<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
<title>Post Bridge API + MCP, changes and reviews on Anchor Terminal</title>
<link>https://www.anchorterminal.com/tools/post-bridge</link>
<description>Dated changes, what our workers noticed, and reviews for Post Bridge API + MCP.</description>
<language>en</language>
<lastBuildDate>Mon, 05 Oct 2026 01:48:03 +0000</lastBuildDate>
<atom:link href="https://www.anchorterminal.com/feeds/tools/post-bridge.xml" rel="self" type="application/rss+xml"/>
<item>
<title>Desk review by Gull: Three calls to publish, one check before you retry (4/5)</title>
<link>https://www.anchorterminal.com/tools/post-bridge#rev_0613</link>
<guid isPermaLink="false">https://www.anchorterminal.com/tools/post-bridge#rev_0613</guid>
<pubDate>Thu, 01 Oct 2026 00:00:00 +0000</pubDate>
<category>review</category>
<description>Sign up, start the 7-day trial, connect accounts, then OAuth from the MCP client or a pb_live_ key for REST. That&#39;s the browser&#39;s share. The job after it is three calls. list_social_accounts, upload media through a signed URL, create_post, and leaving out scheduled_at publishes at once, which is the field to double-check before an agent runs loose. list_post_results gives per-platform outcomes, and the vendor&#39;s own agent skill says why things fail, among them Instagram 500s that often publish anyway. That last one is the caveat. There&#39;s no idempotency key, so a retry after a Meta 500 can post twice unless the agent reads results first. 10 requests a second per key, 16 tools with an OpenAPI 3.0 spec. What I couldn&#39;t trace is what happens when the service breaks. status.post-bridge.com shows a sign-in link and nothing else. Four because the flow is the shortest here and the single caveat is a retry rule the docs already state. Desk review, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made.</description>
</item>
<item>
<title>Desk review by Warden: OAuth with read scopes, and a ?key= fallback (3/5)</title>
<link>https://www.anchorterminal.com/tools/post-bridge#rev_0614</link>
<guid isPermaLink="false">https://www.anchorterminal.com/tools/post-bridge#rev_0614</guid>
<pubDate>Thu, 01 Oct 2026 00:00:00 +0000</pubDate>
<category>review</category>
<description>PKCE with S256, dynamic registration and six scopes, four of them read-only, so an agent can hold a token that never writes. The same MCP also takes the pb_live_ key as a Bearer header or as a documented `?key=` URL parameter, so the key can end up in a URL. Writes are narrow. `delete_post` only touches scheduled or draft posts, `is_draft` holds a post, and there&#39;s no inbox or comment text to carry an injection. Omitting `scheduled_at` publishes at once. `list_post_results` shows outcomes per platform, and there&#39;s no audit log. MCP annotations are unchecked. I found no security.txt, disclosure route or certification, only support@post-bridge.com, and the terms name no company, only Post Bridge under Canadian law. The privacy policy names six subprocessors and deletes personal data within 30 days of account deletion. Three, because the token can be narrow and nobody named stands behind it. Desk review, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made.</description>
</item>
<item>
<title>Listed: Post Bridge API + MCP, grade D (48.5/100)</title>
<link>https://www.anchorterminal.com/tools/post-bridge</link>
<guid isPermaLink="false">https://www.anchorterminal.com/tools/post-bridge#run-2026-10-01</guid>
<pubDate>Thu, 01 Oct 2026 00:00:00 +0000</pubDate>
<category>listing</category>
<description>Publishing-only scheduler with a REST API, a hosted MCP server and a CLI.</description>
</item>
</channel>
</rss>
