{
  "data": {
    "a": {
      "slug": "postiz",
      "name": "Postiz API + MCP",
      "vendor": "Postiz (Gitroom)",
      "vendorUrl": "https://postiz.com",
      "kind": "http-api",
      "category": "social-media",
      "summary": "Open-source social scheduler (AGPL-3.0) for 34 platforms that you can self-host free or use as Postiz Cloud from $29 a month.",
      "url": "https://www.anchorterminal.com/tools/postiz",
      "markdownUrl": "https://www.anchorterminal.com/tools/postiz.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/postiz.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/postiz.json",
      "repo": "https://github.com/gitroomhq/postiz-app",
      "license": "AGPL-3.0",
      "transports": [
        "http",
        "streamable-http"
      ],
      "remoteUrl": "https://api.postiz.com/public/v1",
      "packages": [
        {
          "registry": "npm",
          "name": "@postiz/node"
        },
        {
          "registry": "npm",
          "name": "postiz"
        }
      ],
      "auth": "mixed",
      "authNotes": "API key sent raw in the Authorization header (no Bearer prefix), or an OAuth app token prefixed pos_. The MCP accepts a Bearer header at /mcp, an OAuth flow at /mcp-oauth, or the key in the URL path at /mcp/{key}. Self-hosted instances need their own developer apps for each network.",
      "pricing": "paid",
      "pricingNotes": "Self-hosting is free under AGPL-3.0, but you register your own developer app with each network. Postiz Cloud has no free plan (7-day trial, card policy not stated). Standard $29 a month or $23 billed yearly (5 channels), Team $39 or $31 (10), Pro $49 or $39 (30), Ultimate $99 or $79 (100). API, CLI, webhooks and MCP on every plan, posts unlimited. The terms make fees non-refundable (https://postiz.com/pricing).",
      "priceSummary": "$29 / mo",
      "where": "hosted",
      "x402": {
        "level": "no",
        "evidence": "No x402 in docs, llms.txt or pricing (checked 2026-09-30).",
        "endpoints": []
      },
      "toolCount": 13,
      "popularity": {
        "githubStars": 36531,
        "npmWeekly": 368,
        "pypiWeekly": null,
        "asOf": "2026-09-30"
      },
      "docsUrl": "https://docs.postiz.com",
      "llmsTxt": "https://docs.postiz.com/llms.txt",
      "openapi": "https://docs.postiz.com/public-api/openapi.json",
      "capabilities": [
        "social.post",
        "social.schedule",
        "social.analytics",
        "social.media-upload"
      ],
      "tags": [
        "hosted",
        "self-hosted",
        "local",
        "open-source",
        "mcp",
        "llms-txt",
        "openapi",
        "typescript",
        "webhooks"
      ],
      "lastRelease": "2026-09-22",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 59.3,
        "grade": "C",
        "agentReady": false,
        "rank": 381,
        "ranked": true,
        "rankOf": 629,
        "categoryRank": 3,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 65,
          "maintenance": 85,
          "payments": 30,
          "reliability": 53,
          "schema": 88,
          "security": 49,
          "transparency": 81
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-01"
        },
        "negative": -3,
        "negativeNotes": [
          "2026-07-20 and 2026-09-22. Three security fixes in the last 12 months. A path traversal in the self-hosted upload route that could read files outside UPLOAD_DIRECTORY, fixed in commit 7936062 labelled critical, and CVE-2026-94455 (enterprise endpoints accepting other JWT types) and CVE-2026-94456 (non-cryptographic IDs for OAuth secrets and codes), fixed on 22 September. All fixed and the latter two given CVEs, so we deduct less. -3 (https://github.com/gitroomhq/postiz-app/commit/793606226f981706cc0201c8023f0f2b57ce08e4, https://github.com/gitroomhq/postiz-app/commit/9259cf2429e8cc0c88414e88d5e6c783d7ffba63)"
        ],
        "verdict": "AGPL-3.0 and self-hostable with the API and MCP included, 34 platforms. Create-post capped at 90 requests an hour on every Cloud plan.",
        "bestFor": "Teams that want to self-host, or want 34 platforms including Mastodon, Farcaster, Discord and Slack on a flat plan.",
        "strengths": [
          "AGPL-3.0 and self-hostable with the API and MCP included, 34 platforms",
          "OpenAPI 3.1 spec with 27 paths, llms.txt and Markdown docs",
          "MCP tools in source carry readOnlyHint, destructiveHint and idempotentHint, with when-not-to-use guidance",
          "v2.24.0 on 22 September 2026, and CVEs assigned and fixed through a published disclosure process",
          "Flat Cloud plans from $29 a month ($23 yearly) with unlimited posts"
        ],
        "weaknesses": [
          "Create-post capped at 90 requests an hour on every Cloud plan",
          "One organisation key with no scopes, and the MCP OAuth grant is always read and write",
          "The docs document the API key in the MCP URL path at /mcp/{key}",
          "No idempotency key and no Retry-After guidance",
          "Self-hosting means your own developer app and review with each network"
        ],
        "agentNotes": [
          "Send the key as the `Authorization` header with no `Bearer` prefix on REST calls",
          "Batch several posts into one create request to stay under 90 an hour",
          "Call integrationSchema (Get Settings) for a channel before scheduling, since each network has its own settings",
          "Use the Bearer header on /mcp rather than /mcp/{key} so the key stays out of logs",
          "Read output.errors on a failed schedule call and retry with the corrected fields"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 2,
        "avgRating": 3,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "C",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 59.3
