No description
Find a file
Paulo Castellano 4d8353d758
MCP: workspace settings, viewer read access, and token access (#241)
* Add workspace MCP settings and token access controls.

Ship MCP settings UI, OAuth revoke/list helpers, Passport deploy wiring,
and workspace.token:mcp gating so assistants can connect without pulling
in welcome/onboarding from the parent epic.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Type MCP client config shapes instead of string checks.

Encode http/config-root on each advanced client and tighten primary
client ids so snippet generation does not branch on magic strings.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Polish MCP settings follow-ups from review.

Translate Ukrainian MCP copy, deep-link ChatGPT into connector
creation, drop an unused asset and revoke arg, and assert PATs are
rejected on the MCP endpoint.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Harden MCP connected clients, revoke scope, and OAuth consent.

List recoverable sessions with live refresh tokens, revoke only PATs,
throttle registration alone, and block viewers from authorizing MCP.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Simplify MCP OAuth route throttling to a single middleware group.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Allow workspace viewers read-only MCP access with web policy writes.

Mirror the web app: MCP connects on view + OAuth mcp:use, write tools
enforce createPost/update/delete/manageAccounts/manageTeam, and demotion
to Viewer keeps grants. Cover role denials, consent, and disconnect.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Harden MCP tool authz with shared workspace helpers.

Route ApiKey tools through AuthorizesMcpTool, fail closed on null user
or policy argument, and resolve the current workspace before mutating.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Drop redundant string casts on validated request data.

Enum::from and validated() fields are already strings, so the casts
add noise without changing behavior.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Show only the current user's MCP connections in settings.

Match API keys privacy: list and disconnect your own OAuth clients,
not teammates' across the account.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Cover LoadWorkspaceFromToken gaps and harden AuthorizesMcpTool tests.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Drop redundant is_string guard before UpdatePostTool find.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Refactor AppSidebar to always show MCP link and simplify route middleware definition in ai.php. The MCP link is now consistently displayed regardless of the current workspace state, and the route middleware syntax has been streamlined.

* Refresh MCP connected clients with Inertia usePoll.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Bump laravel/mcp to 0.9.1 and add the TryPost server icon.

Requires laravel/boost 2.5 for the Icon attribute; expose images/trypost/icon.png on TryPostServer.

Co-authored-by: Cursor <cursoragent@cursor.com>

* Drop no-op ReflectionClass import in TryPostServerTest.

Co-authored-by: Cursor <cursoragent@cursor.com>

---------

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-08-06 09:54:51 -03:00
.agents/skills MCP: workspace settings, viewer read access, and token access (#241) 2026-08-06 09:54:51 -03:00
.claude MCP: workspace settings, viewer read access, and token access (#241) 2026-08-06 09:54:51 -03:00
.codex refactor: update documentation to remove Sail references and improve command usage 2026-07-23 12:44:14 -03:00
.cursor MCP: workspace settings, viewer read access, and token access (#241) 2026-08-06 09:54:51 -03:00
.github Update GitHub funding username (#227) 2026-08-03 13:15:28 -03:00
app MCP: workspace settings, viewer read access, and token access (#241) 2026-08-06 09:54:51 -03:00
bootstrap Add Telegram connection flow (controller + webhook) 2026-06-13 21:39:03 -03:00
config Add Ukrainian as a supported platform language (#219) 2026-08-05 19:45:30 -03:00
database MCP: workspace settings, viewer read access, and token access (#241) 2026-08-06 09:54:51 -03:00
docker MCP: workspace settings, viewer read access, and token access (#241) 2026-08-06 09:54:51 -03:00
lang MCP: workspace settings, viewer read access, and token access (#241) 2026-08-06 09:54:51 -03:00
maizzle fix(security): resolve npm audit in maizzle email toolchain 2026-05-21 20:29:32 -03:00
public MCP: workspace settings, viewer read access, and token access (#241) 2026-08-06 09:54:51 -03:00
releases feat(release): render a branded changelog thumbnail in the release ritual 2026-07-18 16:56:38 -03:00
resources MCP: workspace settings, viewer read access, and token access (#241) 2026-08-06 09:54:51 -03:00
routes MCP: workspace settings, viewer read access, and token access (#241) 2026-08-06 09:54:51 -03:00
storage chore: first commit 2026-01-14 22:13:44 -03:00
stubs feat: implement MCP server with tools, Post API tests, auth middleware 2026-03-29 20:30:36 -03:00
templates refactor: reorganize settings UI, migrate post templates to a file-based registry, and remove legacy video generation features 2026-05-03 13:44:13 -03:00
tests MCP: workspace settings, viewer read access, and token access (#241) 2026-08-06 09:54:51 -03:00
.dockerignore chore: add .dockerignore 2026-05-12 23:44:55 -03:00
.editorconfig chore: first commit 2026-01-14 22:13:44 -03:00
.env.ci feat: adding tests.. 2026-01-18 22:01:55 -03:00
.env.example MCP: workspace settings, viewer read access, and token access (#241) 2026-08-06 09:54:51 -03:00
.env.testing feat: improvements on ui 2026-01-21 20:50:57 -03:00
.gitattributes chore: first commit 2026-01-14 22:13:44 -03:00
.gitignore Crop the avatar/logo before upload with a dependency-free cropper 2026-07-03 21:46:19 -03:00
.mcp.json refactor: update documentation to remove Sail references and improve command usage 2026-07-23 12:44:14 -03:00
.prettierignore chore: first commit 2026-01-14 22:13:44 -03:00
.prettierrc chore: first commit 2026-01-14 22:13:44 -03:00
AGENTS.md MCP: workspace settings, viewer read access, and token access (#241) 2026-08-06 09:54:51 -03:00
artisan chore: first commit 2026-01-14 22:13:44 -03:00
boost.json MCP: workspace settings, viewer read access, and token access (#241) 2026-08-06 09:54:51 -03:00
Caddyfile feat(docker): add Caddy reverse proxy and domain-portable Reverb config 2026-05-27 14:53:46 -03:00
CLAUDE.md MCP: workspace settings, viewer read access, and token access (#241) 2026-08-06 09:54:51 -03:00
components.json chore: first commit 2026-01-14 22:13:44 -03:00
compose.override.yaml.example feat(docker): replace stale Sail compose with self-contained stack 2026-05-12 23:44:55 -03:00
compose.prod.yaml MCP: workspace settings, viewer read access, and token access (#241) 2026-08-06 09:54:51 -03:00
compose.yaml feat(docker): replace stale Sail compose with self-contained stack 2026-05-12 23:44:55 -03:00
composer.json MCP: workspace settings, viewer read access, and token access (#241) 2026-08-06 09:54:51 -03:00
composer.lock MCP: workspace settings, viewer read access, and token access (#241) 2026-08-06 09:54:51 -03:00
eslint.config.js fix: address PR review findings — publish, REST store, SSRF, race 2026-05-04 12:16:39 -03:00
GEMINI.md Upgrade Pest from v4 to v5 (PHPUnit 13). 2026-07-31 01:40:50 +00:00
LICENSE.md chore: update project license from FSL to AGPL-3.0-only 2026-05-04 15:46:56 -03:00
package-lock.json Remove the Vitest frontend unit-test layer 2026-07-04 10:53:08 -03:00
package.json Remove the Vitest frontend unit-test layer 2026-07-04 10:53:08 -03:00
phpunit.xml feat: adding tests 2026-01-18 22:04:34 -03:00
pint.json chore: first commit 2026-01-14 22:13:44 -03:00
README.md Add Ukrainian as a supported platform language (#219) 2026-08-05 19:45:30 -03:00
tsconfig.json chore: first commit 2026-01-14 22:13:44 -03:00
vite.config.ts chore: add resources/css/app.css to vite build input 2026-05-03 20:30:34 -03:00

