PluginBench
MCP Server
Active
MIT

io.github.cameronrye/activitypub-mcp MCP Server

io.github.cameronrye/activitypub-mcp

Fediverse client for LLMs—explore Mastodon, Misskey, Pleroma, and ActivityPub servers safely.

What is the io.github.cameronrye/activitypub-mcp MCP server?

The ActivityPub MCP Server is a lightweight Model Context Protocol server that lets LLMs explore and interact with the Fediverse—Mastodon, Misskey, Foundkey, Pleroma, and compatible servers. It is read-only by default, with write tools available only when explicitly enabled, prioritizing safety for LLM-driven interactions.

This server bridges LLMs to the decentralized social web, enabling discovery of actors, timeline browsing, searching, thread exploration, and trending-content analysis across ActivityPub-compatible platforms. Use it to research Fediverse content, summarize posts, curate topics, or automate social interactions—all with built-in prompt-injection protections and optional authentication.

How to install io.github.cameronrye/activitypub-mcp

Copy-paste configuration for popular MCP clients.

transport: stdio
Config generated by PluginBench — verify against the source before use.
Environment / auth
  • ACTIVITYPUB_ENABLE_WRITES

    Enable write/mutation tools (post, reply, follow, boost, block). Off by default: read-only unless set to 'true'. See SECURITY.md.

  • LOG_LEVEL

    Logging verbosity: debug, info, warn, or error.

~/Library/Application Support/Claude/claude_desktop_config.json
{
  "mcpServers": {
    "activitypub-mcp": {
      "command": "npx",
      "args": [
        "-y",
        "activitypub-mcp"
      ],
      "env": {
        "ACTIVITYPUB_ENABLE_WRITES": "<YOUR_ACTIVITYPUB_ENABLE_WRITES>",
        "LOG_LEVEL": "<YOUR_LOG_LEVEL>"
      }
    }
  }
}

Tools & capabilities

Tools this server exposes to the agent.

  • discover-actor — Look up an actor (user or bot) by handle across any ActivityPub server using WebFinger.
  • fetch-timeline — Retrieve recent posts from an actor's outbox on any ActivityPub-conformant server.
  • search — Search posts, hashtags, and accounts on Mastodon- or Misskey-API instances.
  • get-post-thread — Fetch a full conversation thread starting from a post.
  • get-instance-info — Retrieve metadata and configuration for a Fediverse instance.
  • get-public-timeline — Fetch the public timeline from a Mastodon- or Misskey-API instance.
  • get-trending-hashtags — List trending hashtags on a Mastodon- or Misskey-API instance.
  • get-trending-posts — Fetch trending posts from a Mastodon- or Misskey-API instance.
  • discover-instances — Find and explore Fediverse instances.
  • list-accounts — List authenticated accounts (requires login).
  • switch-account — Switch the active authenticated account.
  • verify-account — Verify the current authenticated account.
  • get-home-timeline — Fetch the authenticated user's home timeline.
  • get-notifications — Retrieve notifications for the authenticated account.
  • get-bookmarks — List bookmarked posts for the authenticated user.
  • get-favourites — List favorited posts for the authenticated user.
  • get-relationship — Check relationship status with another account.
  • post — Create a new post (write tool; requires ACTIVITYPUB_ENABLE_WRITES=true).
  • reply — Reply to a post (write tool; requires ACTIVITYPUB_ENABLE_WRITES=true).
  • delete — Delete a post (write tool; requires ACTIVITYPUB_ENABLE_WRITES=true).

Use cases

  • Research and summarize posts from specific Fediverse accounts or trending topics.
  • Discover and explore ActivityPub-compatible servers and their public timelines.
  • Automate Fediverse interactions—post, reply, boost, favorite, and follow accounts (with writes enabled).
  • Monitor notifications and curate bookmarks or favorites for content curation workflows.
  • Build Fediverse research digests, notification triage systems, or topic-specific bots.

io.github.cameronrye/activitypub-mcp MCP server FAQ

What is the ActivityPub MCP Server?

It's an MCP server that gives LLMs read and optional write access to the Fediverse (Mastodon, Misskey, Pleroma, Lemmy, PeerTube, and other ActivityPub servers). It's read-only by default for safety.

Is it free?

Yes, it's open-source under the MIT license and available on npm as `activitypub-mcp`.

How do I install it in Cursor or Claude?

For Cursor, edit `~/.cursor/mcp.json` with the npx command. For Claude Desktop, use the one-click installer or manually edit the config file. VS Code Insiders also has a one-click install button.