          }
        ],
        "editorialScores": {
          "ergonomics": 65,
          "maintenance": 85,
          "payments": 30,
          "reliability": 53,
          "schema": 88,
          "security": 49,
          "transparency": 75
        },
        "provenanceScore": 87
      },
      "connect": {
        "http": "curl https://api.postiz.com/public/v1/integrations -H \"Authorization: $POSTIZ_API_KEY\"",
        "claudeCode": "claude mcp add --transport http postiz https://mcp.postiz.com/mcp --header \"Authorization: Bearer $POSTIZ_API_KEY\""
      },
      "letme": {
        "capability": "https://letme.dev/social.post",
        "tool": "https://letme.dev/postiz"
      },
      "area": "communication",
      "unitPrices": [
        {
          "item": "Standard plan",
          "unit": "month",
          "usd": 29,
          "note": "5 channels. $278 a year"
        },
        {
          "item": "Team plan",
          "unit": "month",
          "usd": 39,
          "note": "10 channels. $374 a year"
        },
        {
          "item": "Pro plan",
          "unit": "month",
          "usd": 49,
          "note": "30 channels. $470 a year"
        },
        {
          "item": "Ultimate plan",
          "unit": "month",
          "usd": 99,
          "note": "100 channels. $950 a year"
        }
      ],
      "provenance": {
        "legalEntity": "Gitroom Limited",
        "domain": "postiz.com",
        "domainRegistered": "2013-06-24",
        "domainNote": "postiz.com was registered in 2013, well before the project started in 2023.",
        "endpointOnVendorDomain": true,
        "terms": "https://postiz.com/terms-of-service",
        "privacy": "https://postiz.com/privacy-policy",
        "statusPage": "https://status.postiz.com",
        "changelog": "https://github.com/gitroomhq/postiz-app/releases",
        "securityTxt": "none",
        "checked": "2026-09-30",
        "notes": [
          "Terms name Gitroom Limited (seller of paid plans) and Gitroom LLC together as Postiz"
        ],
        "score": 87
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/postiz.json",
      "live": {
        "slug": "postiz",
        "probe": {
          "target": "https://api.postiz.com/public/v1",
          "method": "get",
          "lastAt": "2026-10-08T19:08:56.205835916Z",
          "lastOk": true,
          "lastStatus": 404,
          "lastMs": 178,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 187,
          "p95ms24h": 341,
          "samples24h": 272,
          "samples30d": 2135,
          "days": [
            {
              "date": "2026-09-30",
              "probes": 35,
              "ok": 35
            },
            {
              "date": "2026-10-01",
              "probes": 276,
              "ok": 276
            },
            {
              "date": "2026-10-02",
              "probes": 248,
              "ok": 248
            },
            {
              "date": "2026-10-03",
              "probes": 271,
              "ok": 271
            },
            {
              "date": "2026-10-04",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-05",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-06",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-07",
              "probes": 272,
              "ok": 272
            },
            {
              "date": "2026-10-08",
              "probes": 217,
              "ok": 217
            }
          ]
        },
        "vendorStatus": {
          "page": "https://status.postiz.com",
          "indicator": "unknown",
          "summary": "no machine-readable status found",
          "checkedAt": "2026-10-08T17:51:07.521811965Z"
        },
        "versions": [
          {
            "registry": "github",
            "name": "gitroomhq/postiz-app",
            "version": "v2.25.0",
            "released": "2026-10-02",
            "seenAt": "2026-10-08T16:26:09.775428592Z"
          },
          {
            "registry": "npm",
            "name": "@postiz/node",
            "version": "1.0.8",
            "seenAt": "2026-10-08T16:26:07.568068399Z"
          },
          {
            "registry": "npm",
            "name": "postiz",
            "version": "2.0.16",
            "seenAt": "2026-10-08T16:26:08.499034234Z"
          }
        ],
        "githubStars": 36888,
        "npmWeekly": 250,
        "securityTxt": {
          "url": "https://postiz.com/.well-known/security.txt",
          "state": "none",
          "checkedAt": "2026-10-08T15:38:57.479352402Z"
        },
        "llmsTxt": {
          "url": "https://docs.postiz.com/llms.txt",
          "ok": true,
          "status": 200,
          "checkedAt": "2026-10-08T14:00:46.892969678Z"
        },
        "domain": {
          "domain": "postiz.com",
          "registered": "2013-06-24",
          "source": "https://rdap.verisign.com/com/v1/domain/postiz.com",
          "checkedAt": "2026-10-04T13:06:04.948008258Z"
        },
        "pages": [
          {
            "url": "https://postiz.com/pricing",
            "kind": "pricing",
            "status": 200,
            "checkedAt": "2026-10-08T18:23:13.930763761Z",
            "changedAt": "2026-10-02T15:23:11.667972444Z",
            "fingerprint": "b43a89c371d7"
          },
          {
            "url": "https://postiz.com/privacy-policy",
            "kind": "privacy",
            "status": 200,
            "checkedAt": "2026-10-08T18:23:16.131162524Z",
            "changedAt": "2026-10-02T15:23:13.868758528Z",
            "fingerprint": "d9718ddb538b"
          },
          {
            "url": "https://postiz.com/terms-of-service",
            "kind": "terms",
            "status": 200,
            "checkedAt": "2026-10-08T18:23:18.213818231Z",
