No description
Find a file
Paulo Castellano 2ca5948309
Scope MCP OAuth tokens to user + workspace (#222) (#245)
* Scope MCP OAuth tokens to user + workspace

Bind authorization-code grants to the authorizing workspace (via auth codes),
inherit workspace on refresh, resolve MCP/API requests from the token instead
of current_workspace_id, backfill existing grants, and revoke workspace tokens
when a member is removed.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Add multi-workspace MCP OAuth coverage

Cover coexistence of the same client across workspaces, settings
list/disconnect scoped to the current workspace, and API key
controllers excluding workspace-bound MCP grants.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Use constrained foreignUuid for oauth_auth_codes.workspace_id

Match the project's UUID foreign-key convention instead of a separate
foreign() call.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Localize the MCP OAuth authorize consent screen

Wire authorize.blade.php to mcp.* translation keys (including the
workspace scope copy) and cover pt-BR rendering.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Fix invalid Mockery import in bind workspace test

CI treats the non-compound `use Mockery` as an ErrorException and
aborts the whole parallel suite.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Inline MCP OAuth workspace backfill into the migration

Move the one-shot backfill out of a dedicated Action and wrap it in an
explicit transaction so a failure rolls back partial binds/revokes.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Nest MCP authorize i18n keys and test backfill rollback

Group consent-screen copy under mcp.authorize.*, and assert the
workspace backfill migration rolls back binds when it fails before
commit.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Hardcode TryPost in the MCP authorize page title

Drop the config('app.name') interpolation from the consent screen title.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Add workspace picker to MCP OAuth consent screen

Let users choose which workspace to bind at authorize time instead of
always using current_workspace_id; silent re-consent still falls back.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Tighten MCP authorize workspace select spacing

Match NativeSelect styling and give the label, control, and helper text room to breathe.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Convert MCP OAuth consent screen to Inertia Vue

Reuse AuthCardLayout, Button, and NativeSelect so the authorize page
matches the app UI. Keep native form posts so Passport's external
redirect still works for MCP client popups.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Polish MCP authorize layout with logo and workspace combobox

Drop the shield and AuthCardLayout double-logo, put TryPost branding
at the top, and reuse the app Combobox pattern for workspace search.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Align MCP OAuth workspace backfill with mcpOAuth scope

Reuse AccessToken::mcpOAuth() so the migration only touches mcp:use
grants on non-PAT clients, matching the rest of the codebase.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Tighten MCP OAuth workspace backfill heuristics

Only touch connected MCP sessions, bind a sole membership or a valid
current workspace, and revoke ambiguous multi-workspace grants instead
of guessing the oldest workspace.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Drop Passport connection override from auth code migration

Always use the app default database connection from .env.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Bind MCP OAuth workspace in AccessTokenRepository

Replace the AccessTokenCreated listener with the same Passport repository
override pattern used for auth codes, so workspace_id is set at persist.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Simplify AccessTokenRepository workspace binding

Drop redundant string casts and the oldest-workspace fallback; keep a
small ownedWorkspace/payloadId helper surface instead.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Extract Passport MCP authorization view from AppServiceProvider

Keep configurePassport thin by moving the Inertia consent props into an
invokable App\Passport\AuthorizationView class.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Simplify AuthorizationView and cover it with direct tests

Use collection higher-order mapping for workspaces/scopes and add focused
tests for current-workspace selection and empty-user props.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Rename BindWorkspaceToAccessTokenTest after listener removal

The suite now covers AuthCodeRepository and AccessTokenRepository
workspace binding, not an AccessTokenCreated listener.

* Fail closed when auth code has no bindable workspace

Authorization-code grants no longer fall back to the user's current
workspace, so a token cannot be minted for a different tenant than consent.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Retrigger CI after GitHub Actions infrastructure failures

Co-authored-by: Cursor <cursoragent@cursor.com>

* chore: retrigger CI

Co-authored-by: Cursor <cursoragent@cursor.com>

* fix: harden MCP OAuth workspace binding on refresh and backfill

Co-authored-by: Cursor <cursoragent@cursor.com>

* fix: always show MCP OAuth consent to pick a workspace

Disable Passport silent re-consent and require an explicit workspace_id
from the consent form, with Passport wiring moved to its own provider.

Co-authored-by: Cursor <cursoragent@cursor.com>

* fix: sort MCP connected clients by last used

Show most recently used OAuth connections first on the workspace MCP settings page.

