coilyco

bluesky-mcp

Community coilyco
Updated

Authenticated read-only Bluesky MCP with a fixed, bounded AT Protocol tool surface.

bluesky-mcp

bluesky-mcp is Kai's authenticated, strictly read-only Bluesky MCP. It usesthe official AT Protocol SDK to create and refresh an internal app-passwordsession, and the official MCP SDK streamable-HTTP transport to serve a small,reviewed tool surface.

Transport and configuration

The process serves GET /healthz and MCP streamable HTTP at POST /mcp.Defaults are HOST=0.0.0.0 and PORT=9113. Set these runtime variables:

  • BSKY_APP_PASSWORD (required): app password supplied only at runtime.
  • BSKY_HANDLE (optional): authenticated account handle; defaults tocoilysiren.me.
  • MCP_ALLOWED_HOSTS (optional): comma-separated hosts accepted by the MCPtransport's DNS-rebinding defense. It defaults to local development hosts.

Run locally with an app password supplied out of band:

just install
BSKY_APP_PASSWORD=... just run

Exact tool inventory

  1. get_profile
  2. search_profiles
  3. search_posts
  4. get_author_feed
  5. get_posts
  6. get_post_thread
  7. list_followers
  8. list_follows
  9. get_home_timeline
  10. list_notifications
  11. get_kai_liked_posts

All page sizes are bounded to 50 or below. Post batches are capped at 25 andthread depth plus parent height at 6.

Threat model

The configured app password can authorize account writes, so the adapter mustnever expose that authority. It has no post, reply, follow, like, repost,delete, mute, block, report, moderation, chat, account mutation, login,generic URL, arbitrary XRPC, or raw HTTP tool. Inputs accept only bounded,validated actors, post AT URIs, cursors, queries, and limits. The app passwordand session tokens remain in process memory and credential-shaped result fieldsare stripped before an MCP response is created. SDK failures are deliberatelylogged without their values.

The source image runs as the non-root node user. Deployment access control,secret injection, and network exposure are intentionally outside this sourcerepository.

Development

just lint, just typecheck, just test, just audit, and just precommitare the supported validation verbs. A main-branch workflow tests and publishesthe private imageforgejo.coilysiren.me/coilyco-flight-deck/bluesky-mcp:<full-source-sha>.Deployment uses a separate read-only forgejo-registry pull credential.

See also

  • AGENTS.md - agent operating rules for this repository.
  • docs/FEATURES.md - inventory of what ships today.
  • justfile - dev verbs.
  • .ward/ward.yaml - catalog metadata only.

MCP Server · Populars

MCP Server · New

    vanshyadav1408

    Omentir

    Open Source HeyReach & Gojiberry alternative

    Community vanshyadav1408
    irinabuht12-oss

    Google Ads MCP + Meta Ads MCP (Facebook Ads MCP) + GA4: one hosted MCP server for Claude, ChatGPT and Cursor

    Google Ads MCP server + Meta Ads MCP (Facebook Ads MCP) + GA4 + Search Console in one hosted remote MCP for Claude, ChatGPT, Cursor & n8n: 250+ tools, OAuth login, no API keys, approval-gated writes, free. By Ryze AI.

    Community irinabuht12-oss
    silamir

    BoondManager MCP Server

    Serveur MCP pour l'API BoondManager (ERP/CRM des ESN) : 182 outils, 12 prompts et 22 ressources pour piloter candidats, consultants, opportunités, projets, CRA, notes de frais et facturation depuis Claude. TypeScript, transports stdio et HTTP (OAuth2). Un projet Silamir.

    Community silamir
    infino-ai

    supergrep

    Retrieval + inference offload for AI coding agents.

    Community infino-ai
    SylphxAI

    anymd

    Any file → clean Markdown for AI agents: PDF, Word, PowerPoint, Excel, EPUB, HTML and web pages, images (OCR), audio and video (metadata, subtitles, transcripts). A fast Rust MCP server and CLI that runs on your machine. No API key.

    Community SylphxAI