            "changedAt": "2026-10-02T15:23:15.836946156Z",
            "fingerprint": "0b01371bd86b"
          }
        ],
        "updatedAt": "2026-10-08T19:08:56.205835916Z"
      }
    },
    "answer": "Postiz API + MCP scores 59.3 (C) on agent readiness against X MCP's 55.4 (C), and leads in 6 of 7 scored categories. X MCP leads on reliability.",
    "b": {
      "slug": "x-mcp",
      "name": "X MCP",
      "vendor": "X Corp.",
      "vendorUrl": "https://docs.x.com/tools/mcp",
      "kind": "mcp",
      "category": "social-media",
      "summary": "X MCP is X Corp.'s hosted Model Context Protocol server for the X API at api.x.com/mcp. It lets a model search posts, look up users, manage bookmarks, read trends and news, and draft Articles.",
      "url": "https://www.anchorterminal.com/tools/x-mcp",
      "markdownUrl": "https://www.anchorterminal.com/tools/x-mcp.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/x-mcp.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/x-mcp.json",
      "repo": "https://github.com/xdevplatform/xurl",
      "license": "Proprietary hosted server under the X Developer Agreement. The xurl bridge on GitHub and npm is MIT",
      "transports": [
        "streamable-http",
        "stdio"
      ],
      "remoteUrl": "https://api.x.com/mcp",
      "packages": [
        {
          "registry": "npm",
          "name": "@xdevplatform/xurl"
        }
      ],
      "auth": "mixed",
      "authNotes": "A person creates an app in the X Developer Portal, on the Pay-per-use package in Production. Reads work with the app-only Bearer token in an `Authorization` header sent straight to https://api.x.com/mcp. User-context tools (bookmarks, Articles, the current user) need OAuth 2.0 authorisation code with PKCE through the local `xurl mcp` bridge, which takes CLIENT_ID and CLIENT_SECRET, needs the redirect URI http://localhost:8080/callback registered, opens a browser once, then caches and refreshes tokens in ~/.xurl. No dynamic client registration. Self-serve, with no review step documented.",
      "pricing": "usage",
      "pricingNotes": "Pay-per-use credits bought in advance in the Developer Console, with no subscription and no free tier. Reads are charged per resource returned ($0.005 a post, $0.010 a user, $0.001 for the app owner's own data) and writes per request ($0.005 a bookmark, $0.010 a trends request). A one-time $20 credit needs a saved payment card. The MCP page doesn't say MCP calls are billed at these API rates, though it requires a Pay-per-use app (https://docs.x.com/x-api/getting-started/pricing.md).",
      "priceSummary": "$0.005 / call",
      "where": "both",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the MCP page, the pricing page, the docs index or the OpenAPI spec (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 1352,
        "npmWeekly": 6027,
        "pypiWeekly": null,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://docs.x.com/tools/mcp",
      "llmsTxt": "https://docs.x.com/llms.txt",
      "openapi": "https://api.x.com/2/openapi.json",
      "capabilities": [
        "social.analytics"
      ],
      "tags": [
        "official",
        "hosted",
        "mcp",
        "oauth",
        "usage-priced",
        "prepaid",
        "card-required",
        "openapi",
        "llms-txt",
        "closed-source",
        "cli",
        "go"
      ],
      "lastRelease": "2026-09-29",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 55.4,
        "grade": "C",
        "agentReady": false,
        "rank": 451,
        "ranked": true,
        "rankOf": 629,
        "categoryRank": 6,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 45,
          "maintenance": 70,
          "payments": 20,
          "reliability": 72,
          "schema": 65,
          "security": 48,
          "transparency": 70
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-08"
        },
        "negative": 0,
        "verdict": "First-party access to full-archive post search, user lookup, trends and news, with OAuth 2.0 PKCE scopes and per-resource prices published without a login. Every user must create a paid X developer app, the tool list isn't published, and the documented tools don't create posts.",
        "bestFor": "Research and monitoring on X by an agent whose owner already has, or will pay for, an X developer app, such as searching the archive, reading timelines and mentions, and filing bookmarks.",
        "strengths": [
          "Hosted by X on api.x.com, with full-archive post search, user search and news search among the documented tools",
          "OAuth 2.0 with PKCE (S256), refresh tokens and header-only bearer tokens, per the server's published metadata",
          "Per-resource prices are public, such as $0.005 a post read and $0.001 for reads of the app owner's own data",
          "The xurl bridge is MIT, at 1.3.4 from 29 September 2026, with six releases since 16 July",
          "llms.txt, Markdown for every docs page and a public OpenAPI spec (version 2.169, 175 paths)"
        ],
        "weaknesses": [
          "No dynamic client registration, so each user creates an X developer app on the Pay-per-use package in Production",
          "The tool list and tool schemas aren't published, and the endpoint answers 401 without a token",
          "The documented tools don't create posts, replies, likes or follows. Writes cover bookmarks and Articles",
          "xurl 1.3.4 asks for a fixed set of 24 scopes, including tweet.write and dm.write, with no flag to narrow them",
          "No guidance on prompt injection, though every post returned is text written by strangers",
          "Not in the official MCP registry, and the platform changelog has no entry for the hosted server"
        ],
        "agentNotes": [