Co-authored-by: Cursor <cursoragent@cursor.com>

---------

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-08-06 21:59:34 -03:00
.agents/skills MCP: workspace settings, viewer read access, and token access (#241) 2026-08-06 09:54:51 -03:00
.claude MCP: workspace settings, viewer read access, and token access (#241) 2026-08-06 09:54:51 -03:00
.codex refactor: update documentation to remove Sail references and improve command usage 2026-07-23 12:44:14 -03:00
.cursor MCP: workspace settings, viewer read access, and token access (#241) 2026-08-06 09:54:51 -03:00
.github Update GitHub funding username (#227) 2026-08-03 13:15:28 -03:00
app Scope MCP OAuth tokens to user + workspace (#222) (#245) 2026-08-06 21:59:34 -03:00
bootstrap Scope MCP OAuth tokens to user + workspace (#222) (#245) 2026-08-06 21:59:34 -03:00
config fix: Pinterest video processing timeout — longer poll + retry (#246) 2026-08-06 20:49:37 -03:00
database Scope MCP OAuth tokens to user + workspace (#222) (#245) 2026-08-06 21:59:34 -03:00
docker MCP: workspace settings, viewer read access, and token access (#241) 2026-08-06 09:54:51 -03:00
lang Scope MCP OAuth tokens to user + workspace (#222) (#245) 2026-08-06 21:59:34 -03:00
maizzle fix(security): resolve npm audit in maizzle email toolchain 2026-05-21 20:29:32 -03:00
public MCP: workspace settings, viewer read access, and token access (#241) 2026-08-06 09:54:51 -03:00
releases feat(release): render a branded changelog thumbnail in the release ritual 2026-07-18 16:56:38 -03:00
resources Scope MCP OAuth tokens to user + workspace (#222) (#245) 2026-08-06 21:59:34 -03:00
routes Welcome: pre-subscription funnel and member subscription-required screen (#243) 2026-08-06 11:34:50 -03:00
storage chore: first commit 2026-01-14 22:13:44 -03:00
stubs feat: implement MCP server with tools, Post API tests, auth middleware 2026-03-29 20:30:36 -03:00
templates refactor: reorganize settings UI, migrate post templates to a file-based registry, and remove legacy video generation features 2026-05-03 13:44:13 -03:00
tests Scope MCP OAuth tokens to user + workspace (#222) (#245) 2026-08-06 21:59:34 -03:00
.dockerignore chore: add .dockerignore 2026-05-12 23:44:55 -03:00
.editorconfig chore: first commit 2026-01-14 22:13:44 -03:00
.env.ci feat: adding tests.. 2026-01-18 22:01:55 -03:00
.env.example MCP: workspace settings, viewer read access, and token access (#241) 2026-08-06 09:54:51 -03:00
.env.testing feat: improvements on ui 2026-01-21 20:50:57 -03:00
.gitattributes chore: first commit 2026-01-14 22:13:44 -03:00
.gitignore Crop the avatar/logo before upload with a dependency-free cropper 2026-07-03 21:46:19 -03:00
.mcp.json refactor: update documentation to remove Sail references and improve command usage 2026-07-23 12:44:14 -03:00
.prettierignore chore: first commit 2026-01-14 22:13:44 -03:00
.prettierrc chore: first commit 2026-01-14 22:13:44 -03:00
AGENTS.md MCP: workspace settings, viewer read access, and token access (#241) 2026-08-06 09:54:51 -03:00
artisan chore: first commit 2026-01-14 22:13:44 -03:00
boost.json MCP: workspace settings, viewer read access, and token access (#241) 2026-08-06 09:54:51 -03:00
Caddyfile feat(docker): add Caddy reverse proxy and domain-portable Reverb config 2026-05-27 14:53:46 -03:00
CLAUDE.md MCP: workspace settings, viewer read access, and token access (#241) 2026-08-06 09:54:51 -03:00
components.json chore: first commit 2026-01-14 22:13:44 -03:00
compose.override.yaml.example feat(docker): replace stale Sail compose with self-contained stack 2026-05-12 23:44:55 -03:00
compose.prod.yaml MCP: workspace settings, viewer read access, and token access (#241) 2026-08-06 09:54:51 -03:00
compose.yaml feat(docker): replace stale Sail compose with self-contained stack 2026-05-12 23:44:55 -03:00
composer.json Bump Inertia to laravel 3.3.1 and vue3 3.6.1. (#242) 2026-08-06 10:08:24 -03:00
composer.lock Bump Inertia to laravel 3.3.1 and vue3 3.6.1. (#242) 2026-08-06 10:08:24 -03:00
eslint.config.js fix: address PR review findings — publish, REST store, SSRF, race 2026-05-04 12:16:39 -03:00
GEMINI.md Upgrade Pest from v4 to v5 (PHPUnit 13). 2026-07-31 01:40:50 +00:00
LICENSE.md chore: update project license from FSL to AGPL-3.0-only 2026-05-04 15:46:56 -03:00
package-lock.json Bump Inertia to laravel 3.3.1 and vue3 3.6.1. (#242) 2026-08-06 10:08:24 -03:00
package.json Bump Inertia to laravel 3.3.1 and vue3 3.6.1. (#242) 2026-08-06 10:08:24 -03:00
phpunit.xml feat: adding tests 2026-01-18 22:04:34 -03:00
pint.json chore: first commit 2026-01-14 22:13:44 -03:00
README.md Add Ukrainian as a supported platform language (#219) 2026-08-05 19:45:30 -03:00
tsconfig.json chore: first commit 2026-01-14 22:13:44 -03:00
vite.config.ts chore: add resources/css/app.css to vite build input 2026-05-03 20:30:34 -03:00

