Hosted Streamable HTTP MCP
Connect your AI to the accounts you already own.
Social Fanout gives compatible MCP clients a per-user OAuth path to inspect connected accounts, dry-run exact posts, publish or schedule, and read a separate receipt for every account result.
https://socialfanout.com/mcp
Prefer the raw guide? Markdown version
Bounded publishing
What the hosted connector can do
- List available providers and accounts connected to the selected Social Fanout key.
- Inspect account-specific formats, media rules, required fields, and scheduling support.
- Dry-run one post without contacting the social provider or consuming publish quota.
- Publish now or schedule one post to one selected account per tool call.
- List jobs, inspect status and provider receipts, and cancel an unclaimed scheduled job.
- Start a first-party handoff for connecting another social account.
Per-user OAuth
Authorize one key without sharing it in chat
Add the endpoint
Add
https://socialfanout.com/mcpas a custom connector in a compatible client, or choose Social Fanout after a directory listing becomes available.Sign in to Social Fanout
Follow the first-party sign-in prompt. Never paste a Social Fanout API key or a social-platform token into chat.
Select the exact key
Choose one active Social Fanout key that you own and approve the named OAuth client. Its connector access is limited to the accounts and entitlement attached to that key.
Keep control
Review or revoke the application in Dashboard → Authorized assistants. Revocation blocks future connector calls.
The hosted connector does not return the selected API key or stored social-platform credentials to the MCP client.
Exact-action confirmation
Dry-run the request Claude or ChatGPT will actually send
Inspect first
List connections and capabilities, then choose one exact account. Use the selected connection ID as
accountId; optionalconnectionIdmust match it.Run a preflight
Call
fanout_publish_postwithdryRun: truefor the exact content, destination, media, options, and schedule.Review the tokenized result
A successful dry run returns a short-lived
confirmationTokenandconfirmationExpiresAt. Review that result before the live call.Reuse it unchanged
For the approved live request, pass the same token with
dryRun: falseand leave every publish field unchanged.
Data handling
What is sent, recorded, and under your control
The connector sends Social Fanout the signed-in account context and fields needed for the requested operation. Publishing can include post text, media URLs, a selected account identifier, provider-specific options, and a schedule. A live publish sends those fields onward to the selected social provider. Provider credentials stay on Social Fanout's servers.
Social Fanout records content-free authorization, revocation, and tool events for security, audit, support, reliability, capacity planning, and trusted Claude/OpenAI attribution. They can contain an event and tool name, outcome, dry-run state, trusted source classification, opaque key and grant identifiers, a key fingerprint, a one-way OAuth client-ID hash, and timestamps. They exclude post text, media URLs, destination or social-account identifiers, email addresses, access tokens, raw API keys, and the raw OAuth client ID.
Connector grants remain until revoked, the selected key becomes unavailable, or the account is deleted. Connector events remain until account deletion or operational cleanup; no fixed automatic purge interval is currently claimed. Revocation blocks future calls but does not immediately erase historical content-free events. Read the Privacy Policy for deletion and other controls.
Existing alternatives remain
Use the credential boundary that fits your client
- Local stdio MCP: the package runs on your machine and calls Social Fanout with a customer-owned API key.
- Private GPT Action: import the hosted OpenAPI schema into a custom GPT where Actions are available and configure a customer-owned Bearer key.
- REST API: integrate server to server, including the separate multi-target request shape.
These API-key paths are documented in the Quickstart and are distinct from the hosted OAuth connector.