Do I need to authenticate?

No—public read tools (discover-actor, fetch-timeline, search, etc.) work without login. Authenticated tools (home timeline, notifications, bookmarks) require OAuth login via the CLI: `npx activitypub-mcp login mastodon.social`.

Can I write posts or interact with accounts?

Yes, but only if you explicitly enable writes by setting `ACTIVITYPUB_ENABLE_WRITES=true` in the environment or MCP config. Write tools are opt-in for safety.

What platforms does it support?

Plain ActivityPub tools work on any conformant server (Mastodon, Misskey, Lemmy, PeerTube, GoToSocial, Pixelfed). Instance-API tools (search, trending, write) require Mastodon- or Misskey-API compatibility.

README (reference)

Source of truth, from the repository.

<p align="center"> <img src="public/logo.svg" alt="ActivityPub MCP Logo" width="200" /> </p> <h1 align="center">ActivityPub MCP Server</h1> <p align="center"> <strong>Fediverse Client for LLMs</strong> </p> <p align="center"> A lightweight <strong>Model Context Protocol (MCP)</strong> server that lets an LLM explore and interact with the existing Fediverse — Mastodon, Misskey, Foundkey, Pleroma, and compatible servers. Read-only by default; write tools are opt-in. </p> <!-- DEMO: record a ~20-30s screen capture of a Claude session using activitypub-mcp (see docs/launch-kit.md for the shot list), save it to docs/demo.gif, then uncomment the block below. Kept commented so the README never shows a broken image. <p align="center"> <img src="docs/demo.gif" alt="Demo: Claude exploring the Fediverse via activitypub-mcp" width="720" /> </p> --> <p align="center"> <a href="https://badge.fury.io/js/activitypub-mcp"><img src="https://badge.fury.io/js/activitypub-mcp.svg" alt="npm version" /></a> <a href="https://opensource.org/licenses/MIT"><img src="https://img.shields.io/badge/License-MIT-yellow.svg" alt="License: MIT" /></a> <a href="https://www.typescriptlang.org/"><img src="https://img.shields.io/badge/TypeScript-007ACC?logo=typescript&logoColor=white" alt="TypeScript" /></a> <a href="https://nodejs.org/"><img src="https://img.shields.io/badge/Node.js-20+-339933?logo=node.js&logoColor=white" alt="Node.js" /></a> <a href="https://modelcontextprotocol.io/"><img src="https://img.shields.io/badge/MCP-Compatible-blueviolet" alt="MCP Compatible" /></a> </p> <p align="center"> <a href="https://github.com/cameronrye/activitypub-mcp/actions"><img src="https://github.com/cameronrye/activitypub-mcp/actions/workflows/ci.yml/badge.svg" alt="CI" /></a> <a href="https://www.npmjs.com/package/activitypub-mcp"><img src="https://img.shields.io/npm/dm/activitypub-mcp.svg" alt="npm downloads" /></a> <a href="https://github.com/cameronrye/activitypub-mcp"><img src="https://img.shields.io/github/stars/cameronrye/activitypub-mcp?style=social" alt="GitHub stars" /></a> </p> <p align="center"> <a href="https://glama.ai/mcp/servers/cameronrye/activitypub-mcp"><img src="https://glama.ai/mcp/servers/cameronrye/activitypub-mcp/badge" alt="Glama quality and maintenance score" width="200" /></a> <a href="https://smithery.ai/servers/rye/activitypub-mcp"><img src="https://smithery.ai/badge/rye/activitypub-mcp" alt="Smithery" /></a> </p>

Install

Requires Node.js 20+.

npx -y activitypub-mcp

One-click install:

Add to Cursor Install in VS Code

Claude Desktop

One-click: download the .mcpb bundle (activitypub-mcp-<version>.mcpb) from the latest release and open it in Claude Desktop.

Manual: edit ~/Library/Application Support/Claude/claude_desktop_config.json (macOS) or %APPDATA%\Claude\claude_desktop_config.json (Windows):

{
  "mcpServers": {
    "activitypub": {
      "command": "npx",
      "args": ["-y", "activitypub-mcp"]
    }
  }
}

Restart Claude Desktop.

Cursor

Edit ~/.cursor/mcp.json:

{
  "mcpServers": {
    "activitypub": {
      "command": "npx",
      "args": ["-y", "activitypub-mcp"]
    }
  }
}

Restart Cursor.


