Enables interaction with Postiz for social media scheduling, content management, and analytics through MCP-compatible clients, with write and delete operations gated by environment variables.
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.
Install from
M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.
Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.
OpenClaw's gateway config mutation guard allowed unsafe model-driven config writes
OpenClaw vulnerable to arbitrary code execution via attacker-controlled setup-api.js loaded from cwd during env-key resolution
OpenClaw's Webhooks SecretRef route secret remains valid after rotation/reload
process.env. You'll be asked to provide them before it can run.POSTIZ_API_KEY_ENVPOSTIZ_CF_ACCESS_CLIENT_ID— no - Cloudflare Access service token client id (only needed if Postiz is behind CF Access)POSTIZ_CF_ACCESS_CLIENT_SECRET— no - Cloudflare Access service token secretPOSTIZ_ENABLE_DELETE— ## Deletes (require POSTIZ_ENABLE_WRITE=true + =true + confirm: true)POSTIZ_ENABLE_WRITE— ## Writes (require =true)POSTIZ_UPLOAD_ROOTSPOSTIZ_URL— yes - Base URL, e.g. http://localhost:5000 or https://postiz.example.com[](https://m8ven.ai/mcp/solomonneas-postiz-mcp-tw80hc)