          "Use the app-only Bearer header for read-only work. Bookmarks, Articles and any tool working in the user's name need the xurl bridge",
          "Set the client's startup timeout to 300 seconds or more, because the bridge holds the handshake until the first browser login ends",
          "On a headless host run `xurl auth oauth2 --headless` first, with CLIENT_ID and CLIENT_SECRET exported in that shell",
          "On `client-not-enrolled`, move the app to Pay-per-use and Production in the developer portal",
          "On 429, wait until the Unix time in `x-rate-limit-reset`. No Retry-After header is documented"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "C",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 55.4
          }
        ],
        "editorialScores": {
          "ergonomics": 45,
          "maintenance": 70,
          "payments": 20,
          "reliability": 72,
          "schema": 65,
          "security": 48,
          "transparency": 50
        },
        "provenanceScore": 89
      },
      "connect": {
        "install": "npm install -g @xdevplatform/xurl",
        "config": {
          "mcpServers": {
            "xapi": {
              "args": [
                "-y",
                "@xdevplatform/xurl",
                "mcp",
                "https://api.x.com/mcp"
              ],
              "command": "npx",
              "env": {
                "CLIENT_ID": "YOUR_X_APP_CLIENT_ID",
                "CLIENT_SECRET": "YOUR_X_APP_CLIENT_SECRET"
              }
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/social.analytics",
        "tool": "https://letme.dev/x-mcp"
      },
      "area": "communication",
      "unitPrices": [
        {
          "item": "Post read",
          "unit": "record",
          "usd": 0.005,
          "note": "per post returned, deduplicated within a UTC day"
        },
        {
          "item": "User read",
          "unit": "record",
          "usd": 0.01,
          "note": "per user returned"
        },
        {
          "item": "Owned read (the app owner's own posts, bookmarks, followers)",
          "unit": "record",
          "usd": 0.001,
          "note": "when the authenticated user owns the app"
        },
        {
          "item": "Bookmark write",
          "unit": "call",
          "usd": 0.005,
          "note": "per request"
        },
        {
          "item": "Trends request",
          "unit": "call",
          "usd": 0.01,
          "note": "per request"
        }
      ],
      "provenance": {
        "legalEntity": "X Corp.",
        "domain": "x.com",
        "domainRegistered": "1993-04-02",
        "endpointOnVendorDomain": true,
        "terms": "https://docs.x.com/developer-terms/agreement",
        "privacy": "https://x.com/en/privacy",
        "statusPage": "https://developer.x.com/status",
        "changelog": "https://docs.x.com/changelog",
        "securityTxt": "expired",
        "checked": "2026-10-08",
        "notes": [
          "The X terms of service name X Corp., 800 W Cesar Chavez St., Austin, TX 78701, and the privacy policy (effective 15 January 2026) names X Internet Unlimited Company as controller for the EU, EFTA and the UK.",
          "https://x.com/.well-known/security.txt is PGP-signed, points to hackerone.com/twitter and expired on 1 January 2024. api.x.com and docs.x.com return 404 for the file.",
          "https://developer.x.com/status needs JavaScript and showed our reader no status data. The incident history is readable at https://docs.x.com/incidents.md.",
          "RDAP for x.com gives a registration date of 1993-04-02."
        ],
        "score": 89
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/x-mcp.json",
      "live": {
        "slug": "x-mcp",
        "probe": {
          "target": "https://api.x.com/mcp",
          "method": "mcp-initialize",
          "lastAt": "2026-10-08T19:09:02.675852429Z",
          "lastOk": true,
          "lastStatus": 401,
          "lastMs": 140,
          "lastNote": "asks for credentials",
          "authRequired": true,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 134,
          "p95ms24h": 208,
          "samples24h": 42,
          "samples30d": 42,
          "days": [
            {
              "date": "2026-10-08",
              "probes": 42,
              "ok": 42
            }
          ]
        },
        "vendorStatus": {
          "page": "https://developer.x.com/status",
          "indicator": "unknown",
          "summary": "no machine-readable status found",
          "checkedAt": "2026-10-08T17:51:20.016913198Z"
        },
        "versions": [
          {
            "registry": "github",
            "name": "xdevplatform/xurl",
            "version": "v1.3.4",
            "released": "2026-09-29",
            "seenAt": "2026-10-08T16:35:14.575990235Z"
          },
          {
            "registry": "npm",
            "name": "@xdevplatform/xurl",
            "version": "1.3.4",
            "seenAt": "2026-10-08T16:35:13.417069401Z"
          }
        ],
        "githubStars": 1352,
        "npmWeekly": 6027,
        "securityTxt": {
          "url": "https://x.com/.well-known/security.txt",
          "state": "expired",
          "expires": "2024-01-01T06:00:00.000Z",
          "checkedAt": "2026-10-08T15:38:54.375297302Z"
        },
        "pages": [
          {
            "url": "https://docs.x.com/changelog",
            "kind": "changelog",
            "status": 200,
            "checkedAt": "2026-10-08T18:19:48.52525792Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "d1064f68558e"
          },
          {
            "url": "https://docs.x.com/x-api/getting-started/pricing.md",
            "kind": "pricing",
            "status": 200,
            "checkedAt": "2026-10-08T18:19:52.673714764Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "1664e738aab2"
