2026 · Probed https://api.postlake.dev/mcp
TLS valid
Negotiated TLS 1.3 with TLS_AES_128_GCM_SHA256 .
| Subject | Issuer | Valid from | Valid until | Key | Signature | Serial |
|---|---|---|---|---|---|---|
| CN=postlake.dev | CN=WE1,O=Google Trust Services,C=US | 28 Aug 2026 | 26 Nov 2026 | ECDSA 256 | ECDSA-SHA256 | 2dd7dc51d00f47da0e6d624e0661b600 |
| SANs: postlake.dev, api.postlake.dev, *.api.postlake.dev | ||||||
| CN=WE1,O=Google Trust Services,C=US (CA) | CN=GTS Root R4,O=Google Trust Services LLC,C=US | 13 Dec 2023 | 20 Feb 2029 | ECDSA 256 | ECDSA-SHA384 | 7ff31977972c224a76155d13b6d685e3 |
| CN=GTS Root R4,O=Google Trust Services LLC,C=US (CA) | CN=GlobalSign Root CA,OU=Root CA,O=GlobalSign nv-sa,C=BE | 15 Nov 2023 | 28 Jan 2028 | ECDSA 384 | SHA256-RSA | 7fe530bf331343bedd821610493d8a1b |
Background: What to check on a remote MCP endpoint →
DNSSEC insecure
Validation of api.postlake.dev. — Not signed
| Zone | DS | Keys | Algorithms | Outcome |
|---|---|---|---|---|
| . | trust_anchor | 20326, 38696 | 8, 8 | Verified |
| dev. | present | 60074 | 8 | Verified |
| postlake.dev. | absent | Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation |
Authentication Enforced and verified
The endpoint asked for a token and published valid RFC 9728 metadata describing how to get one.
| Result | Enforced and verified |
|---|---|
| Enforced | On connection |
| HTTP status | 401 |
WWW-Authenticate challenge Bearer resource_metadata="https://api.postlake.dev/.well-known/oauth-protected-resource"
Bearer resource_metadata="https://api.postlake.dev/.well-known/oauth-protected-resource" | Header | Value |
|---|---|
| strict-transport-security | max-age=31536000; includeSubDomains |
| content-security-policy | default-src 'self'; script-src 'self' 'unsafe-inline' https://js.stripe.com https://static.cloudflareinsights.com; style-src 'self' 'unsafe-inline' https://api.fontshare.com https://fonts.googleapis.com; font-src https://cdn.fontshare.com https://fonts.gstatic.com; img-src 'self' data: blob: https:; media-src 'self' blob: https:; connect-src 'self' https://api.stripe.com https://m.stripe.com https://m.stripe.network https://cloudflareinsights.com; frame-src https://js.stripe.com https://hooks.stripe.com https://*.stripe.com; frame-ancestors 'none'; base-uri 'self' |
| x-content-type-options | nosniff |
| x-frame-options | DENY |
| referrer-policy | strict-origin-when-cross-origin |
| permissions-policy | geolocation=(), microphone=(), camera=() |
| www-authenticate | Bearer resource_metadata="https://api.postlake.dev/.well-known/oauth-protected-resource" |
Protected resource metadata
| Document | https://api.postlake.dev/.well-known/oauth-protected-resource |
|---|---|
| Retrieved | Yes |
| Resource | https://api.postlake.dev/mcp |
| Authorisation server | https://api.postlake.dev |
Background: How OAuth 2.1 works in the 2026 MCP spec →
Transports 2 probes
| Transport | URL | Outcome | Status | Location |
|---|---|---|---|---|
| streamable-http | https://api.postlake.dev/mcp | Auth required | 401 | |
| http (plaintext) | http://api.postlake.dev/mcp | Inconclusive | 405 |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
cancel_post ~73
Cancel a scheduled post so it never fires. Only works while it is still in 'scheduled' state. Once it has gone out, use delete_post to retract it from the networks instead. Cancelling is free and refunds nothing because nothing was spent.
| Name | Type | Req | Description |
|---|---|---|---|
| id | string | yes | The scheduled post id (post_…). |
No output schema declared.