Read-only by default

Out of the box, only read tools are registered: discover actors, fetch timelines, search, get threads, explore instances, read trending content. No write tools exist in the MCP session, so injected fediverse content cannot trigger account actions.

Public read tools (no account needed): discover-actor, fetch-timeline, get-post-thread, get-instance-info, get-public-timeline, get-trending-hashtags, get-trending-posts, search, discover-instances.

Authenticated read tools (account required): list-accounts, switch-account, verify-account, get-home-timeline, get-notifications, get-bookmarks, get-favourites, get-relationship.

Enabling writes

Set ACTIVITYPUB_ENABLE_WRITES=true in the environment or MCP config env block. This registers the full set of mutation tools: post, reply, delete, boost, favourite, bookmark, follow, mute, block, vote, upload media, and scheduled posts. Read the threat model before enabling.

{
  "mcpServers": {
    "activitypub": {
      "command": "npx",
      "args": ["-y", "activitypub-mcp"],
      "env": {
        "ACTIVITYPUB_ENABLE_WRITES": "true"
      }
    }
  }
}

Authentication

Log in with the CLI:

npx activitypub-mcp login mastodon.social

This runs OAuth (Mastodon-family) or MiAuth (Misskey) in your browser and saves credentials to ~/.config/activitypub-mcp/accounts.json. Multi-account is supported — use switch-account to change the active account.

Alternatively, set ACTIVITYPUB_DEFAULT_INSTANCE and ACTIVITYPUB_DEFAULT_TOKEN env vars for a single account without the CLI flow.


Platform support

discover-actor and fetch-timeline speak plain ActivityPub (WebFinger → actor → outbox), so they read any conformant ActivityPub server — Mastodon, Misskey, Foundkey, Pleroma/Akkoma, Lemmy (communities and users), PeerTube (channels and accounts), GoToSocial, and Pixelfed.

The instance-API read tools (search, get-trending-hashtags, get-trending-posts, get-public-timeline) and every write tool require a Mastodon- or Misskey-API instance, since they call those platforms' REST APIs. Login uses OAuth (Mastodon-family) or MiAuth (Misskey).


Example

After adding the server to your MCP client, try:

"Look up @gargron@mastodon.social and summarize their latest posts."

The model will call discover-actor to fetch the profile, then fetch-timeline to read recent posts.

See examples/ for copy-pasteable recipes — Fediverse research digests, scheduled threads, notification triage, image posts with alt text, and topic curation.


HTTP transport

In addition to stdio (default), the server supports HTTP mode with a bearer-gated /mcp endpoint and /health liveness check. Set MCP_HTTP_SECRET (min 16 chars) to enable.

To self-host it as a service, the repo includes a Dockerfile and a docker-compose.yml (HTTP mode):

export MCP_HTTP_SECRET=$(node -e "console.log(require('crypto').randomBytes(32).toString('hex'))")
docker compose up --build   # then: curl http://localhost:8080/health

See the docs for full configuration.


Security

This server fetches world-writable fediverse content — posts, bios, notifications — and feeds it to the LLM. That content can contain prompt-injection payloads. Notifications are an unsolicited channel: anyone can mention your account. The <untrusted-content> envelope and read-only default reduce the risk surface, but do not eliminate it.

See SECURITY.md for the full threat model, SSRF protections, credential handling, and reporting instructions.


Documentation

The full tool reference, resource list, prompt catalog, environment variable guide, and deployment notes live on the docs site:

cameronrye.github.io/activitypub-mcp/docs/


License

MIT — see LICENSE.

Acknowledgments

Built on the Model Context Protocol by Anthropic, and interacts with the decentralized social web as specified by ActivityPub (W3C) and ActivityStreams.

Related MCP servers

Browse Gopher and Gemini protocol resources safely with SSRF protection, TLS/TOFU validation, and structured JSON output.

12
Python
MIT
View repository →

Offline MCP access to ZIM knowledge archives—Wikipedia, Wiktionary, Stack Exchange via Kiwix.

81
Python
MIT
View repository →

Persistent, portable memory for AI coding agents across sessions and machines.

11
JavaScript
MIT
View repository →
REReddit Ads logo

Reddit Ads API v3: campaigns, ad groups, ads, reports, plus working writes with safety tiers.

1
TypeScript
MIT
View repository →

Check the bank behind an IBAN before you pay: bank-code check, BIC with source, bank-level sanctions

0
TypeScript
MIT
View repository →

Swiss customs tariff (TARES), FINMA register, NOGA/NACE/ISIC codes. 3 free tools + search trial.

0
HTML
View repository →