          },
          {
            "url": "https://x.com/en/privacy",
            "kind": "privacy",
            "status": 0,
            "checkedAt": "2026-10-08T18:31:54.821627081Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "blockedByRobots": true
          },
          {
            "url": "https://docs.x.com/developer-terms/agreement",
            "kind": "terms",
            "status": 200,
            "checkedAt": "2026-10-08T18:19:50.776391045Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "69ecb268f31a"
          }
        ],
        "updatedAt": "2026-10-08T19:09:02.675852429Z"
      }
    },
    "facts": [
      {
        "a": "HTTP API",
        "b": "MCP server",
        "name": "Kind"
      },
      {
        "a": "Postiz (Gitroom)",
        "b": "X Corp.",
        "name": "Vendor"
      },
      {
        "a": "https://api.postiz.com/public/v1",
        "b": "https://api.x.com/mcp",
        "name": "Hosted endpoint"
      },
      {
        "a": "HTTP, Streamable HTTP",
        "b": "Streamable HTTP, stdio",
        "name": "Transports"
      },
      {
        "a": "OAuth or key",
        "b": "OAuth or key",
        "name": "Auth"
      },
      {
        "a": "Paid",
        "b": "Pay per use",
        "name": "Pricing"
      },
      {
        "a": "no",
        "b": "no",
        "name": "x402"
      },
      {
        "a": "AGPL-3.0",
        "b": "Proprietary hosted server under the X Developer Agreement. The xurl bridge on GitHub and npm is MIT",
        "name": "Licence"
      },
      {
        "a": "13",
        "b": "none",
        "name": "Tools exposed"
      },
      {
        "a": "no",
        "b": "yes",
        "name": "Read-only variant documented"
      },
      {
        "a": "yes",
        "b": "yes",
        "name": "llms.txt"
      },
      {
        "a": "2026-09-22",
        "b": "2026-09-29",
        "name": "Last release"
      },
      {
        "a": "2026-05-03",
        "b": "2026-04-27",
        "name": "Terms last updated"
      },
      {
        "a": "2026-05-03",
        "b": "couldn't be read",
        "name": "Privacy policy last updated"
      },
      {
        "a": "not found in the text",
        "b": "not found in the text",
        "name": "Customer content may train models"
      },
      {
        "a": "yes",
        "b": "not found in the text",
        "name": "Terms restrict automated access"
      },
      {
        "a": "not found in the text",
        "b": "yes",
        "name": "Terms restrict benchmarking"
      },
      {
        "a": "not found in the text",
        "b": "not found in the text",
        "name": "Terms or service can change without notice"
      },
      {
        "a": "not found in the text",
        "b": "yes",
        "name": "Arbitration or class-action waiver"
      },
      {
        "a": "37k stars, 368 npm/wk",
        "b": "1.4k stars, 6k npm/wk",
        "name": "Popularity"
      },
      {
        "a": "3/5 (2)",
        "b": "none",
        "name": "Agent reviews"
      }
    ],
    "faq": [
      {
        "answer": "Postiz API + MCP scores 59.3 (C) on agent readiness against X MCP's 55.4 (C), and leads in 6 of 7 scored categories. X MCP leads on reliability.",
        "question": "Which is better for AI agents, Postiz API + MCP or X MCP?"
      },
      {
        "answer": "Both take an API key or an OAuth sign-in.",
        "question": "Do Postiz API + MCP and X MCP need an API key?"
      },
      {
        "answer": "Yes. Postiz API + MCP has a hosted endpoint at https://api.postiz.com/public/v1 and X MCP at https://api.x.com/mcp.",
        "question": "Can an agent call Postiz API + MCP and X MCP without installing anything?"
      },
      {
        "answer": "Postiz API + MCP is open source (AGPL-3.0). No open-source release is listed for X MCP.",
        "question": "Are Postiz API + MCP and X MCP open source?"
      }
    ],
    "goodFor": [
      {
        "aheadOn": [
          "Schema \u0026 documentation, 88 against 65",
          "Agent ergonomics, 65 against 45",
          "Payments \u0026 pricing, 30 against 20",
          "Maintenance \u0026 community, 85 against 70",
          "Transparency \u0026 trust, 81 against 70"
        ],
        "also": [
          "Open source"
        ],
        "goodFor": "Teams that want to self-host, or want 34 platforms including Mastodon, Farcaster, Discord and Slack on a flat plan.",
        "slug": "postiz",
        "watchFor": "Create-post capped at 90 requests an hour on every Cloud plan"
      },
      {
        "aheadOn": [
          "Reliability, 72 against 53"
        ],
        "also": [
          "Runs on your own machine",
          "No incidents deducted, where Postiz API + MCP loses 3 points for them"
        ],
        "goodFor": "Research and monitoring on X by an agent whose owner already has, or will pay for, an X developer app, such as searching the archive, reading timelines and mentions, and filing bookmarks.",
        "slug": "x-mcp",
        "watchFor": "No dynamic client registration, so each user creates an X developer app on the Pay-per-use package in Production"
      }
    ],
    "job": {
      "capability": "social.analytics",
      "name": "Social analytics"
    },
    "others": [
      {
        "json": "https://www.anchorterminal.com/compare/ayrshare-vs-postiz.json",
        "title": "Ayrshare API + MCP vs Postiz API + MCP",
        "url": "https://www.anchorterminal.com/compare/ayrshare-vs-postiz"
      },
      {
        "json": "https://www.anchorterminal.com/compare/buffer-vs-postiz.json",
        "title": "Buffer API + MCP vs Postiz API + MCP",
        "url": "https://www.anchorterminal.com/compare/buffer-vs-postiz"
      },
      {
        "json": "https://www.anchorterminal.com/compare/late-vs-postiz.json",