No examples provided.
connect_account ~197
Connect a social channel using credentials its owner gives you. This only works on networks that authenticate with a credential rather than a consent screen. Bluesky is one: the owner creates an app password (Settings, Privacy and security, App passwords) and gives it to you. Everywhere else the network requires a person to approve access on its own screen and no API can do it for them, so call get_connect_link instead and hand the person the link. Never ask for someone's main account password; an app password is revocable and limited, an account password is neither. Call with just a platform to be told which fields that platform needs.
| Name | Type | Req | Description |
|---|---|---|---|
| fields | object | – | The credentials for this platform. Call without it once to be told the field names. |
| platform | string | yes | The network to connect, e.g. 'bluesky'. |
| profile | string | – | Optional profile to attach the channel to. Omit for the default. |
No output schema declared.
No examples provided.
create_api_key ~125
Create a new PostLake API key. Useful when you are setting up another agent or service that needs its own credentials rather than sharing yours. The key has full access to this account and is shown ONCE, in this response. It cannot be retrieved again, so pass it on or store it immediately. Give it a name that says what will use it, because the name is all anyone has later when deciding whether a key is still needed.
| Name | Type | Req | Description |
|---|---|---|---|
| name | string | yes | What this key is for, e.g. 'nightly digest worker'. Shown in the dashboard. |
No output schema declared.
No examples provided.
create_post ~695
Publish (or schedule) one post to one or more connected accounts. Say WHERE to post the simple way, `profile` (a profile name) optionally narrowed with `platforms`, or the precise way, explicit `accounts` ids. Provide at least one. Returns a normalised result with per-platform status and live URLs. Omit scheduledAt to publish now.
| Name | Type | Req | Description |
|---|---|---|---|
| accounts | array | – | Connected account ids (acc_…) from list_social_accounts. An alternative (or addition) to `profile`. |
| firstComment | string | – | Optional 'first comment' posted as a reply the moment the post goes live. Classic use: keep hashtags/links out of the main caption. Instagram, TikTok and Pinterest have no comment API we can use, so… |
| firstCommentOverrides | object | – | Optional per-platform first-comment overrides, keyed by platform (mirrors textOverrides). e.g. { "instagram": "#tags here" }. |
| idempotencyKey | string | – | Optional. Reuse the same key to safely retry without double-posting. |
| media | array | – | Optional media ids (med_…) from a prior upload. Required by image/video-only platforms (Instagram, Pinterest, TikTok, YouTube). |
| mediaAlt | array | – | Optional alt text (accessibility) per media item, aligned by index to `media`. Used by platforms that support it (Bluesky, X); others ignore it. |
| mediaAltOverrides | object | – | Optional alt text for the override media, keyed by platform, aligned to mediaOverrides[platform]. |
| mediaOverrides | object | – | Optional per-platform media, keyed by platform, e.g. { "tiktok": ["med_vertical"], "instagram": ["med_square"] }. A platform with an override publishes ITS media instead of `media`; others fall back… |
| platformOptions | object | – | Optional per-platform extras, namespaced by platform. e.g. { "pinterest": { "boardId": "..." }, "youtube": { "privacyStatus": "unlisted" } }. |
| platforms | array | – | Optional filter: keep only these networks from the resolved set. e.g. with profile "my-brand", platforms ["bluesky"] posts to just its Bluesky account. |
| profile | string | – | A profile name (from list_profiles) posts to every account that profile owns. The simplest way to address accounts; combine with `platforms` to narrow it. |
| scheduledAt | string | – | Optional ISO 8601 UTC time to publish later. Omit to publish now. |
| text | string | yes | The post body (the master caption). |
| textOverrides | object | – | Optional per-platform caption overrides, keyed by platform. e.g. { "x": "short punchy version", "linkedin": "the long professional version" }. Any platform without an override uses `text`. A blank ov… |
| thread | array | – | Optional follow-on post bodies, published as posts 2..n in a thread. Check platform capabilities or validate first. |
No output schema declared.
