MCP
Connect a client
Copy-paste setup for Claude, Claude Code, Cursor and any other MCP client, plus the headless path for a server that has no browser.
Every MCP client needs the same thing: one URL. Sign-in is OAuth 2.1 with dynamic client registration and PKCE, so there is nothing to create on the Reblog side first.
https://reblog.so/api/mcpPer client#
Settings -> Connectors -> Add custom connector
Name: Reblog
URL: https://reblog.so/api/mcp
A Reblog consent screen opens in your browser.
Pick the access level and the projects, then approve.What the consent screen asks#
Two questions, both of which you can change later by revoking and reconnecting.
- 1
How much access
Read-only to look but never touch. Read + create/edit for an app that writes and publishes but can never delete. Full access for everything except the sensitive capabilities. Custom to tick individual capabilities yourself.
- 2
Which projects
The connection reaches the projects and workspaces you select, and nothing else. A tool call naming any other project is refused.
Presets stay current, custom grants stay frozen
A preset grant re-expands against the live vocabulary, so it picks up new non-sensitive capabilities as they ship. A custom grant keeps exactly the capabilities you ticked, forever. That is the trade-off: a custom grant never gains a power you did not choose, and it never gains a new feature either -- the server tells the agent when that is why a tool is missing.
Check that it worked#
Ask the client to call list_projects, then describe_project. The first proves the connection resolves your projects; the second returns a one-call overview -- languages, article counts, the idea backlog, and, if permitted, the active agents and the job queue.
A good first prompt
"List my Reblog projects, then describe the first one and tell me what it should publish next." It exercises discovery, the read tools and the editorial planning tools in one go.
When a connection covers several projects#
Every project-scoped tool then gains a project_id argument, and the client must pass it. With exactly one project reachable, it is inferred and you can leave it out. list_projects returns the ids.
Credits are spent per project
Generating an article or an image bills the project it is filed under, and the image lands in that project's asset library. When several projects are reachable, say which one you mean rather than letting the agent choose.
Headless: connecting with an API key#
A server-side agent with no browser cannot complete an OAuth consent. Give it a project API key instead and send it as a bearer token -- the MCP endpoint accepts both credentials on the same header.
curl -X POST https://reblog.so/api/mcp \
-H "Authorization: Bearer $REBLOG_API_KEY" \
-H "Content-Type: application/json" \
-d '{
"jsonrpc": "2.0",
"id": 1,
"method": "initialize",
"params": {
"protocolVersion": "2025-06-18",
"capabilities": {},
"clientInfo": { "name": "my-agent", "version": "1.0.0" }
}
}'- The key binds the connection to one project, so
project_idis never needed. - A read + write key (level 3) maps to full access on that project; a read key (level 2) to the read-only set.
- The key does not expire. Rotate it from the dashboard when a machine is decommissioned.
Revoking a connection#
In the dashboard, Settings -> Connected apps lists every grant with what it may do, which projects it reaches, and when it was last used. Revoking one kills its tokens immediately. API keys are revoked from the project's API keys screen.