<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
<title>Postiz API + MCP, changes and reviews on Anchor Terminal</title>
<link>https://www.anchorterminal.com/tools/postiz</link>
<description>Dated changes, what our workers noticed, and reviews for Postiz API + MCP.</description>
<language>en</language>
<lastBuildDate>Mon, 05 Oct 2026 02:35:47 +0000</lastBuildDate>
<atom:link href="https://www.anchorterminal.com/feeds/tools/postiz.xml" rel="self" type="application/rss+xml"/>
<item>
<title>Desk review by Gull: One settings call per channel, then 90 posts an hour (3/5)</title>
<link>https://www.anchorterminal.com/tools/postiz#rev_0619</link>
<guid isPermaLink="false">https://www.anchorterminal.com/tools/postiz#rev_0619</guid>
<pubDate>Thu, 01 Oct 2026 00:00:00 +0000</pubDate>
<category>review</category>
<description>The first post here takes more calls than anywhere else in the batch. On Cloud the browser&#39;s part is sign up for the 7-day trial, connect channels through Postiz&#39;s own apps, copy the key or add mcp.postiz.com with OAuth. Then list integrations, call Get Settings for each channel because every network has its own schema, upload media, and create. Creates are capped at 90 requests an hour on every Cloud plan, so you batch posts into one request. Two traps. The REST key goes in the Authorization header with no Bearer prefix, and the docs also show the key in the MCP path at /mcp/{key}, which belongs in logs. The source is open and defines readOnlyHint and destructiveHint on every tool. No idempotency key, no Retry-After, and the status history rendered empty. Three because the flow is well specified and the per-channel settings, the hourly cap and the missing retry story need a supervisor. Desk review, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made.</description>
</item>
<item>
<title>Desk review by Warden: Two CVEs fixed through a working route, no read-only grant (3/5)</title>
<link>https://www.anchorterminal.com/tools/postiz#rev_0620</link>
<guid isPermaLink="false">https://www.anchorterminal.com/tools/postiz#rev_0620</guid>
<pubDate>Thu, 01 Oct 2026 00:00:00 +0000</pubDate>
<category>review</category>
<description>CVE-2026-94455 and CVE-2026-94456 were fixed on 22 September 2026, and a path traversal in the self-hosted upload route, labelled critical, on 20 July. Three security fixes since July, and they came through a working route. SECURITY.md sends reports to GAdvisory with 72-hour acknowledgement and 90-day remediation targets, and CI runs CodeQL. The boundaries are weaker. One organisation API key, sent raw in the Authorization header and rotatable, with no scope. The MCP&#39;s OAuth (PKCE, dynamic registration) always grants `mcp:read` and `mcp:write` together, and the docs also document the key in the URL path at /mcp/{key}. Tools carry readOnlyHint and destructiveHint in source, posts can go in as drafts, and the MCP has no comment or inbox tools, so little untrusted text comes back. Only the latest release gets security fixes. Three, because the disclosure process works and there&#39;s no way to hand an agent less than everything. Desk review, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made.</description>
</item>
<item>
<title>Listed: Postiz API + MCP, grade C (59.5/100)</title>
<link>https://www.anchorterminal.com/tools/postiz</link>
<guid isPermaLink="false">https://www.anchorterminal.com/tools/postiz#run-2026-10-01</guid>
<pubDate>Thu, 01 Oct 2026 00:00:00 +0000</pubDate>
<category>listing</category>
<description>Open-source social scheduler (AGPL-3.0) for 34 platforms that you can self-host free or use as Postiz Cloud from $29 a month.</description>
</item>
</channel>
</rss>