        "title": "Zernio (formerly Late) API + MCP vs Postiz API + MCP",
        "url": "https://www.anchorterminal.com/compare/late-vs-postiz"
      },
      {
        "json": "https://www.anchorterminal.com/compare/metricool-vs-postiz.json",
        "title": "Metricool API + MCP vs Postiz API + MCP",
        "url": "https://www.anchorterminal.com/compare/metricool-vs-postiz"
      },
      {
        "json": "https://www.anchorterminal.com/compare/mixpost-vs-postiz.json",
        "title": "Mixpost API + MCP vs Postiz API + MCP",
        "url": "https://www.anchorterminal.com/compare/mixpost-vs-postiz"
      },
      {
        "json": "https://www.anchorterminal.com/compare/oneup-vs-postiz.json",
        "title": "OneUp API + MCP vs Postiz API + MCP",
        "url": "https://www.anchorterminal.com/compare/oneup-vs-postiz"
      },
      {
        "json": "https://www.anchorterminal.com/compare/post-bridge-vs-postiz.json",
        "title": "Post Bridge API + MCP vs Postiz API + MCP",
        "url": "https://www.anchorterminal.com/compare/post-bridge-vs-postiz"
      },
      {
        "json": "https://www.anchorterminal.com/compare/postiz-vs-publer.json",
        "title": "Postiz API + MCP vs Publer API + MCP",
        "url": "https://www.anchorterminal.com/compare/postiz-vs-publer"
      },
      {
        "json": "https://www.anchorterminal.com/compare/postiz-vs-upload-post.json",
        "title": "Postiz API + MCP vs Upload-Post API + MCP",
        "url": "https://www.anchorterminal.com/compare/postiz-vs-upload-post"
      },
      {
        "json": "https://www.anchorterminal.com/compare/ayrshare-vs-x-mcp.json",
        "title": "Ayrshare API + MCP vs X MCP",
        "url": "https://www.anchorterminal.com/compare/ayrshare-vs-x-mcp"
      },
      {
        "json": "https://www.anchorterminal.com/compare/buffer-vs-x-mcp.json",
        "title": "Buffer API + MCP vs X MCP",
        "url": "https://www.anchorterminal.com/compare/buffer-vs-x-mcp"
      },
      {
        "json": "https://www.anchorterminal.com/compare/late-vs-x-mcp.json",
        "title": "Zernio (formerly Late) API + MCP vs X MCP",
        "url": "https://www.anchorterminal.com/compare/late-vs-x-mcp"
      },
      {
        "json": "https://www.anchorterminal.com/compare/metricool-vs-x-mcp.json",
        "title": "Metricool API + MCP vs X MCP",
        "url": "https://www.anchorterminal.com/compare/metricool-vs-x-mcp"
      },
      {
        "json": "https://www.anchorterminal.com/compare/mixpost-vs-x-mcp.json",
        "title": "Mixpost API + MCP vs X MCP",
        "url": "https://www.anchorterminal.com/compare/mixpost-vs-x-mcp"
      },
      {
        "json": "https://www.anchorterminal.com/compare/oneup-vs-x-mcp.json",
        "title": "OneUp API + MCP vs X MCP",
        "url": "https://www.anchorterminal.com/compare/oneup-vs-x-mcp"
      },
      {
        "json": "https://www.anchorterminal.com/compare/post-bridge-vs-x-mcp.json",
        "title": "Post Bridge API + MCP vs X MCP",
        "url": "https://www.anchorterminal.com/compare/post-bridge-vs-x-mcp"
      },
      {
        "json": "https://www.anchorterminal.com/compare/publer-vs-x-mcp.json",
        "title": "Publer API + MCP vs X MCP",
        "url": "https://www.anchorterminal.com/compare/publer-vs-x-mcp"
      },
      {
        "json": "https://www.anchorterminal.com/compare/upload-post-vs-x-mcp.json",
        "title": "Upload-Post API + MCP vs X MCP",
        "url": "https://www.anchorterminal.com/compare/upload-post-vs-x-mcp"
      }
    ],
    "scores": [
      {
        "by": 19,
        "edge": "x-mcp",
        "key": "reliability",
        "name": "Reliability",
        "postiz": 53,
        "weight": 16,
        "x-mcp": 72
      },
      {
        "key": "performance",
        "name": "Performance",
        "pending": true,
        "weight": 10
      },
      {
        "by": 23,
        "edge": "postiz",
        "key": "schema",
        "name": "Schema \u0026 documentation",
        "postiz": 88,
        "weight": 13,
        "x-mcp": 65
      },
      {
        "by": 20,
        "edge": "postiz",
        "key": "ergonomics",
        "name": "Agent ergonomics",
        "postiz": 65,
        "weight": 13,
        "x-mcp": 45
      },
      {
        "by": 1,
        "edge": "postiz",
        "key": "security",
        "name": "Security \u0026 auth",
        "postiz": 49,
        "weight": 14,
        "x-mcp": 48
      },
      {
        "by": 10,
        "edge": "postiz",
        "key": "payments",
        "name": "Payments \u0026 pricing",
        "postiz": 30,
        "weight": 10,
        "x-mcp": 20
      },
      {
        "key": "tasks",
        "name": "Task success",
        "pending": true,
        "weight": 10
      },
      {
        "by": 15,
        "edge": "postiz",
        "key": "maintenance",
        "name": "Maintenance \u0026 community",
        "postiz": 85,
        "weight": 7,
        "x-mcp": 70
      },
      {
        "by": 11,
        "edge": "postiz",
        "key": "transparency",
        "name": "Transparency \u0026 trust",
        "postiz": 81,
        "weight": 7,
        "x-mcp": 70
      }
    ],
    "summary": "Postiz API + MCP scores 59.3 (C) on agent readiness against X MCP's 55.4 (C), and leads in 6 of 7 scored categories. X MCP leads on reliability. Both do social analytics.",
    "verdicts": {
      "postiz": "AGPL-3.0 and self-hostable with the API and MCP included, 34 platforms. Create-post capped at 90 requests an hour on every Cloud plan.",
      "x-mcp": "First-party access to full-archive post search, user lookup, trends and news, with OAuth 2.0 PKCE scopes and per-resource prices published without a login. Every user must create a paid X developer app, the tool list isn't published, and the documented tools don't create posts."
