# Chirpie (npm · @chirpie/mcp)

Post, schedule, and track social posts on X, Bluesky, LinkedIn, Instagram and more from AI agents.

- Trust score: 76/100 (medium)
- Change this week: +3
- Registry status: active
- Liveness: live
- Owner verified: no
- Last scored: 2026-09-20

## Components

- remote · `chirpie.ai`: 38/100, [markdown](https://verifymcp.io/servers/firefloco-chirpie/chirpie.md), [page](https://verifymcp.io/servers/firefloco-chirpie/chirpie)
- npm · `@chirpie/mcp`: 76/100 (this document), [markdown](https://verifymcp.io/servers/firefloco-chirpie/chirpie-mcp.md), [page](https://verifymcp.io/servers/firefloco-chirpie/chirpie-mcp)

## Channel facts

- Registry: `npm`
- Package: `@chirpie/mcp`
- Version: `1.0.21`
- Transport: `stdio`

## Trust breakdown

How this component scores in each security and reliability category. Every signal is checked automatically from public evidence about the published package, including repeated runs of it in an isolated sandbox, and we only credit what we can confirm. Scores are 0–100 per category. Scoring method: https://verifymcp.io/docs/scoring (what has changed: https://verifymcp.io/docs/scoring/changelog)

Scored 2026-09-20.

- **Supply Chain Security**: 98/100
  - No malware found by supply-chain analysis.
  - No known CVEs affecting this package version or its production dependencies.
  - No install/post-install scripts declared.
  - 31 of 96 dependencies flagged as unhealthy.
- **Provenance & Transparency**: 45/100
  - Source repository is publicly reachable at the declared URL.
  - Provenance check failed: no build-provenance attestation is published.
  - Clear OSI-approved license (MIT).
  - Actively maintained (last published 1 days ago).
  - Disclosure check failed: no security disclosure policy was found in the source repository.
- **Schema Quality & AI Usability**: 81/100
  - AI-judged instruction clarity (excellent).
  - Tool/resource definitions use about 1594 tokens (~75/item across 21 items; 21 tools + 0 resources), lean.
  - Usage-examples check failed: none of the tools include examples.
- **Stability & Change Management**: 50/100
  - Stability observed for 15 of 30 days with no destabilising changes; credit accrues until the full window elapses.
- **Tool Coverage**: 100/100
  - 100% of tools have a non-trivial description (not blank, and not just the tool's name).
  - 100% of tool parameters carry a description.
- **Tool Safety**: 75/100
  - No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.
  - 0 of 3 tool(s) whose name or description implies an irreversible operation declare an MCP destructiveHint annotation; "chirpie_delete_post" implies "delete" and declares no destructiveHint at all, which the MCP spec reads as destructive by default.
  - An AI judge read all 21 captured unit(s) of tool text and found none that tries to manipulate the model reading it.
- **Capabilities**: 100/100
  - Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.

## Install

### How do I install the Chirpie MCP server?

Chirpie runs locally as an npm package, launched with npx -y @chirpie/mcp. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.

### Claude

```bash
claude mcp add firefloco-chirpie -- npx -y @chirpie/mcp
```

### Cursor

```json
{
  "mcpServers": {
    "firefloco-chirpie": {
      "command": "npx",
      "args": [
        "-y",
        "@chirpie/mcp"
      ]
    }
  }
}
```

### VS Code

```json
{
  "servers": {
    "firefloco-chirpie": {
      "command": "npx",
      "args": [
        "-y",
        "@chirpie/mcp"
      ]
    }
  }
}
```

### Codex

```bash
codex mcp add firefloco-chirpie -- npx -y @chirpie/mcp
```

### opencode

```json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "firefloco-chirpie": {
      "type": "local",
      "command": [
        "npx",
        "-y",
        "@chirpie/mcp"
      ],
      "enabled": true
    }
  }
}
```

### OpenClaw

```bash
openclaw mcp add firefloco-chirpie --command npx --arg -y --arg @chirpie/mcp
```

### Hermes

```yaml
mcp_servers:
  firefloco-chirpie:
    command: "npx"
    args: ["-y", "@chirpie/mcp"]
```

### Netclaw

```json
{
  "McpServers": {
    "firefloco-chirpie": {
      "Transport": "stdio",
      "Command": "npx",
      "Arguments": [
        "-y",
        "@chirpie/mcp"
      ]
    }
  }
}
```

### Vellum

```bash
assistant mcp add firefloco-chirpie -t stdio -c npx -a -y @chirpie/mcp
```

### Other

```json
{
  "mcpServers": {
    "firefloco-chirpie": {
      "command": "npx",
      "args": [
        "-y",
        "@chirpie/mcp"
      ]
    }
  }
}
```

## Changelog

Every change recorded for this component, newest first. Days that predate change tracking, or that we cannot explain, say so: "we were watching and nothing happened" and "we were not watching" are different claims.

### 2026-09-18 (score 76, +1)

No change was recorded against any check on this day. Stability & Change Management went from 40 to 43. That category is still filling its 30-day observation window: 12 days of observed history at the previous scan, 13 at this one. The score rises as the window fills, whether or not the server changes.

