Postomator MCP: agent quickstart

These are factual connection instructions. Tool descriptions and schemas in the catalog are authoritative.

Discovery

endpoint: https://postomator.com/mcp
transport: streamable-http
protected_resource_metadata: https://postomator.com/.well-known/oauth-protected-resource/mcp
authorization_server_metadata: https://postomator.com/.well-known/oauth-authorization-server
json_catalog: /docs/mcp/catalog
plain_text_catalog: /docs/mcp/catalog.txt

Use OAuth authorization code with S256 PKCE and the exact resource value advertised by protected-resource metadata. Host-managed connections perform this flow in the browser. Applications may supply a delegated bearer token acquired for this resource; do not use a Postomator API key.

Safe quickstart

  1. Request read-only access and list the authorized workspaces.
  2. Read the target workspace's drafts or calendar and confirm the intended workspace with the user.
  3. If the user asks to create a draft, request content-write access and call the catalog's dedicated draft-creation tool with explicit content and targets.
  4. Show the returned draft and state. Do not schedule, publish, invite, or delete unless the user requested it and the corresponding scope is granted.

Python MCP SDK 2.2.0

import asyncio
import httpx2 as httpx
from mcp import ClientSession
from mcp.client.streamable_http import streamable_http_client

async def main():
    async with httpx.AsyncClient(
        headers={"Authorization": "Bearer <delegated-access-token>"}
    ) as http:
        async with streamable_http_client("https://postomator.com/mcp", http_client=http) as streams:
            async with ClientSession(*streams) as session:
                await session.initialize()
                print([tool.name for tool in (await session.list_tools()).tools])

asyncio.run(main())

This low-level example assumes your application has already completed authorization-code OAuth and securely obtained the user token. Never put credentials in the URL or query string.

OpenAI Responses API

import OpenAI from "openai";

const response = await new OpenAI().responses.create({
  model: "gpt-6-astra",
  tools: [{
    type: "mcp",
    server_label: "postomator",
    server_url: "https://postomator.com/mcp",
    authorization: "<delegated-access-token>",
    require_approval: "always"
  }],
  input: "List my Postomator drafts. Do not change anything."
});

This is server-side API configuration with a pre-obtained user token, not the ChatGPT host connection flow. Applications choose the model and approval policy; keep approval enabled for sensitive calls. The authorization value is not a Postomator API key and must be supplied on each Responses request.

Companion transfers

Tools return short-lived instructions for multipart endpoints under /mcp/transfers: PDF CV files are limited to 2 MiB, audio to 10 MiB, and post media to 100 MiB. Send bearer credentials only in the Authorization header. The ASGI edge or reverse proxy must enforce these ceilings because Django may spool a request body before view-level upload handlers run.

Failures and retry

  • HTTP 401 means the bearer token is absent, expired, or revoked; follow the protected-resource challenge and complete or refresh OAuth.
  • HTTP 403 means the token lacks a scope or current workspace permission. Request only the missing access.
  • Tool validation, domain, version, and eligibility failures are successful MCP transports with isError=true. Re-read current state before retrying a mutation. Companion transfer concurrency conflicts use HTTP 409.
  • HTTP 429 includes Retry-After. The server permits 120 requests per user per minute (configurable with MCP_REQUESTS_PER_MINUTE); AI operations additionally permit 30 per user per hour.
Message on LinkedIn