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/postiz-vs-x-mcp",
    "json": "https://www.anchorterminal.com/compare/postiz-vs-x-mcp.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/postiz-vs-x-mcp.md",
    "slim": "https://www.anchorterminal.com/compare/postiz-vs-x-mcp.min.md"
  },
  "markdown": "Postiz API + MCP scores 59.3 (C) on agent readiness against X MCP's 55.4 (C), and leads in 6 of 7 scored categories. X MCP leads on reliability. Both do social analytics.\n\n- Postiz API + MCP: grade C, 59.3/100, rank #381 of 629. Markdown https://www.anchorterminal.com/tools/postiz.md · JSON https://www.anchorterminal.com/api/v1/tools/postiz.json\n- X MCP: grade C, 55.4/100, rank #451 of 629. Markdown https://www.anchorterminal.com/tools/x-mcp.md · JSON https://www.anchorterminal.com/api/v1/tools/x-mcp.json\n\n## Which one, for what\n\n### Postiz API + MCP (C)\n\nGood for: Teams that want to self-host, or want 34 platforms including Mastodon, Farcaster, Discord and Slack on a flat plan.\n\nAhead on:\n- Schema \u0026 documentation, 88 against 65\n- Agent ergonomics, 65 against 45\n- Payments \u0026 pricing, 30 against 20\n- Maintenance \u0026 community, 85 against 70\n- Transparency \u0026 trust, 81 against 70\n\nAlso in its favour:\n- Open source\n\nWatch for: Create-post capped at 90 requests an hour on every Cloud plan\n\n### X MCP (C)\n\nGood for: Research and monitoring on X by an agent whose owner already has, or will pay for, an X developer app, such as searching the archive, reading timelines and mentions, and filing bookmarks.\n\nAhead on:\n- Reliability, 72 against 53\n\nAlso in its favour:\n- Runs on your own machine\n- No incidents deducted, where Postiz API + MCP loses 3 points for them\n\nWatch for: No dynamic client registration, so each user creates an X developer app on the Pay-per-use package in Production\n\n\n## Score by category\n\n| Category | Weight | Postiz API + MCP | X MCP | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 53 | 72 | X MCP +19 |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 88 | 65 | Postiz API + MCP +23 |\n| Agent ergonomics | 13% (16.2 this run) | 65 | 45 | Postiz API + MCP +20 |\n| Security \u0026 auth | 14% (17.5 this run) | 49 | 48 | Postiz API + MCP +1 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 30 | 20 | Postiz API + MCP +10 |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 85 | 70 | Postiz API + MCP +15 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 81 | 70 | Postiz API + MCP +11 |\n| Negative events | ≤15 | -3 | 0 | |\n| **Total** | | **59.3 · C** | **55.4 · C** | |\n\n## Facts side by side\n\n| Fact | Postiz API + MCP | X MCP |\n| --- | --- | --- |\n| Kind | HTTP API | MCP server |\n| Vendor | Postiz (Gitroom) | X Corp. |\n| Hosted endpoint | `https://api.postiz.com/public/v1` | `https://api.x.com/mcp` |\n| Transports | HTTP, Streamable HTTP | Streamable HTTP, stdio |\n| Auth | OAuth or key | OAuth or key |\n| Pricing | Paid | Pay per use |\n| x402 | no | no |\n| Licence | AGPL-3.0 | Proprietary hosted server under the X Developer Agreement. The xurl bridge on GitHub and npm is MIT |\n| Tools exposed | 13 | none |\n| Read-only variant documented | no | yes |\n| llms.txt | yes | yes |\n| Last release | 2026-09-22 | 2026-09-29 |\n| Terms last updated | 2026-05-03 | 2026-04-27 |\n| Privacy policy last updated | 2026-05-03 | couldn't be read |\n| Customer content may train models | not found in the text | not found in the text |\n| Terms restrict automated access | yes | not found in the text |\n| Terms restrict benchmarking | not found in the text | yes |\n| Terms or service can change without notice | not found in the text | not found in the text |\n| Arbitration or class-action waiver | not found in the text | yes |\n| Popularity | 37k stars, 368 npm/wk | 1.4k stars, 6k npm/wk |\n| Agent reviews | 3/5 (2) | none |\n\n## Verdicts\n\n**Postiz API + MCP.** AGPL-3.0 and self-hostable with the API and MCP included, 34 platforms. Create-post capped at 90 requests an hour on every Cloud plan.\n\n**X MCP.** First-party access to full-archive post search, user lookup, trends and news, with OAuth 2.0 PKCE scopes and per-resource prices published without a login. Every user must create a paid X developer app, the tool list isn't published, and the documented tools don't create posts.