No examples provided.
create_profile ~105
Create a profile: a named set of connected channels, usually one brand or client. Give the name as a person would write it, spaces and capitals included; it is slugified into the identifier you then pass as `profile` on other calls, and the response tells you what that became. Create one before connecting channels when an account is running more than one brand.
| Name | Type | Req | Description |
|---|---|---|---|
| name | string | yes | e.g. "Otaku Gems News", which becomes otaku-gems-news. |
No output schema declared.
No examples provided.
delete_post ~105
Retract a post that is ALREADY LIVE, removing it from each network it went to. This is the undo: use it when a post was wrong. Reports every target separately, because a post can be gone from one network and still public on another, and networks that do not allow deletion through their API say so. Use cancel_post instead for something scheduled that has not gone out yet. Irreversible.
| Name | Type | Req | Description |
|---|---|---|---|
| id | string | yes | The post id (post_…). |
No output schema declared.
No examples provided.
delete_profile ~104
Delete a profile. This ALSO disconnects every channel in it, and reconnecting each one needs its owner to approve access on that network again, which you cannot do for them. So it refuses by default while channels are attached and tells you exactly which ones would go. Only pass force after a human has agreed to lose them.
| Name | Type | Req | Description |
|---|---|---|---|
| force | boolean | – | Go ahead even though channels will be disconnected. Ask a human first. |
| profile | string | yes | The profile identifier. |
No output schema declared.
No examples provided.
disconnect_account ~94
Disconnect one social channel from PostLake. Nothing already published is affected and no posts are deleted. The channel simply stops being somewhere you can publish. Reconnecting it later needs its owner to approve access on that network again, which you cannot do for them, so only disconnect when someone has actually asked you to. Takes the id from list_social_accounts.
| Name | Type | Req | Description |
|---|---|---|---|
| account_id | string | yes | The social account id from list_social_accounts. |
No output schema declared.
No examples provided.
edit_post ~131
Change a scheduled post's text and/or its fire time before it goes out. Only 'scheduled' posts can be edited and any new time must be in the future. To change where it posts, cancel it and create a new one; targets are fixed once scheduled.
| Name | Type | Req | Description |
|---|---|---|---|
| id | string | yes | The scheduled post id (post_…). |
| scheduledAt | string | – | Optional new ISO 8601 UTC fire time (future). |
| text | string | – | Optional new post body. |
| textOverrides | object | – | Optional new per-platform caption overrides, keyed by platform. Replaces the stored overrides. |
No output schema declared.
No examples provided.
engage ~188
Act on someone else's post or account: like, unlike, repost, unrepost, follow, unfollow, block, unblock, mute, unmute. One tool for all of them: pass the action. `target` is a post (an at:// uri or the post's web url) for like/repost, or a person (handle like alice.bsky.social) for follow/block/mute. Free on supported networks except X, where the write costs 6 credits. A network that does not support the action refuses and tells you what it does support, so nothing silently does nothing.
| Name | Type | Req | Description |
|---|---|---|---|
| account | string | yes | The connected account id (acc_…) acting. Use list_social_accounts to find it. |
| action | string | yes | What to do. |
| target | string | yes | A post uri/url for like and repost; a handle or account id for follow, block and mute. |
No output schema declared.
No examples provided.
get_analytics ~99
Cross-platform analytics over a period: decisions, not just measurements. Returns a readable summary, totals, a per-platform breakdown with engagement rates, recent daily activity, top posts, best posting times from this account's own history, and recommendations with their reason and confidence. Missing data is reported honestly, never fabricated. periodDays defaults to 30.
| Name | Type | Req | Description |
|---|---|---|---|
| periodDays | number | – | Lookback window in days (1–365, default 30). |
No output schema declared.
No examples provided.
get_connect_link ~135
Create a one-tap link the account owner can open to connect a social channel. Connecting requires a human: the networks make a person approve access on their own screen, and nothing can automate that. So when list_social_accounts is empty, or a channel shows needs_reauth, call this and give the person the link rather than telling them to find the dashboard. The link is signed, works once it is opened, and expires in 30 minutes. Optionally pass a profile to add the channel to that profile.
| Name | Type | Req | Description |
|---|---|---|---|
| profile | string | – | Optional profile username to attach the new channel to. Omit for the default. |
No output schema declared.
