Skip to documentation

MCP setup

Connect an approved host and verify profile and project reads.

Connection prerequisites

  • Maintainer-approved test access and a dedicated registered client for this host, with S256 PKCE and its exact callback. Dynamic client registration is disabled.
  • Local resource: https://localhost:3005/mcp; app: https://localhost:3000.
  • Hosted dev resource: https://mcp-dev.postede.com/mcp; app: https://dev.postede.com.
  • ChatGPT cannot reach localhost directly. A local test needs an explicitly approved HTTPS tunnel and a client registered with the exact callback shown by the host. Live ChatGPT acceptance and production readiness are unverified.

Stop if the host’s registration or matching resource is unavailable. Keep each host and environment’s client/grant separate.

Connect and verify

  1. Add the exact registered MCP resource in the host.
  2. The user completes the host’s browser OAuth flow and chooses permissions. The host manages credentials and token exchange.
  3. Discover the host’s available tools, then call get_profile and list_projects with empty arguments.
Read-only verification prompt
Show my Postede profile and list my projects. Do not change content, settings or delivery state.

Confirm the intended account/environment and successful reads. An empty project list is valid. Use the discovered catalog: hosts may expose 12 baseline tools or all 29 with parity enabled.

Connection recovery

  • Expired access: let the host refresh. Reconnect through its OAuth flow if refresh fails or consent is revoked.
  • Missing tool: inspect the discovered catalog and operator-enabled capabilities; do not assume all 29 are exposed.
  • Permission denied: check scope, project role and consent. After a user changes permissions, reconnect for an updated grant.
  • Rate limit: follow the returned retry interval; do not loop or repeatedly reconnect.

Disconnect

Revoke the grant in Connected apps in the same environment, then remove the connection from the host. Never request passwords, cookies or tokens in conversation.

V-2026-10-05_17.35.45