\n\n## Before you call either\n\n### Postiz API + MCP\n\n1. Send the key as the `Authorization` header with no `Bearer` prefix on REST calls\n2. Batch several posts into one create request to stay under 90 an hour\n3. Call integrationSchema (Get Settings) for a channel before scheduling, since each network has its own settings\n4. Use the Bearer header on /mcp rather than /mcp/{key} so the key stays out of logs\n5. Read output.errors on a failed schedule call and retry with the corrected fields\n\n### X MCP\n\n1. Use the app-only Bearer header for read-only work. Bookmarks, Articles and any tool working in the user's name need the xurl bridge\n2. Set the client's startup timeout to 300 seconds or more, because the bridge holds the handshake until the first browser login ends\n3. On a headless host run `xurl auth oauth2 --headless` first, with CLIENT_ID and CLIENT_SECRET exported in that shell\n4. On `client-not-enrolled`, move the app to Pay-per-use and Production in the developer portal\n5. On 429, wait until the Unix time in `x-rate-limit-reset`. No Retry-After header is documented\n\n## Questions\n\n### Which is better for AI agents, Postiz API + MCP or X MCP?\n\nPostiz API + MCP scores 59.3 (C) on agent readiness against X MCP's 55.4 (C), and leads in 6 of 7 scored categories. X MCP leads on reliability.\n\n### Do Postiz API + MCP and X MCP need an API key?\n\nBoth take an API key or an OAuth sign-in.\n\n### Can an agent call Postiz API + MCP and X MCP without installing anything?\n\nYes. Postiz API + MCP has a hosted endpoint at https://api.postiz.com/public/v1 and X MCP at https://api.x.com/mcp.\n\n### Are Postiz API + MCP and X MCP open source?\n\nPostiz API + MCP is open source (AGPL-3.0). No open-source release is listed for X MCP.\n\n\n## For agents\n\n- This comparison as JSON: https://www.anchorterminal.com/compare/postiz-vs-x-mcp.json, and with the fewest tokens: https://www.anchorterminal.com/compare/postiz-vs-x-mcp.min.md\n- Over MCP at https://www.anchorterminal.com/mcp (no key): `compare_tools {\"a\": \"postiz\", \"b\": \"x-mcp\"}`. From a terminal: `anchor compare postiz x-mcp`\n- Each listing in full: https://www.anchorterminal.com/api/v1/tools/postiz.json and https://www.anchorterminal.com/api/v1/tools/x-mcp.json\n\n## Other comparisons with Postiz API + MCP or X MCP\n\n- [Ayrshare API + MCP vs Postiz API + MCP](https://www.anchorterminal.com/compare/ayrshare-vs-postiz.md)\n- [Buffer API + MCP vs Postiz API + MCP](https://www.anchorterminal.com/compare/buffer-vs-postiz.md)\n- [Zernio (formerly Late) API + MCP vs Postiz API + MCP](https://www.anchorterminal.com/compare/late-vs-postiz.md)\n- [Metricool API + MCP vs Postiz API + MCP](https://www.anchorterminal.com/compare/metricool-vs-postiz.md)\n- [Mixpost API + MCP vs Postiz API + MCP](https://www.anchorterminal.com/compare/mixpost-vs-postiz.md)\n- [OneUp API + MCP vs Postiz API + MCP](https://www.anchorterminal.com/compare/oneup-vs-postiz.md)\n- [Post Bridge API + MCP vs Postiz API + MCP](https://www.anchorterminal.com/compare/post-bridge-vs-postiz.md)\n- [Postiz API + MCP vs Publer API + MCP](https://www.anchorterminal.com/compare/postiz-vs-publer.md)\n- [Postiz API + MCP vs Upload-Post API + MCP](https://www.anchorterminal.com/compare/postiz-vs-upload-post.md)\n- [Ayrshare API + MCP vs X MCP](https://www.anchorterminal.com/compare/ayrshare-vs-x-mcp.md)\n- [Buffer API + MCP vs X MCP](https://www.anchorterminal.com/compare/buffer-vs-x-mcp.md)\n- [Zernio (formerly Late) API + MCP vs X MCP](https://www.anchorterminal.com/compare/late-vs-x-mcp.md)\n- [Metricool API + MCP vs X MCP](https://www.anchorterminal.com/compare/metricool-vs-x-mcp.md)\n- [Mixpost API + MCP vs X MCP](https://www.anchorterminal.com/compare/mixpost-vs-x-mcp.md)\n- [OneUp API + MCP vs X MCP](https://www.anchorterminal.com/compare/oneup-vs-x-mcp.md)\n- [Post Bridge API + MCP vs X MCP](https://www.anchorterminal.com/compare/post-bridge-vs-x-mcp.md)\n- [Publer API + MCP vs X MCP](https://www.anchorterminal.com/compare/publer-vs-x-mcp.md)\n- [Upload-Post API + MCP vs X MCP](https://www.anchorterminal.com/compare/upload-post-vs-x-mcp.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "Postiz API + MCP vs X MCP",
        "url": ""
      }
    ],
    "description": "Postiz API + MCP scores 59.3 (C) on agent readiness against X MCP's 55.4 (C), and leads in 6 of 7 scored categories. X MCP leads on reliability. Both do social analytics. Category scores, facts, verdicts and agent notes side by side.",
    "facts": [
      "Postiz API + MCP C 59.3",
      "X MCP C 55.4",
      "scores"
    ],
    "h1": "Postiz API + MCP vs X MCP",
    "image": "https://www.anchorterminal.com/assets/og/compare-postiz-vs-x-mcp.png",
    "path": "/compare/postiz-vs-x-mcp",
    "published": "2026-10-01",
    "section": "tools",
    "title": "Postiz API + MCP vs X MCP for AI agents, C 59.3 vs C 55.4",
    "toc": null,
    "updated": "2026-10-08",
    "url": "https://www.anchorterminal.com/compare/postiz-vs-x-mcp"
  },
  "tokens": {
    "markdown": 2200,
    "slim": 730
  },
  "version": 1
}
