truth-social-mcp

truth-social-mcp

MCP server for explicitly authorized Truth Social access, offering read-only tools for profiles, timelines, search, and notifications, with optional write operations enabled only under explicit authorization and confirmation.

Category
访问服务器

README

Truth Social MCP

A local Python MCP 2.x server for explicitly authorized Truth Social access. It keeps model-facing tools separate from credential setup, defaults to read-only, and treats all social content as untrusted external data.

Current safety boundary

Truth Social's current Terms of Service prohibit automated/non-human access and data extraction unless separately authorized. The server therefore starts and negotiates MCP normally, but live network calls fail closed until TRUTH_SOCIAL_MCP_AUTHORIZED=1 is configured. Set that variable only after obtaining written authorization or an official API agreement.

This project does not bypass Cloudflare, impersonate a browser, or treat a logged-in browser session as API authorization.

Requirements

  • Python 3.10+
  • An OS credential store supported by Python keyring (macOS Keychain on macOS)
  • An externally issued bearer token for authenticated tools
  • Written permission or an official Truth Social API agreement for live use
  • uv 0.11.26 for the reproducible locked installation below

Install

From a source checkout, install the exact dependency graph recorded in uv.lock:

cd /absolute/path/to/truth-social-mcp
uv sync --locked --extra dev --no-editable --python python3

Portable pip fallback (compatible, but not locked to the exact transitive versions in uv.lock):

cd /absolute/path/to/truth-social-mcp
python3 -m venv .venv
.venv/bin/python -m pip install --upgrade pip
.venv/bin/pip install '.[dev]'

The install creates two cwd-independent commands:

  • .venv/bin/truthsocial-mcp — MCP stdio server
  • .venv/bin/truthsocial-auth — out-of-band token management

The two console commands are part of the installed Python distribution. By contrast, run.sh is a convenience launcher that belongs to the source checkout; it resolves that checkout's .venv regardless of the MCP host's working directory. A wheel installation does not install run.sh or the config-examples directory.

Configure a token safely

Never paste a password, OTP, bearer token, cookie, or access code into an MCP conversation. Import an externally authorized token directly in Terminal:

.venv/bin/truthsocial-auth set-token --username your_handle --scope read
.venv/bin/truthsocial-auth status

Declared scopes are enforced locally as an additional safety gate. If an authorized token is permitted to perform every supported mutation, import it with --scope read --scope write --scope follow; write covers post/media/ like/retruth/delete operations, while follow covers follow/unfollow. Enabling the write environment flag alone never overrides a missing local scope.

The command prompts for the token without echoing it. The token is stored in the operating-system credential store selected by keyring (Keychain on macOS). ~/.truth_social_mcp/session.json contains only non-secret metadata and is written atomically with mode 0600 inside a 0700 directory.

To remove the token:

.venv/bin/truthsocial-auth clear

Run and register

For a normal environment installation, point the MCP host directly at the installed console command:

{
  "mcpServers": {
    "truth-social": {
      "command": "/absolute/path/to/truth-social-mcp/.venv/bin/truthsocial-mcp",
      "args": []
    }
  }
}

Codex registration for the installed console command:

codex mcp add truth-social -- /absolute/path/to/truth-social-mcp/.venv/bin/truthsocial-mcp

When Codex should follow the source checkout's .venv, the repository launcher is equivalent:

codex mcp add truth-social -- /absolute/path/to/truth-social-mcp/run.sh

config-examples/continue_config.yaml is the current Continue configuration. continue_config.legacy.json is retained only for older Continue releases that still use the deprecated JSON configuration.

The server is intentionally useful even when network access is disabled: truth_auth_status reports local configuration without reading the network.

Authorization and environment

After written authorization or an official API agreement, enable live calls in the MCP host's environment:

TRUTH_SOCIAL_MCP_AUTHORIZED=1

Optional settings:

Variable Default Purpose
TRUTH_SOCIAL_MCP_AUTHORIZED 0 Permit live API calls after external authorization
TRUTH_SOCIAL_MCP_ALLOW_WRITES 0 Register mutation tools at startup
TRUTH_SOCIAL_MCP_UPLOAD_ROOTS ~/.truth_social_mcp/uploads :-separated media roots
TRUTH_SOCIAL_MCP_MAX_UPLOAD_MB 25 Maximum local media size
TRUTH_SOCIAL_MCP_TIMEOUT_MS 30000 Request timeout
TRUTH_SOCIAL_MCP_BASE_URL https://truthsocial.com API origin; mainly for authorized/test deployments
TRUTH_SOCIAL_MCP_ALLOW_CUSTOM_ORIGIN 0 Permit a non-Truth-Social HTTPS test/authorized origin
TRUTH_SOCIAL_MCP_USER_AGENT truthsocial-mcp/<version> ... Honest client identification

Tool surface

Default server tools:

  • Local: truth_auth_status, truth_logout
  • Public API: truth_instance_info, truth_lookup_user, truth_get_user_posts, truth_get_status
  • Token-required reads: truth_verify, truth_get_user, truth_followers, truth_following, truth_home_timeline, truth_trending, truth_get_thread, truth_search, truth_notifications

Truth Social's removed public timeline endpoint is not advertised. Search and trending are correctly marked token-required rather than returning fake empty results.