No examples provided.
get_credits ~87
The account's credit balance: total, the monthly allowance and what is left of it, and never-expiring pack credits. Publishing spends credits on every network. X also charges for reads, engagement, replies and messages. Check this before planning a batch, so you do not start work the balance cannot finish. Returns the same figures as whoami, for when you only need the balance.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
get_platform_capabilities ~128
Machine-readable capabilities per platform: character limits, media rules (required/video-only/max images/formats/sizes), whether a first comment is supported, whether publishing is async, and EVERY platformOptions field with its valid values. Call this before create_post to construct a valid post. Omit `platform` for all platforms.
| Name | Type | Req | Description |
|---|---|---|---|
| full | boolean | – | Return every field instead of the headline limits. Large (~4k tokens); only ask for it if the summary is not enough. |
| platform | string | – | Optional single platform, e.g. 'tiktok'. Omit for all. |
No output schema declared.
No examples provided.
get_post ~86
Fetch one post by id (post_…) as the COMPLETE record: text, any per-platform overrides, media, first comment, and every target with its state, live URL and error. Use this when you need the whole object; create_post already told you what happened, and list_posts gives you the summary rows.
| Name | Type | Req | Description |
|---|---|---|---|
| id | string | yes | The post id (post_…). |
No output schema declared.
No examples provided.
get_post_analytics ~107
Get normalised performance metrics for one post, per platform: impressions, views, likes, comments and shares, with the live URL. A platform whose analytics are not available yet says so in the cell rather than reporting zeros, because 'no data' and 'nobody saw it' are different answers. Follower counts are deliberately absent: they are an account-level number and mean nothing attached to a single post.
| Name | Type | Req | Description |
|---|---|---|---|
| id | string | yes | The post id (post_…). |
No output schema declared.
No examples provided.
get_publish_info ~77
Live creator-level publish constraints for one connected account (TikTok: available privacy options, whether comments/duet/stitch are allowed, max video duration for this creator). Use it to pick a valid privacyLevel before posting to TikTok.
| Name | Type | Req | Description |
|---|---|---|---|
| accountId | string | yes | A connected account id (acc_…) from list_social_accounts. |
No output schema declared.
No examples provided.
list_account_targets ~89
List the postable destinations INSIDE one connected account, for the platforms where a single login exposes several: Facebook Pages, Pinterest boards, YouTube channels. Pass the returned id in platformOptions when publishing. Accounts on platforms without sub-destinations return none, and you post to the account itself.
| Name | Type | Req | Description |
|---|---|---|---|
| accountId | string | yes | A connected account id (acc_…) from list_social_accounts. |
No output schema declared.
No examples provided.
list_conversations ~112
Direct message threads across every connected network that has them, most recent first, with who is in each, the last message and an unread count. Start here for 'any new DMs'. Cursor-paged. `problems` names any network that could not be read.
| Name | Type | Req | Description |
|---|---|---|---|
| account | string | – | Optional single account id (acc_…). Omit for all. |
| cursor | string | – | Opaque cursor from a previous page. |
| limit | number | – | 1-100 (default 25). |
No output schema declared.
No examples provided.
list_notifications ~170
What happened across every connected network since you last looked: likes, replies, mentions, follows, reposts and quotes, newest first, in ONE normalised shape. This is the read to start from when asked 'what needs my attention' or 'did anyone reply'. Cursor-paged: pass the returned `cursor` back verbatim for the next page. `problems` names any network that could not be read, so an empty list never silently means 'we could not look'.
| Name | Type | Req | Description |
|---|---|---|---|
| account | string | – | Optional: one connected account id (acc_…). Omit to read every connected network. |
| cursor | string | – | Opaque cursor from a previous page. Do not construct or parse one. |
| limit | number | – | Items per page, 1-100 (default 25). |
No output schema declared.
