MCP
MCP server
Reblog speaks the Model Context Protocol: 56 tools that let Claude, Claude Code, Cursor or your own agent research, write, illustrate, translate, publish and audit a blog, under permissions you control and can revoke.
MCP is the open standard for connecting an AI client to a system it can act on. Reblog implements it as a server, so there is no SDK to install and no glue code to write: an MCP client that knows the URL can read your drafts, write a new article, generate its cover, translate it into every language the project runs, and book it for next Tuesday.
| Server URL | https://reblog.so/api/mcp |
| Transport | Streamable HTTP -- stateless JSON-RPC 2.0 over POST |
| Protocol version | 2025-06-18 |
| Server identity | reblog-mcp 1.0.0 |
| Authentication | OAuth 2.1 (recommended) or a project API key |
| Discovery | https://reblog.so/.well-known/oauth-protected-resource |
| Tools | 56, in 11 permission groups |
Two minutes to connect
Paste the URL into your client, approve the access level in your browser, done. No client id, no secret, no allowlist. Connect a client.
What people actually use it for#
Publish end to end
generate_article writes the draft from a topic and draws its cover in the same job, then publish_article puts it live or schedule_article books a date.
Run the whole backlog
create_idea files topics, list_article_ideas reviews them, promote_idea turns the good ones into drafts.
Write from an X thread
tweet_to_article reads a post AND the discussion under it, and follows the chain: a post that quotes or answers another one is commentary, so the post underneath is read too, with its own replies. The article then says what the original claimed, what the post on top made of it, and where the two reply sections disagree. How far it reads and what the piece should be are the project's own rules, set once with configure_agent on agent type tweet-to-article. scrape_tweet reads all of that for free, analyze_tweet_discussion returns the angle before anything is written, and tweet_to_article reuses both instead of paying for the same read twice. A thread the project has already turned into an article is refused rather than written again, and the existing piece is named.
Go multilingual
translate_missing fills every language a project runs, remapping internal links to the target-language article as it goes.
Fix the pictures
Seven tools operate on the images inside one article, so a photo can be swapped, moved or re-captioned without rewriting a word of the body.
Plan the month
get_publishing_cadence, suggest_publishing_slots and get_content_calendar turn "post twice a week" into actual dates.
Audit what is there
get_content_gaps finds what is missing, find_articles_to_refresh finds what has gone stale, get_article_history shows who changed what.
The catalogue, in one glance#
Each group below is unlocked by one permission. A connection is offered only the groups it was granted, so a read-only app never even sees the tools that write.
| Group | Tools | What it unlocks |
|---|---|---|
account.projects.read | 3 | Which projects this connection can reach, and which of them need an article. |
articles.read | 14 | Articles, categories, revision history, the images in a post, the calendar, content gaps, stale posts, and reading an X thread. |
articles.create | 2 | Write a finished article yourself, or file an idea. |
articles.edit | 16 | Update, patch, roll back, re-illustrate, draw a cover, italicise, publish, schedule, unpublish, approve, purge the live site cache. |
articles.delete | 1 | Delete an article. |
agents.read | 4 | The configured agents, the idea backlog, the job queue, the available image models. |
agents.run | 10 | Write, translate, illustrate, recommend, turn an X thread into an article, configure, cancel. Spends AI credits. |
assets.read / assets.create / assets.delete | 3 | The project media library. |
automation.manage | 3 | The scheduled autopilot routines. Sensitive: never granted by a preset. |
Every tool, with its arguments and the roles that may call it: tool reference.
What keeps it safe#
Handing an agent write access to your blog is a real decision, so the server is built around four properties you can check rather than trust.
- 1
You choose the access level, per connection
The consent screen offers read-only, read plus create and edit, or full access, and a custom mode where you tick capabilities one by one. You also choose which projects the connection can reach.
- 2
A connection can never exceed you
Every call is checked twice: against the grant, and against your live role on the target project. An app with full access still cannot delete an article where you are a contributor.
- 3
New powers are never granted retroactively
A capability added after you approved a connection is not silently acquired by it. Sensitive capabilities -- automation routines today, billing and membership tomorrow -- can only ever be granted by an explicit, itemized consent.
- 4
Everything is on the record
Which app, which tool, which project, which arguments, what it was told, how long it took. Successes, refusals and rejected credentials alike, in Settings -> MCP activity.
The full model, scope by scope and role by role: permissions and scopes.
Next#
Connect a client
Claude, Claude Code, Cursor, and anything else that speaks MCP.
Tool reference
All 56 tools, grouped by permission, with every argument.
Permissions
Scopes, presets, project roles, and how they intersect.
Protocol
The JSON-RPC methods, project routing, and the setup handshake.
OAuth 2.1
For people building the client, not just using one.
Errors
What a refusal looks like and how to read it.