When both TRUTH_SOCIAL_MCP_AUTHORIZED=1 and TRUTH_SOCIAL_MCP_ALLOW_WRITES=1 are present at server startup, these additional tools are registered:

  • truth_post_status, truth_delete_status
  • truth_like, truth_unlike
  • truth_reblog, truth_unreblog
  • truth_follow, truth_unfollow
  • truth_upload_media

Every mutation requires schema-level confirm: true. Posting also uses an idempotency key. Uploads accept only relative paths beneath configured roots, reject symlinks and non-regular files, enforce size limits, and verify supported media signatures.

Error behavior

  • MCP 2.x validates tool arguments before executing handlers.
  • Tool failures return real isError: true results.
  • Upstream HTML, response bodies, tokens, cookies, usernames, query strings and local paths are not copied into error messages.
  • Stable error codes distinguish missing auth, forbidden access, missing resources/endpoints, rate limits, invalid payloads and network failures.
  • Public and authenticated HTTP traffic use physically separate clients; anonymous calls cannot inherit an account token or cookie.

Test

.venv/bin/pytest
.venv/bin/python -m pip check
uv lock --check

The default suite uses in-memory MCP sessions and httpx.MockTransport; it does not contact Truth Social and never performs a real post, like, follow, upload or delete. A subprocess test starts run.sh from outside the repository to protect against cwd/import regressions and also exercises the installed console entrypoint. CI repeats the locked install and full suite on Python 3.10, 3.11, and 3.12.

Known external limitations

Truth Social does not currently publish a stable, generally authorized API contract for this use. Endpoint availability, authentication requirements, Cloudflare policy and account permissions may change independently of this server. Passing local tests proves the MCP implementation, not external API permission or future availability.

License

MIT. See LICENSE.

推荐服务器

Baidu Map

Baidu Map

百度地图核心API现已全面兼容MCP协议,是国内首家兼容MCP协议的地图服务商。

官方
精选
JavaScript
Playwright MCP Server

Playwright MCP Server

一个模型上下文协议服务器,它使大型语言模型能够通过结构化的可访问性快照与网页进行交互,而无需视觉模型或屏幕截图。

官方
精选
TypeScript
Magic Component Platform (MCP)

Magic Component Platform (MCP)

一个由人工智能驱动的工具,可以从自然语言描述生成现代化的用户界面组件,并与流行的集成开发环境(IDE)集成,从而简化用户界面开发流程。

官方
精选
本地
TypeScript
Audiense Insights MCP Server

Audiense Insights MCP Server

通过模型上下文协议启用与 Audiense Insights 账户的交互,从而促进营销洞察和受众数据的提取和分析,包括人口统计信息、行为和影响者互动。

官方
精选
本地
TypeScript
VeyraX

VeyraX

一个单一的 MCP 工具,连接你所有喜爱的工具:Gmail、日历以及其他 40 多个工具。

官方
精选
本地
graphlit-mcp-server

graphlit-mcp-server

模型上下文协议 (MCP) 服务器实现了 MCP 客户端与 Graphlit 服务之间的集成。 除了网络爬取之外,还可以将任何内容(从 Slack 到 Gmail 再到播客订阅源)导入到 Graphlit 项目中,然后从 MCP 客户端检索相关内容。

官方
精选
TypeScript
Kagi MCP Server

Kagi MCP Server

一个 MCP 服务器,集成了 Kagi 搜索功能和 Claude AI,使 Claude 能够在回答需要最新信息的问题时执行实时网络搜索。

官方
精选
Python
e2b-mcp-server

e2b-mcp-server

使用 MCP 通过 e2b 运行代码。

官方
精选
Neon MCP Server

Neon MCP Server

用于与 Neon 管理 API 和数据库交互的 MCP 服务器

官方
精选
Exa MCP Server

Exa MCP Server

模型上下文协议(MCP)服务器允许像 Claude 这样的 AI 助手使用 Exa AI 搜索 API 进行网络搜索。这种设置允许 AI 模型以安全和受控的方式获取实时的网络信息。

官方
精选