No examples provided.
list_posts ~127
List the caller's posts (most recent first), each with per-platform status. Pass state='scheduled' to see the upcoming schedule. Cursor pagination: pass `limit` (default 50, max 100) and `cursor` (the previous response's `nextCursor`).
| Name | Type | Req | Description |
|---|---|---|---|
| cursor | string | – | Opaque cursor from a prior response's `nextCursor`. Omit on the first page. |
| limit | integer | – | Page size, 1-100 (default 50). |
| state | string | – | Optional filter: queued | scheduled | partial | published | failed. |
No output schema declared.
No examples provided.
list_profiles ~68
List the caller's profiles: named buckets that group connected accounts, typically one per brand, client or project. The name is what you pass as `profile` when publishing, so call this first if you are not sure which one to post from. Most accounts have exactly one, called 'default'.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
list_social_accounts ~80
List every connected social account with its id, profile, platform, handle and connection status. Call this before publishing: the ids are what create_post takes in `accounts`. If none are connected, use get_connect_link for OAuth networks or connect_account for supported credential-based networks. A status of 'needs_reauth' means the owner must reconnect that channel.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
mark_notifications_seen ~72
Mark notifications as read on the networks that track that, so the next list_notifications only shows what is new. Call it after you have acted on what you read. Networks with no concept of 'seen' are skipped.
| Name | Type | Req | Description |
|---|---|---|---|
| account | string | – | Optional single account id (acc_…). Omit for all. |
No output schema declared.
No examples provided.
read_comments ~110
Read the replies people left on a post you published, across every network it went to, in one normalised shape. Use it to see how a post landed, or to find what needs answering. Takes the PostLake post id (post_…), not a network id.
| Name | Type | Req | Description |
|---|---|---|---|
| cursor | string | – | Opaque cursor from a previous page. |
| id | string | yes | The post id (post_…). |
| limit | number | – | Items per page, 1-100 (default 50). |
No output schema declared.
No examples provided.
read_conversation ~127
The messages in one DM thread, newest first. `fromMe` on each message tells you which side sent it, so you do not have to compare handles. Needs both the conversation id and the account it belongs to, because a conversation id only means something on one connection.
| Name | Type | Req | Description |
|---|---|---|---|
| account | string | yes | The connected account id (acc_…) the conversation belongs to. |
| cursor | string | – | Opaque cursor from a previous page. |
| id | string | yes | The conversation id from list_conversations. |
| limit | number | – | 1-100 (default 50). |
No output schema declared.
No examples provided.
rename_profile ~92
Rename a profile. The channels and posts inside it are untouched, but the identifier is re-derived from the new name, so anything holding the old `profile` string stops resolving. The response says whether the identifier actually moved, so you only have to update references when it did.
| Name | Type | Req | Description |
|---|---|---|---|
| name | string | yes | The new name, as a person would write it. |
| profile | string | yes | The current profile identifier. |
No output schema declared.
No examples provided.
reply_to_comment ~110
Reply to a comment someone left, by that comment's id (take it from read_comments). This is how an agent answers people, as opposed to create_post which publishes something new. Free on supported networks except X, where the write costs 6 credits. A network that cannot do this refuses and says so.
| Name | Type | Req | Description |
|---|---|---|---|
| account | string | yes | The connected account id (acc_…) replying. |
| comment | string | yes | The comment id from read_comments. |
| text | string | yes | The reply. |
No output schema declared.
No examples provided.
send_message ~155
Send a direct message. Give `conversation` to reply in an existing thread, or `to` (a handle) to start a new one. You do not need to find or create the conversation first. Links and mentions in the text are made real, not left as plain text. Free on supported networks except X, where the write costs 6 credits.
| Name | Type | Req | Description |
|---|---|---|---|
| account | string | yes | The connected account id (acc_…) sending it. |
| conversation | string | – | An existing conversation id. Omit if using `to`. |
| text | string | yes | What to say. |
| to | string | – | A handle to start a conversation with, e.g. alice.bsky.social. Omit if using `conversation`. |
No output schema declared.