### 2026-09-16 (score 75, +1)

No change was recorded against any check on this day. Stability & Change Management went from 33 to 37. That category is still filling its 30-day observation window: 10 days of observed history at the previous scan, 11 at this one. The score rises as the window fills, whether or not the server changes.

### 2026-09-14 (score 74, +1)

No change was recorded against any check on this day. Stability & Change Management went from 27 to 30. That category is still filling its 30-day observation window: 8 days of observed history at the previous scan, 9 at this one. The score rises as the window fills, whether or not the server changes.

### 2026-09-13 (score 73, +4)

- [functional improvement] Stability: unverified → 0.27

### 2026-09-06 (score 69, +15)

- [security improvement] Malware scan: unverified → pass

### 2026-09-05 (score 54)

First indexed and scored.

## MCP tools (21)

### `chirpie_post` (~381 tokens)

Create a post on X/Twitter, Bluesky, LinkedIn, Threads, Mastodon, Instagram, Facebook, or Telegram with optional media. Posts immediately or at a scheduled time. Note: Instagram REQUIRES media. X posts whose text contains a link are billed at $0.25 each on paid plans and are rejected on the Free plan (x_link_posts_require_paid_plan); X accounts connected with your own X API keys are exempt.

Input parameters:

- `account_id` (string, required): Account ID to post from (X, Bluesky, LinkedIn, Threads, Mastodon, Instagram, Facebook, or Telegram)
- `media_urls` (array): Public image URLs. X supports images + video (max 4); Bluesky supports images only (~1MB each, max 4); LinkedIn supports images (JPEG, PNG, GIF up to 8MB each, max 4). Threads supports one image per…
- `schedule_at` (string): ISO 8601 datetime to schedule the post. Must carry a timezone — '2026-04-01T14:00:00Z' or '2026-04-01T16:00:00+02:00' — and is normalized to UTC. Scheduled posts publish within ~5 minutes of this tim…
- `text` (string, required): Post text (max 280 chars for standard X, 25,000 for X Premium, 300 for Bluesky, 3,000 for LinkedIn, 500 for Threads, 500 for Mastodon, 2,200 for Instagram, 63,206 for Facebook, 4,096 for Telegram)

### `chirpie_thread` (~242 tokens)

Create a thread (multiple posts) on X/Twitter, Bluesky, LinkedIn, Threads, Mastodon, Instagram, Facebook, or Telegram. X, Bluesky, Threads, Mastodon, and Telegram support native reply threading. Others degrade gracefully to standalone posts. On X, each post in the thread whose text contains a link is billed at $0.25 on paid plans; on the Free plan such threads are rejected (x_link_posts_require_paid_plan). X accounts connected with your own X API keys are exempt.

Input parameters:

- `account_id` (string, required): Account ID to post from (X, Bluesky, LinkedIn, Threads, Mastodon, Instagram, Facebook, or Telegram). Some platforms degrade to standalone posts.
- `posts` (array, required): Array of posts in the thread
- `schedule_at` (string): ISO 8601 datetime to schedule the thread. Must carry a timezone — '2026-04-01T14:00:00Z' or '2026-04-01T16:00:00+02:00' — and is normalized to UTC. Scheduled threads publish within ~5 minutes of this…

### `chirpie_list_posts` (~61 tokens)

List recent posts. Filter by status or account.

Input parameters:

- `account_id` (string): Filter by account ID
- `limit` (number): Max results (default 20)
- `status` (string): Filter: draft, scheduled, published, failed

### `chirpie_get_post` (~26 tokens)

Get a single post by ID.

Input parameters:

- `id` (string, required): Post ID

### `chirpie_delete_post` (~37 tokens)

Delete a post. Also deletes it from the platform if it was already published.

Input parameters:

- `id` (string, required): Post ID to delete

### `chirpie_list_accounts` (~36 tokens)

List connected social accounts (X/Twitter, Bluesky, LinkedIn, Threads, Mastodon, Instagram, Facebook and Telegram).

### `chirpie_analytics` (~66 tokens)

Get analytics (likes, reposts, replies, etc.) for a published post on X, Bluesky, LinkedIn, Threads, Mastodon, Instagram or Facebook. Note: Telegram does not expose analytics.

Input parameters:

- `post_id` (string, required): Post ID to get analytics for

### `chirpie_create_key` (~64 tokens)

Create a new Chirpie API key. Returns the full key once — store it securely. Keys are prefixed `chirpie_sk_` and never re-shown by the API.

Input parameters:

- `name` (string): Friendly name for the key (default: 'Default')

### `chirpie_list_keys` (~31 tokens)

List the user's Chirpie API keys (prefix + metadata; the full key is only shown on creation).

### `chirpie_revoke_key` (~41 tokens)

Revoke a Chirpie API key by its ID. Revocation is permanent and immediate.

