Model Context Protocol server for Postiz social media scheduling API
This is a solid community server with good naming conventions, comprehensive parameter schemas, and detailed descriptions. All 6 tools follow verb_noun naming patterns (postiz-get-channels, postiz-create-post, etc.). Schemas are well-structured with Zod validation. However, there are notable gaps: no output schemas documented, error handling guidance is minimal, and security considerations around file uploads and API key management could be strengthened. The descriptions are generally good (100-300+ chars) but lack explicit dependency hints and recovery guidance for failure cases. The server demonstrates above-average quality for its domain but falls short of production-grade excellence.
Create a new post in Postiz (draft, scheduled, or immediate)
Delete a post from Postiz
Get list of available social media channels/integrations in Postiz
List posts from Postiz with date range filtering. Date-only inputs are expanded to the full day.
Update an existing post in Postiz. IMPORTANT: updates are not partial; include the full content again or it will be cleared.
Upload a file to Postiz for use in posts (images, videos, etc.)
No documented output schemas for any tool. LLMs cannot infer what fields to expect from responses, hindering downstream tool composition and forcing agents to guess data structure.
postiz-upload-file lacks guidance on handling upload failures and does not document maximum file size, supported formats, or timeout behavior. Error responses appear unstructured.
postiz-delete-post (destructive operation) has no confirmation pattern or dry-run capability. A tool that permanently deletes should offer a confirm_before_execute or preview step to prevent accidental data loss.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | B | 71 | 2026-07-28+ | v2 |
| 2026-03-09 | D | 57 | - | v1 |
Error handling is not documented at the tool level. No actionable recovery guidance provided (e.g., 'If scheduling fails due to timezone, verify the format is ISO 8601 with offset'). Error classifications (retryable vs fatal) are absent.
postiz-create-post and postiz-update-post accept 'images' as array of strings but the description says 'PUBLIC URLs', however, the parameter description also mentions 'file IDs' in postiz-update-post, creating ambiguity about what format is actually accepted.
postiz-list-posts date filtering behavior is documented in prose ('expanded to full day') but lacks formal constraints (regex, format declaration). LLMs may pass malformed dates.
No pagination guidance for postiz-list-posts. If many posts exist within a date range, the response could be massive and blow the context window. No limit, offset, or cursor documented.
POSTIZ_API_KEY is injected via environment variable (good security practice), but no explicit documentation in tool descriptions about permission scopes (e.g., 'requires write:posts scope'). Agents cannot reason about least-privilege.