Yes. Claude, ChatGPT, Cursor and Claude Code can schedule social media posts, as long as they are connected to a scheduler that exposes its tools over MCP, the Model Context Protocol. On their own they have no access to your accounts and cannot post anywhere. Connect Preflight's hosted MCP server at https://preflight.social/mcp, sign in once, and the assistant can list your channels, upload files, check a post against each network's rules, schedule it, publish it and read the figures afterwards. What keeps this from being reckless is that publishing is a separate permission, an immediate publish or a delete has to be confirmed by a person, and every post can be checked with validate_post before anything is created.
Facts about Preflight below were checked against its code, and facts about the assistants against their own documentation, on 8 October 2026. Assistants rename their menus often, so where a label has moved, follow the vendor page linked in that section.
What an assistant can do with it
The server has 26 tools. In practice they fall into five jobs:
- Draft. The assistant writes the caption, and
draft_postputs a text draft in your composer for you to finish. That tool cannot publish or schedule. - Check.
validate_postis a dry run ofcreate_postwith the same arguments. It checks every channel, file, time and network limit, the plan's monthly allowance and paused channels, and creates nothing. - Schedule or publish.
create_postmakes a real post on any mix of networks: at a time, into the queue, or now. Files go throughcreate_media_upload,complete_media_uploadandget_media; the bytes never pass through the assistant. - Manage.
list_posts,get_post,update_post,delete_postandretry_postcover the queue, including the channels where a post failed and why. - Learn.
post_performance,post_insights,analytics_summary,audienceandlist_commentsread figures and comments, andact_on_commentcan reply to them.
A short session looks like this. You type:
Schedule this Friday's launch video to YouTube, TikTok and Bluesky at 9am Prague time. Caption: "The new composer is live." Check it first and ask me before anything goes out.
The assistant calls list_channels to find the channel ids, create_media_upload for the video, and get_media until the file is ready. For TikTok it calls tiktok_creator_info to see which privacy levels the account allows and asks you to pick one. It then runs validate_post and reports what it found: for example that the Bluesky text is fine but TikTok has no privacy level yet. When the check is clean it calls create_post with the time and a fresh idempotencyKey. A week later you ask "how did it do?" and it calls post_performance for each network.
Connect it
You need a Preflight workspace on a plan with the MCP server (see "Plans and cost" at the end) and the address https://preflight.social/mcp. Preflight supports OAuth 2.1 with PKCE and dynamic client registration, so a client that supports remote OAuth servers needs only the URL; you sign in to Preflight and approve the scopes on a consent screen. Clients with a headers field can send an API key from Settings, API keys instead.
Claude
On Free, Pro and Max, Anthropic's custom connector guide has you open Customize, Connectors, then "+ Add" and "Add custom connector". Enter a name and the URL, continue, choose how to sign in, and click Add. To use it, press the "+" in a chat, choose Connectors and switch it on for that conversation. On Team and Enterprise an owner adds the connector first under Organization settings, Connectors; members then click Connect on it themselves. Free accounts are limited to one custom connector.
Claude Code
In a terminal, following the Claude Code MCP documentation:
claude mcp add --transport http preflight https://preflight.social/mcp
Then run /mcp inside Claude Code and follow the browser sign-in. To use an API key instead of OAuth, add --header "Authorization: Bearer sk_live_...". Claude Code then uses that header and does not fall back to OAuth. claude mcp list shows whether the server is connected.
ChatGPT
OpenAI's page on connecting a remote MCP server says to open ChatGPT Plugins, press the plus button, choose "Add custom MCP server", give it a name and description, choose a public endpoint, and enter the URL including its /mcp path. The server must be public HTTPS with streamable HTTP, which Preflight's is. After you review the risk warning and create it, you start a new conversation, type @ and select it. Which plans may add custom servers, whether developer mode must be on, and whether write actions are allowed depend on your plan and workspace role, and OpenAI has moved those labels more than once. We could not open OpenAI's help article on developer mode, so check your own settings, and treat read-only access as the safe assumption until you have seen a write tool run.
Cursor
Cursor's MCP documentation puts the config in .cursor/mcp.json for one project or ~/.cursor/mcp.json for every project. A remote server takes a url and optional headers, so with an API key the entry is "preflight": { "url": "https://preflight.social/mcp", "headers": { "Authorization": "Bearer ${env:PREFLIGHT_KEY}" } } inside mcpServers. Cursor's documented OAuth setup asks for a client id, which Preflight does not require, so the key route is the one we can vouch for. Details for other clients are on the MCP docs page.
What the assistant is allowed to do
Every connection carries scopes, and the server shows an assistant only the tools its scopes allow. The OAuth consent screen puts each one in a plain sentence before you approve.
| Scope | What it lets the assistant do |
|---|---|
posts:read | Read channels, posts, comments, figures and plan usage; run validate_post |
posts:write | Write drafts, edit or delete posts that have not gone out |
posts:publish | Anything that goes live: schedule, publish now, retry, edit or delete a live post, reply to a comment |
media:read, media:write | See and upload files |
Publishing is its own scope, not an extension of write. A connection without posts:publish can still draft, and the consent screen then says it "can write drafts and upload files, but nothing it does goes out without you." If you only want an assistant to analyse results, grant read alone.