Input parameters:

- `id` (string, required): API key ID to revoke

### `chirpie_connect_x` (~37 tokens)

Start the OAuth flow for a X/Twitter account. Returns an authorization_url the user must open in a browser to complete the connection.

### `chirpie_connect_linkedin` (~37 tokens)

Start the OAuth flow for a LinkedIn account. Returns an authorization_url the user must open in a browser to complete the connection.

### `chirpie_connect_threads` (~35 tokens)

Start the OAuth flow for a Threads account. Returns an authorization_url the user must open in a browser to complete the connection.

### `chirpie_connect_instagram` (~36 tokens)

Start the OAuth flow for a Instagram account. Returns an authorization_url the user must open in a browser to complete the connection.

### `chirpie_connect_facebook` (~37 tokens)

Start the OAuth flow for a Facebook Pages account. Returns an authorization_url the user must open in a browser to complete the connection.

### `chirpie_connect_bluesky` (~65 tokens)

Connect a Bluesky account using an app password (create one at https://bsky.app/settings/app-passwords).

Input parameters:

- `app_password` (string, required): Bluesky app password
- `identifier` (string, required): Bluesky handle (e.g. user.bsky.social)

### `chirpie_connect_mastodon` (~47 tokens)

Start the OAuth flow for a Mastodon account on a specific instance.

Input parameters:

- `instance_url` (string, required): Mastodon instance URL (e.g. https://mastodon.social)

### `chirpie_connect_telegram` (~75 tokens)

Connect a Telegram bot. Create a bot with @BotFather on Telegram, then pass the bot token and the chat ID (user, group, or channel).

Input parameters:

- `bot_token` (string, required): Bot token from @BotFather
- `chat_id` (string, required): Target chat ID (user, group, or channel)

### `chirpie_set_x_keys` (~153 tokens)

Register the user's OWN X developer app (from developer.x.com) so their X accounts connect through it and post against their X API credits instead of Chirpie's. Link posts from accounts connected this way are not surcharged. After setting keys, the user must add the returned redirect_uri as a callback URI on their X app and then reconnect each X account (chirpie_connect_x) to move it onto their app.

Input parameters:

- `client_id` (string, required): OAuth 2.0 Client ID from developer.x.com
- `client_secret` (string, required): OAuth 2.0 Client Secret from developer.x.com. Stored encrypted and never returned.
- `label` (string): Optional human-readable name for the app

### `chirpie_get_x_keys_status` (~43 tokens)

Check whether the user has registered their own X developer app. Returns configuration status and the callback URI to register on the X app — never the client secret.

### `chirpie_remove_x_keys` (~44 tokens)

Remove the user's own X developer app. X accounts connected through it stop refreshing until the keys are re-added or the accounts are reconnected through Chirpie's app.

## Diagnostics

Captured diagnostic sections: Provenance, Dependencies. The full working is on the page: https://verifymcp.io/servers/firefloco-chirpie/chirpie-mcp#diagnostics

## Score history

- 2026-09-20: 76
- 2026-09-19: 76
- 2026-09-18: 76
- 2026-09-17: 75
- 2026-09-16: 75
- 2026-09-15: 74
- 2026-09-14: 74
- 2026-09-13: 73
- 2026-09-12: 69
- 2026-09-11: 69
- 2026-09-10: 69
- 2026-09-09: 69
- 2026-09-08: 69
- 2026-09-07: 69
- 2026-09-06: 69
- 2026-09-05: 54

## Common questions

### What is the Chirpie MCP server?

Chirpie is an MCP server listed in the public MCP registry as io.github.Firefloco/chirpie. Post, schedule, and track social posts on X, Bluesky, LinkedIn, Instagram and more from AI agents. This page covers its npm package (@chirpie/mcp).

### Is the Chirpie MCP server safe to use?

Chirpie scores 76 out of 100 on VerifyMCP. We found no known CVEs affecting it as of 20 September 2026. It declares no install or post-install scripts. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.

### What tools does the Chirpie MCP server expose?

Chirpie exposes 21 tools: chirpie_post, chirpie_thread, chirpie_list_posts, chirpie_get_post, chirpie_delete_post, and 16 more. Their descriptions and schemas cost roughly 1,594 tokens of context every time the server is loaded.

### Is the Chirpie MCP server still maintained?

Chirpie is still listed as active in the MCP registry. We last reached this channel on 20 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.

### What licence is the Chirpie MCP server under?

Chirpie declares the MIT licence, which is OSI-approved. That covers the source only, and says nothing about the cost of any service it calls.

## Links

- npm package: https://www.npmjs.com/package/@chirpie/mcp
- Socket report: https://socket.dev/npm/package/@chirpie/mcp
- Repository: https://github.com/Firefloco/chirpie-mcp
- Website: https://chirpie.ai/docs/mcp
- Changelog RSS feed: https://verifymcp.io/servers/firefloco-chirpie/chirpie-mcp.xml
- Changelog JSON feed: https://verifymcp.io/servers/firefloco-chirpie/chirpie-mcp.json
- HTML version of this page: https://verifymcp.io/servers/firefloco-chirpie/chirpie-mcp