TryPost

Run your whole social presence from one calendar

An open-source social media scheduler with an AI copilot, native publishing to 12 networks,
and an MCP server so your AI assistant can post for you. Self-host it, or skip the setup on cloud.

Stars License Release Discussions

Try on Cloud  •  Documentation  •  Community

TryPost — plan, write, and publish from one calendar


What you get

📅  One calendar, every network Plan a month at a glance, drag any post to a new slot, and publish natively to 12 platforms. No redirects, no "finish in the mobile app."
  An AI copilot that knows your brand Captions, hooks, full drafts, and multi-slide carousels in your tone, voice, and colors. It reads your brand profile on every generation.
🤖  Built for AI agents A first-class MCP server and REST API. Claude, Cursor, ChatGPT, or your own scripts can draft, schedule, and publish for you.
⚙️  Automations that run themselves A visual workflow builder: triggers, conditions, RSS, webhooks, and AI generation, all server-side. Set it once, let it post.
🗂️  Made for many clients Workspaces, roles, and approval flows so an agency or freelancer can run a roster of brands without the spreadsheets.

Features

Visual calendar Month, week, and day views. Drag and drop to reschedule across networks.
Multi-platform composer Write once, then tailor the preview per network in parallel.
AI generate & review Draft from a prompt, get inline feedback before you publish.
AI carousel builder Prompt to a multi-slide carousel with images, on-brand.
Brand profile Tone, voice, language, and colors applied to every AI call.
Automations Schedule / RSS triggers, conditions, publish steps, and webhooks.
Asset library Reusable workspace media, plus Unsplash and Giphy search built in.
Signatures & labels Reusable hashtag and CTA blocks, color-coded post tags.
Team collaboration Owner / Admin / Member roles, comments with @mentions on drafts.
Workspaces Isolate each brand, client, or project in its own space.
REST API + MCP Full programmatic control; AI assistants integrate natively.
Native analytics Per-account reach and engagement across every connected platform.
Multi-language English, Ukrainian, Spanish, Portuguese, French, German, Italian, Dutch, Polish, Greek, Japanese, Korean, Chinese, Russian, Turkish, and Arabic.

Supported platforms

Posts publish natively through each platform's official API.


Instagram

Facebook

LinkedIn

X (Twitter)

TikTok

YouTube

Pinterest

Threads

Bluesky

Mastodon

Telegram

Discord

Get started

☁️  Cloud The fastest way in. We host, update, and scale it for you. Start at trypost.it →
🛠️  Self-host Free forever, your servers, your data. Installation guide →
🤖  Drive it with AI Connect Claude, Cursor, or ChatGPT over MCP. MCP setup →

Own your stack

TryPost is open source on purpose. Self-host it and your posts, drafts, and metrics stay on your infrastructure, under a license that is yours to keep. No seat tax, no feature gates, no vendor deciding when to lock you out. Read every line, fork it, and ship it. When you would rather not run servers, the same product is one click away on cloud.

Contributing

Contributions of any size are welcome. Pick an issue, say hi in Discussions, or open a PR with what you would like to see.

Short on time? A star is the most valuable thing you can give. It helps more people find the project.

License

GNU Affero General Public License v3.0. Use, modify, fork, self-host, and redistribute, including commercially. If you run a modified version as a network service, make your changes available to its users (AGPL §13).


Built in the open. Star TryPost on GitHub and tell a friend.