autoapply-mcp
An MCP server that automates job applications by discovering postings from ATS boards, applying eligibility gates, scoring candidates, and drafting answers, while requiring human approval before submission. It respects anti-bot controls and only submits with explicit consent.
README
autoapply-mcp
An MCP server that turns a verified candidate profile into a governed job-application pipeline: it discovers postings from public ATS boards, applies hard eligibility gates, scores what survives with quotable evidence, drafts only the answers your profile actually supports, and refuses to submit anything without a recorded human approval.
It is built for high-volume search without becoming a spam bot. Discovery, ranking and form-filling are automated. Judgement, truthfulness and consent are not.
What it does
| Stage | Behaviour |
|---|---|
| Discover | Fetches Greenhouse, Lever and Ashby public job-board APIs for the companies you configure |
| Gate | Hard-rejects on location, seniority, compensation floor, clearance, citizenship and sponsorship constraints |
| Score | Ranks survivors across seven weighted dimensions, each with the quote that earned it |
| Draft | Builds a match report, loads the employer's real questions, and answers only what verified profile data supports |
| Approve | Binds a human approval to a hash of the exact submission content |
| Submit | Manual, assisted or auto - never beyond the mode the campaign permits |
| Track | Records submissions, outcomes and an append-only audit log |
Design rules
- Nothing is invented. Every drafted answer traces to a profile field or a pre-approved answer. Anything else is handed back to you.
- Sensitive questions always stop. Work authorization, citizenship, compensation, criminal history, demographics and legal attestations require a human decision by default.
- Approval binds to content.
approve_applicationrecords a packet hash. Editing anything invalidates it and submission is refused. - Job descriptions are untrusted data. Text from employers is scanned for prompt-injection patterns, wrapped in an explicit data boundary, and never treated as instructions.
- Anti-bot controls are respected. A detected CAPTCHA aborts the run and hands the application back to you. There is no solving, evading or fingerprint spoofing.
- Destinations are allowlisted. Submissions only go to hosts the campaign explicitly trusts, over HTTPS.
Requirements
- Node.js 22.5 or newer (uses the built-in
node:sqlite, so there is no native build step) - Playwright, only if you want assisted or automatic form filling:
npm install playwright && npx playwright install chromium
Install
git clone <your-fork> autoapply-mcp
cd autoapply-mcp
npm install
npm run build
npm test
Configure
Personal data lives outside the repository, so a checkout can be published as-is. The default home is ~/.autoapply:
mkdir -p ~/.autoapply
cp examples/profile.example.json ~/.autoapply/profile.json
cp examples/campaign.example.json ~/.autoapply/campaign.json
cp presets/ai-security-us-canada.json ~/.autoapply/companies.json
Then edit them and verify:
node dist/cli/doctor.js --probe
doctor validates all three files, checks that your resume files exist and are real PDFs, confirms every track points at a resume variant, and probes each configured board.
presets/ai-security-us-canada.json ships 80 company boards that were verified live against the ATS APIs, weighted toward AI, security and infrastructure companies in the US and Canada.
Nothing in this repository is specific to one candidate. Keep profile.json, resumes and the database in ~/.autoapply and they can never be committed by accident.
Environment variables
| Variable | Default | Purpose |
|---|---|---|
AUTOAPPLY_HOME |
~/.autoapply |
Root for config, database and artifacts |
AUTOAPPLY_PROFILE |
$HOME/profile.json |
Candidate profile |
AUTOAPPLY_CAMPAIGN |
$HOME/campaign.json |
Campaign policy |
AUTOAPPLY_COMPANIES |
$HOME/companies.json |
Company board list |
AUTOAPPLY_DB |
$HOME/data/autoapply.sqlite |
SQLite database |
AUTOAPPLY_ARTIFACTS |
$HOME/artifacts |
Screenshots and submission evidence |
AUTOAPPLY_LOG_LEVEL |
info |
debug, info, warn, error |
AUTOAPPLY_MIN_INTERVAL_MS |
700 |
Minimum delay between requests to one host |
AUTOAPPLY_MAX_RESPONSE_MB |
64 |
Response size ceiling |
Register with an MCP client
{
"mcpServers": {
"autoapply": {
"command": "node",
"args": ["/absolute/path/to/autoapply-mcp/dist/index.js"],
"env": { "AUTOAPPLY_HOME": "/absolute/path/to/your/.autoapply" }
}
}
}
The server speaks stdio. All logs go to stderr, so stdout stays clean for the protocol. AUTOAPPLY_HOME can be omitted if you use the default ~/.autoapply.
