truth-social-mcp
MCP server for explicitly authorized Truth Social access, offering read-only tools for profiles, timelines, search, and notifications, with optional write operations enabled only under explicit authorization and confirmation.
README
Truth Social MCP
A local Python MCP 2.x server for explicitly authorized Truth Social access. It keeps model-facing tools separate from credential setup, defaults to read-only, and treats all social content as untrusted external data.
Current safety boundary
Truth Social's current Terms of Service
prohibit automated/non-human access and data extraction unless separately
authorized. The server therefore starts and
negotiates MCP normally, but live network calls fail closed until
TRUTH_SOCIAL_MCP_AUTHORIZED=1 is configured. Set that variable only after
obtaining written authorization or an official API agreement.
This project does not bypass Cloudflare, impersonate a browser, or treat a logged-in browser session as API authorization.
Requirements
- Python 3.10+
- An OS credential store supported by Python
keyring(macOS Keychain on macOS) - An externally issued bearer token for authenticated tools
- Written permission or an official Truth Social API agreement for live use
uv0.11.26 for the reproducible locked installation below
Install
From a source checkout, install the exact dependency graph recorded in
uv.lock:
cd /absolute/path/to/truth-social-mcp
uv sync --locked --extra dev --no-editable --python python3
Portable pip fallback (compatible, but not locked to the exact transitive
versions in uv.lock):
cd /absolute/path/to/truth-social-mcp
python3 -m venv .venv
.venv/bin/python -m pip install --upgrade pip
.venv/bin/pip install '.[dev]'
The install creates two cwd-independent commands:
.venv/bin/truthsocial-mcp— MCP stdio server.venv/bin/truthsocial-auth— out-of-band token management
The two console commands are part of the installed Python distribution. By
contrast, run.sh is a convenience launcher that belongs to the source
checkout; it resolves that checkout's .venv regardless of the MCP host's
working directory. A wheel installation does not install run.sh or the
config-examples directory.
Configure a token safely
Never paste a password, OTP, bearer token, cookie, or access code into an MCP conversation. Import an externally authorized token directly in Terminal:
.venv/bin/truthsocial-auth set-token --username your_handle --scope read
.venv/bin/truthsocial-auth status
Declared scopes are enforced locally as an additional safety gate. If an
authorized token is permitted to perform every supported mutation, import it
with --scope read --scope write --scope follow; write covers post/media/
like/retruth/delete operations, while follow covers follow/unfollow. Enabling
the write environment flag alone never overrides a missing local scope.
The command prompts for the token without echoing it. The token is stored in the
operating-system credential store selected by keyring (Keychain on macOS).
~/.truth_social_mcp/session.json contains only non-secret metadata and is
written atomically with mode 0600 inside a 0700 directory.
To remove the token:
.venv/bin/truthsocial-auth clear
Run and register
For a normal environment installation, point the MCP host directly at the installed console command:
{
"mcpServers": {
"truth-social": {
"command": "/absolute/path/to/truth-social-mcp/.venv/bin/truthsocial-mcp",
"args": []
}
}
}
Codex registration for the installed console command:
codex mcp add truth-social -- /absolute/path/to/truth-social-mcp/.venv/bin/truthsocial-mcp
When Codex should follow the source checkout's .venv, the repository launcher
is equivalent:
codex mcp add truth-social -- /absolute/path/to/truth-social-mcp/run.sh
config-examples/continue_config.yaml is the current Continue configuration.
continue_config.legacy.json is retained only for older Continue releases that
still use the deprecated JSON configuration.
The server is intentionally useful even when network access is disabled:
truth_auth_status reports local configuration without reading the network.
