API

The Reblog API

How the Reblog API works end to end: the two programmable surfaces, the two ways to authenticate, and the complete list of what a connection can do to a project.


Reblog exposes its content and its editorial machinery through two surfaces that share one authentication story. Which one you want depends on who is calling: your website, or an AI agent.

Content APIMCP server
EndpointGET /api/external/articlesPOST /api/mcp
ProtocolREST, JSONJSON-RPC 2.0 (Model Context Protocol)
CallerYour site, your build step, your CDNClaude, Claude Code, Cursor, your own agent
Can readPublished articles onlyDrafts, ideas, assets, jobs, agents, history
Can writeNothingEverything the granted permissions allow
AuthProject API keyOAuth 2.1 token, or project API key
ReferenceContent APIMCP overview

One base URL

Everything lives at https://reblog.so. The API routes and the OAuth discovery documents sit at the domain root, never under /app -- that prefix is the dashboard UI and it redirects, which breaks integrations that do not follow redirects.

The Content API#

A single read endpoint, built for the one job a blog front end has: turn a URL into an article. It is deliberately small. It answers in four modes, selected by the query parameters you send.

  • One article -- ?handle=guides/getting-started or ?article_id=<id>. Returns the full document: markdown body, cover, SEO fields, language mirrors, recommendations and structured metadata.
  • A category feed -- ?category=guides&lang=EN&page=0&limit=10. Paginated, newest first, with a has_more flag.
  • The sitemap -- ?sitemap=true. Every published handle with its dates, for generating sitemap.xml.
  • Scheduled posts stay hidden -- every mode filters on status: published AND a publication date that has already passed, so a future-dated article never leaks.
Fetch one article
curl -H "Authorization: Bearer $REBLOG_API_KEY" \
  "https://reblog.so/api/external/articles?handle=guides/getting-started"

Full parameter tables, response shapes and framework examples: Content API reference and the article object.

The MCP server#

MCP (Model Context Protocol) is the open standard that lets an AI client call your tools. Reblog ships an MCP server, so instead of writing glue code you point Claude, Claude Code, Cursor or your own agent at one URL and it can operate the blog directly: research a topic, write the draft, illustrate it, translate it into every language the project runs, and schedule it.

EndpointPOST https://reblog.so/api/mcp
TransportStreamable HTTP, stateless JSON-RPC over POST
Protocol version2025-06-18
Serverreblog-mcp 1.0.0
Tools54, across 11 permission groups
Discovery/.well-known/oauth-protected-resource

Nothing to register by hand

Sign-in uses OAuth 2.1 with dynamic client registration and PKCE. A client discovers the endpoints, registers itself, and opens a Reblog consent screen in your browser. You pick the access level. See Connect a client.

What a connection can do#

Everything below is reachable through the MCP server. Each row names the permission that unlocks it -- that is the same string the consent screen shows you, and the same one a tool declares in code.

CapabilityPermissionWhat it covers
Discoveryaccount.projects.readList the projects and workspaces a connection can reach, and ask which of them is overdue for an article.
Read contentarticles.readArticles with their markdown, categories, revision history, the images inside a post, the publishing calendar, content gaps, and which articles have gone stale.
Create contentarticles.createWrite a finished article yourself, or file a topic in the ideas backlog.
Edit and publisharticles.editUpdate fields, apply targeted find-and-replace edits, roll back to an earlier revision, add or swap the pictures in a post, set the cover, publish now, schedule for a date, unpublish, approve from the review queue.
Deletearticles.deleteDelete an article for good.
Run AI agentsagents.runGenerate an article from a topic, translate one article or every missing language, generate images, rebuild internal recommendations, cancel a running job, and configure the project agents that decide how all of that sounds. Spends AI credits.
See AI agentsagents.readInspect the configured agents, the idea backlog, the job queue, and the image models the account can reach.
Assetsassets.read / assets.create / assets.deleteBrowse the project media library, upload a file into the project CDN, and delete one (refused while published articles still point at it, unless forced).
Automation routinesautomation.manageList, run and pause the scheduled autopilot pipelines. Sensitive: a routine publishes on its own and spends credits on a schedule.

The complete catalogue, tool by tool with every argument, is on the tool reference page.

Authentication in one paragraph#

A project API key is a long-lived secret bound to exactly one project, created in the dashboard, and sent as Authorization: Bearer <key>. It works on both surfaces and carries one of two levels: read-only, or read and write. An OAuth 2.1 token is what an MCP client obtains for you when you approve its consent screen; it can cover several projects, it expires and refreshes, and you can revoke it at any time from the connected-apps page. Details, including the deprecated query-parameter form: Authentication.

The permission model#

This is the part worth reading before you build anything on top. Reblog checks two independent things on every MCP call, and a call needs both to pass.

  1. 1

    What the app was allowed to ask for

    The grant's scopes. A connection approved as read-only is never offered a tool that writes -- those tools do not appear in its catalogue at all.

  2. 2

    What you are allowed to do

    Your own role on the target project, re-read live on every call. A connection can never do more than the person behind it: an app you granted full access still cannot delete an article in a project where you are only a contributor.

Demotion takes effect immediately

Because the role is resolved per call, removing someone from a project shrinks every connection they authorized, with no token to revoke and no cache to wait out.

Every scope, every consent preset, and the exact tool-to-role matrix: Permissions and scopes.

Limits and timeouts#

ValueNotes
MCP rate limit5 requests / secondPer grant (OAuth) or per key (API key). Exceeding it returns a JSON-RPC error, and the attempt is recorded.
MCP request timeout300 secondsTool calls are answered on the same request. Image generation and article writing routinely take 90 to 120 seconds.
Content API page size30 itemslimit is capped server-side.
Access token lifetime60 minutesRefresh tokens last 60 days and rotate on every use.
Authorization code lifetime60 secondsPKCE, single use.

You can see every call#

Every MCP request is written to an activity log against your account: which app called, which tool, on which project, with which arguments, and what it was told -- including the calls that were refused by a permission or a rate limit. It is in the dashboard under Settings -> MCP activity. Refused credentials are attributed too, when the token is recognizable, so a revoked app that keeps knocking is visible rather than silent.

Where to go next#