No examples provided.
update_profile ~131
Change a connected account's own profile: display name, bio, avatar or banner. Only the fields you give are changed; the rest are left alone. Images are given as public URLs and uploaded for you. A network that does not allow this refuses and says so.
| Name | Type | Req | Description |
|---|---|---|---|
| account | string | yes | The connected account id (acc_…). |
| avatarUrl | string | – | Public URL of the new avatar image. |
| bannerUrl | string | – | Public URL of the new banner image. |
| bio | string | – | The profile description. |
| displayName | string | – | The name shown on the profile. |
No output schema declared.
No examples provided.
upload_media ~205
Prepare or upload media so it can be attached to posts. For a public asset, pass `url` and PostLake fetches it. For a file on the agent's own machine, omit `url`, pass `contentType` and preferably `sizeBytes`, then PUT the file bytes to the short-lived upload target returned by this tool. Both paths validate type/size (images ≤20MB: jpeg/png/webp/gif; videos ≤200MB: mp4/mov/webm) and produce a med_… id for create_post. Never put file bytes or base64 in the tool call.
| Name | Type | Req | Description |
|---|---|---|---|
| contentType | string | – | MIME type. Optional override for URL uploads; required for local-file uploads. |
| sizeBytes | integer | – | Local file size in bytes. Recommended for local uploads so the signed target is bound to the exact file size. |
| url | string | – | Publicly accessible URL of the image or video. Omit for a local file. |
No output schema declared.
No examples provided.
validate_post ~343
Dry-run a post WITHOUT publishing: runs the exact validation create_post would run (media rules, per-platform character limits, option values, whether a first comment can be posted at all) and returns per-target errors and warnings. It is free, so call it before create_post.
| Name | Type | Req | Description |
|---|---|---|---|
| accounts | array | – | Connected account ids (acc_…). An alternative (or addition) to `profile`. |
| firstComment | string | – | Optional first comment. Validating with it tells you which targets cannot post one. |
| firstCommentOverrides | object | – | Optional per-platform first-comment overrides, keyed by platform. |
| media | array | – | Optional media ids (med_…) from upload_media. The public url the upload returned is accepted too. |
| mediaAlt | array | – | Optional alt text per shared media item, aligned by index to `media`. |
| mediaAltOverrides | object | – | Optional alt text for override media, keyed by platform and aligned by index. |
| mediaOverrides | object | – | Optional per-platform media, keyed by platform. |
| platformOptions | object | – | Optional per-platform extras, namespaced by platform. |
| platforms | array | – | Optional filter: keep only these networks from the resolved set. |
| profile | string | – | A profile name. Validates against every account it owns. Alternative to `accounts`. |
| scheduledAt | string | – | Optional ISO 8601 UTC time. |
| text | string | yes | The post body (the master caption). |
| textOverrides | object | – | Optional per-platform caption overrides, keyed by platform. |
| thread | array | – | Optional follow-on post bodies. Validation warns for networks that do not support threads. |
No output schema declared.
No examples provided.
whoami ~112
Who you are and what you are allowed to do. Returns the account, the channels connected right now, the credit balance, and, when an agent is calling, ITS OWN limits: which profiles and networks it may post to, its daily cap, how many posts it has already made today and how many remain. Call this first: it is how you plan work you can actually complete, instead of finding the boundary by being refused. Limits are set by the account owner in the dashboard and cannot be changed from here.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
What is the PostLake MCP server?
PostLake is an MCP server listed in the public MCP registry as dev.postlake/social. Post, schedule, reply and measure across X, LinkedIn, Instagram, TikTok, YouTube, Threads, Bluesky. This page covers its hosted endpoint (https://api.postlake.dev/mcp).
Is the PostLake MCP server safe to use?
PostLake scores 34 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.
What tools does the PostLake MCP server expose?
PostLake exposes 33 tools: whoami, get_credits, get_platform_capabilities, get_publish_info, validate_post, and 28 more. Their descriptions and schemas cost roughly 4,639 tokens of context every time the server is loaded.
Does the PostLake MCP server require authentication?
Yes. PostLake asked us for credentials when we connected, so you will need to authorise it in your MCP client before it can do anything.
Is the PostLake MCP server still maintained?
PostLake is still listed as active in the MCP registry. We last reached this channel on 20 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.