Authorization and environment
After written authorization or an official API agreement, enable live calls in the MCP host's environment:
TRUTH_SOCIAL_MCP_AUTHORIZED=1
Optional settings:
| Variable | Default | Purpose |
|---|---|---|
TRUTH_SOCIAL_MCP_AUTHORIZED |
0 |
Permit live API calls after external authorization |
TRUTH_SOCIAL_MCP_ALLOW_WRITES |
0 |
Register mutation tools at startup |
TRUTH_SOCIAL_MCP_UPLOAD_ROOTS |
~/.truth_social_mcp/uploads |
:-separated media roots |
TRUTH_SOCIAL_MCP_MAX_UPLOAD_MB |
25 |
Maximum local media size |
TRUTH_SOCIAL_MCP_TIMEOUT_MS |
30000 |
Request timeout |
TRUTH_SOCIAL_MCP_BASE_URL |
https://truthsocial.com |
API origin; mainly for authorized/test deployments |
TRUTH_SOCIAL_MCP_ALLOW_CUSTOM_ORIGIN |
0 |
Permit a non-Truth-Social HTTPS test/authorized origin |
TRUTH_SOCIAL_MCP_USER_AGENT |
truthsocial-mcp/<version> ... |
Honest client identification |
Tool surface
Default server tools:
- Local:
truth_auth_status,truth_logout - Public API:
truth_instance_info,truth_lookup_user,truth_get_user_posts,truth_get_status - Token-required reads:
truth_verify,truth_get_user,truth_followers,truth_following,truth_home_timeline,truth_trending,truth_get_thread,truth_search,truth_notifications
Truth Social's removed public timeline endpoint is not advertised. Search and trending are correctly marked token-required rather than returning fake empty results.
When both TRUTH_SOCIAL_MCP_AUTHORIZED=1 and
TRUTH_SOCIAL_MCP_ALLOW_WRITES=1 are present at server startup, these additional
tools are registered:
truth_post_status,truth_delete_statustruth_like,truth_unliketruth_reblog,truth_unreblogtruth_follow,truth_unfollowtruth_upload_media
Every mutation requires schema-level confirm: true. Posting also uses an
idempotency key. Uploads accept only relative paths beneath configured roots,
reject symlinks and non-regular files, enforce size limits, and verify supported
media signatures.
Error behavior
- MCP 2.x validates tool arguments before executing handlers.
- Tool failures return real
isError: trueresults. - Upstream HTML, response bodies, tokens, cookies, usernames, query strings and local paths are not copied into error messages.
- Stable error codes distinguish missing auth, forbidden access, missing resources/endpoints, rate limits, invalid payloads and network failures.
- Public and authenticated HTTP traffic use physically separate clients; anonymous calls cannot inherit an account token or cookie.
Test
.venv/bin/pytest
.venv/bin/python -m pip check
uv lock --check
The default suite uses in-memory MCP sessions and httpx.MockTransport; it does
not contact Truth Social and never performs a real post, like, follow, upload or
delete. A subprocess test starts run.sh from outside the repository to protect
against cwd/import regressions and also exercises the installed console
entrypoint. CI repeats the locked install and full suite on Python 3.10, 3.11,
and 3.12.
Known external limitations
Truth Social does not currently publish a stable, generally authorized API contract for this use. Endpoint availability, authentication requirements, Cloudflare policy and account permissions may change independently of this server. Passing local tests proves the MCP implementation, not external API permission or future availability.
License
MIT. See LICENSE.
推荐服务器
Baidu Map
百度地图核心API现已全面兼容MCP协议,是国内首家兼容MCP协议的地图服务商。
Playwright MCP Server
一个模型上下文协议服务器,它使大型语言模型能够通过结构化的可访问性快照与网页进行交互,而无需视觉模型或屏幕截图。
Magic Component Platform (MCP)
一个由人工智能驱动的工具,可以从自然语言描述生成现代化的用户界面组件,并与流行的集成开发环境(IDE)集成,从而简化用户界面开发流程。
Audiense Insights MCP Server
通过模型上下文协议启用与 Audiense Insights 账户的交互,从而促进营销洞察和受众数据的提取和分析,包括人口统计信息、行为和影响者互动。
VeyraX
一个单一的 MCP 工具,连接你所有喜爱的工具:Gmail、日历以及其他 40 多个工具。
graphlit-mcp-server
模型上下文协议 (MCP) 服务器实现了 MCP 客户端与 Graphlit 服务之间的集成。 除了网络爬取之外,还可以将任何内容(从 Slack 到 Gmail 再到播客订阅源)导入到 Graphlit 项目中,然后从 MCP 客户端检索相关内容。
Kagi MCP Server
一个 MCP 服务器,集成了 Kagi 搜索功能和 Claude AI,使 Claude 能够在回答需要最新信息的问题时执行实时网络搜索。
e2b-mcp-server
使用 MCP 通过 e2b 运行代码。
Neon MCP Server
用于与 Neon 管理 API 和数据库交互的 MCP 服务器
Exa MCP Server
模型上下文协议(MCP)服务器允许像 Claude 这样的 AI 助手使用 Exa AI 搜索 API 进行网络搜索。这种设置允许 AI 模型以安全和受控的方式获取实时的网络信息。