TryPost

Run your whole social presence from one calendar

An open-source social media scheduler with an AI copilot, native publishing to 12 networks,
and an MCP server so your AI assistant can post for you. Self-host it, or skip the setup on cloud.

Stars License Release Discussions

Try on Cloud  •  Documentation  •  Community

TryPost — plan, write, and publish from one calendar


What you get

📅  One calendar, every network Plan a month at a glance, drag any post to a new slot, and publish natively to 12 platforms. No redirects, no "finish in the mobile app."
  An AI copilot that knows your brand Captions, hooks, full drafts, and multi-slide carousels in your tone, voice, and colors. It reads your brand profile on every generation.
🤖  Built for AI agents A first-class MCP server and REST API. Claude, Cursor, ChatGPT, or your own scripts can draft, schedule, and publish for you.
⚙️  Automations that run themselves A visual workflow builder: triggers, conditions, RSS, webhooks, and AI generation, all server-side. Set it once, let it post.
🗂️  Made for many clients Workspaces, roles, and approval flows so an agency or freelancer can run a roster of brands without the spreadsheets.

Features

Visual calendar Month, week, and day views. Drag and drop to reschedule across networks.
Multi-platform composer Write once, then tailor the preview per network in parallel.
AI generate & review Draft from a prompt, get inline feedback before you publish.
AI carousel builder Prompt to a multi-slide carousel with images, on-brand.
Brand profile Tone, voice, language, and colors applied to every AI call.
Automations Schedule / RSS triggers, conditions, publish steps, and webhooks.
Asset library Reusable workspace media, plus Unsplash and Giphy search built in.
Signatures & labels Reusable hashtag and CTA blocks, color-coded post tags.
Team collaboration Owner / Admin / Member roles, comments with @mentions on drafts.
Workspaces Isolate each brand, client, or project in its own space.
REST API + MCP Full programmatic control; AI assistants integrate natively.
Native analytics Per-account reach and engagement across every connected platform.
Multi-language English, Ukrainian, Spanish, Portuguese, French, German, Italian, Dutch, Polish, Greek, Japanese, Korean, Chinese, Russian, Turkish, and Arabic.

Supported platforms

Posts publish natively through each platform's official API.


Instagram

Facebook

LinkedIn

X (Twitter)

TikTok

YouTube

Pinterest

Threads

Bluesky

Mastodon

Telegram

Discord

Get started

☁️  Cloud The fastest way in. We host, update, and scale it for you. Start at trypost.it →
🛠️  Self-host Free forever, your servers, your data. Installation guide →
🤖  Drive it with AI Connect Claude, Cursor, or ChatGPT over MCP. MCP setup →

Own your stack

TryPost is open source on purpose. Self-host it and your posts, drafts, and metrics stay on your infrastructure, under a license that is yours to keep. No seat tax, no feature gates, no vendor deciding when to lock you out. Read every line, fork it, and ship it. When you would rather not run servers, the same product is one click away on cloud.

Contributing

Contributions of any size are welcome. Pick an issue, say hi in Discussions, or open a PR with what you would like to see.

Short on time? A star is the most valuable thing you can give. It helps more people find the project.

License

GNU Affero General Public License v3.0. Use, modify, fork, self-host, and redistribute, including commercially. If you run a modified version as a network service, make your changes available to its users (AGPL §13).


Built in the open. Star TryPost on GitHub and tell a friend.