Typical session
Single application:
discover_jobs -> fetch every board, gate, score, store
list_queue -> the ranked, de-duplicated shortlist
explain_job jobId -> gate result and scoring evidence
prepare_application jobId -> match report, employer questions, drafted answers
set_application_content -> your cover letter and any answers only you can give
preview_application -> the exact packet plus its hash
approve_application + hash -> your explicit authorization
submit_application mode -> manual, assisted or auto
record_outcome -> track what happened
High volume:
prepare_batch {tiers:["A","B"], locationClasses:["bay-area"], minCompensation:250000}
preview_batch -> the set, plus grouped blocking questions
approve_batch + manifestHash + expectedCount
submit_batch mode -> honours daily limit and pacing
list_batches -> progress
See docs/TOOLS.md for every tool, docs/BATCH.md for high-volume campaigns and cached personal data, docs/CONFIGURATION.md for the schemas, docs/RESUMES.md for resume variants and LaTeX builds, and docs/SAFETY.md for the guarantees and their limits.
Submission modes
| Mode | Behaviour | Use it when |
|---|---|---|
manual |
Server prepares the packet; you submit it yourself | Always start here |
assisted |
Server fills the hosted form in a visible browser and leaves it open for you to review and submit | After the manual pilot proves the packets are right |
auto |
Server fills and clicks submit | Only for allowlisted companies on forms you have already seen work |
auto additionally requires the company to appear in submission.allowedCompanies, every required field to be fillable, and no blocked questions to remain unanswered.
What it deliberately does not do
- No LinkedIn, Indeed or Wellfound automation. Their terms prohibit it and their anti-bot systems are built to stop it. Use their alerts as leads, then apply through the employer's own board.
- No Workday support. Each tenant is bespoke, session-bound and protected; a candidate-side integration cannot be done reliably or respectfully.
- No CAPTCHA solving, proxy rotation or fingerprint evasion.
- No writing of your resume prose or cover letters. The server supplies structured evidence; your agent writes the words and you approve them.
Known limitations
- Compensation parsed from description text is a heuristic. Postings that list several geographic pay zones can yield the wrong figure, so those results carry a
compensation-parsed-from-textflag. Structured ATS pay data is preferred whenever a board publishes it. - FX rates in
campaign.jsonare static. Update them before relying on a cross-currency floor. - Only Greenhouse publishes an application question schema. For Lever and Ashby the server drafts against a baseline field set and reads the real form during an assisted run.
@modelcontextprotocol/sdkcurrently pulls a transitive advisory in@hono/node-serveraffecting its static-file server. This server uses the stdio transport only and never serves static files, so the affected code path is not reachable.
Development
npm run typecheck
npm test
npm run coverage
174 tests cover location classification, compensation parsing, every gate, scoring, the answer policy, resume validation, submission guards, packet hashing, persistence, the ATS adapters and an end-to-end run through a real in-memory MCP client.
License
MIT
推荐服务器
Baidu Map
百度地图核心API现已全面兼容MCP协议,是国内首家兼容MCP协议的地图服务商。
Playwright MCP Server
一个模型上下文协议服务器,它使大型语言模型能够通过结构化的可访问性快照与网页进行交互,而无需视觉模型或屏幕截图。
Magic Component Platform (MCP)
一个由人工智能驱动的工具,可以从自然语言描述生成现代化的用户界面组件,并与流行的集成开发环境(IDE)集成,从而简化用户界面开发流程。
Audiense Insights MCP Server
通过模型上下文协议启用与 Audiense Insights 账户的交互,从而促进营销洞察和受众数据的提取和分析,包括人口统计信息、行为和影响者互动。
VeyraX
一个单一的 MCP 工具,连接你所有喜爱的工具:Gmail、日历以及其他 40 多个工具。
graphlit-mcp-server
模型上下文协议 (MCP) 服务器实现了 MCP 客户端与 Graphlit 服务之间的集成。 除了网络爬取之外,还可以将任何内容(从 Slack 到 Gmail 再到播客订阅源)导入到 Graphlit 项目中,然后从 MCP 客户端检索相关内容。
Kagi MCP Server
一个 MCP 服务器,集成了 Kagi 搜索功能和 Claude AI,使 Claude 能够在回答需要最新信息的问题时执行实时网络搜索。
e2b-mcp-server
使用 MCP 通过 e2b 运行代码。
Neon MCP Server
用于与 Neon 管理 API 和数据库交互的 MCP 服务器
Exa MCP Server
模型上下文协议(MCP)服务器允许像 Claude 这样的 AI 助手使用 Exa AI 搜索 API 进行网络搜索。这种设置允许 AI 模型以安全和受控的方式获取实时的网络信息。