Three further rules sit in the tools themselves:
- Confirmation.
create_postrefuses to publish immediately unlessconfirmPublishNowis true, and the refusal tells the assistant to confirm with you first. Deleting a post, taking one down from a network, or deleting a comment needsconfirmDelete. - Idempotency.
create_postrequires anidempotencyKey. If a call times out and the assistant retries with the same key, the first post is returned instead of a second one being published. - Past times. A scheduled time that has already passed is refused rather than published at once.
The tool descriptions ask the assistant to confirm before it calls anything marked destructive, but that is guidance to a model, not a lock. The enforced parts are the scope, the confirmation flags and the key. You can revoke a connection at any time in Settings, which also ends every other token that client holds.
Why the check matters when an agent posts
A person who tries to publish a bad post sees the error on screen. An agent working through twenty posts in one turn may not stop at the sixth. The check has to live where the post is created, not in the assistant's good intentions. validate_post and create_post run the same rules as the web composer and the REST API, so an assistant cannot skip a rule by calling a different door. Some examples of what comes back:
- A Bluesky post of 301 graphemes is refused; the limit is 300 graphemes (and 3,000 bytes), counted the way Bluesky counts them. See the Bluesky limits.
- A TikTok post is not accepted until a privacy level has been chosen, because a tool that leaves it unset posts as only-me and the video is invisible.
tiktok_creator_infolists the levels the account may use. See the TikTok limits. - A Pinterest pin needs a board;
list_pinterest_boardsprovides the ids. - Video length, size, frame rate and format are checked against the network's rules before the upload is sent anywhere.
Settings a network does not take come back as warnings rather than being silently dropped, and a refusal because of the plan's allowance carries the limit. The full rule set is on the post limits page.
Client approval
If a client must approve posts, an approval rule applies to assistants too. A post whose approval is pending, or where changes were asked for, does not publish at its time, whoever created it. If an assistant edits a post the client had already approved, the approval is withdrawn and the post waits for a new one; update_post has a keepApproval option for a typo fix, which the assistant should use only when you have said the change is small. What an assistant cannot do is send the approval link: there is no MCP tool for it, so you ask for approval in the app. A sensible split is that the assistant drafts and validates, and a person sends the link.
What it cannot do
- X is not switched on. Preflight has an X adapter for text only, and it is not offered to new accounts, so an assistant cannot post there. Media upload to X is not built.
- LinkedIn Company Pages. Posting is to personal profiles only. Pages need an app review from LinkedIn that Preflight has not passed; see the LinkedIn page.
- It cannot see what you have not connected. Every tool works on the channels already connected to the workspace; an assistant cannot connect a network or reconnect an expired one.
list_channelssays which need reconnecting. - Not every action is a tool. There are no tools for approval links, account presets, channel posting schedules or billing.
next_queue_timesreads the schedule but cannot change it. - It is bound by the plan. The monthly publish allowance, the channel cap and paused channels apply to an assistant exactly as to you, and
get_usagereports what is left. - It does what networks allow. Taking a post down or editing a live one works only where the network permits it, and some networks do not.
- It is not a guarantee of reach. The check catches posts the network would refuse. It cannot tell you whether the post is any good, and the assistant's copy still needs your eye.
A few prompts that work
Show me which channels are connected, which need reconnecting, and when each one's queue slot next opens.
Draft three captions for this video, one per network, and save them as drafts. Do not schedule anything.
Run validate_post on tomorrow's post for all channels and tell me what is wrong before you create it.
Schedule it for the next queue slot on Bluesky and Mastodon. If a check fails, stop and tell me; do not change the text without asking.
Which of last month's posts did best on each network, by views and comments, and which three comments need a reply? Do not reply to any.
Plans and cost
The MCP server comes with the Pro and Studio plans; Free and Starter have no API keys, webhooks or MCP. The assistant is whatever Claude or ChatGPT subscription you already use, which is a separate cost, and posts made through it count against the workspace's monthly allowance like any other. The plans are on the pricing page. The REST API behind these tools is documented at /documentation, and the tool-by-tool reference is on the MCP docs page.
Questions people ask
- Can ChatGPT schedule social media posts?
- Not by itself, because it has no access to your accounts. Connected to a scheduler's MCP server it can. With Preflight you add https://preflight.social/mcp as a custom MCP server in ChatGPT and sign in; the assistant can then validate, schedule and publish posts through its tools. Which ChatGPT plans may add a custom server, and whether write actions are allowed, is set by OpenAI and your workspace, so check that before relying on it.
- Can Claude post to Instagram and TikTok?
- Yes, through the connector, if the channels are connected in Preflight. The assistant uploads the file, checks it with validate_post and creates the post. For TikTok a privacy level must be chosen before the post is accepted; Instagram has its own account and media rules, which validate_post checks. It cannot connect the accounts for you.
- Is it safe to let an AI agent publish?
- It is safe to the extent that you limit it. Publishing is a separate scope you can leave out, publishing at once needs an explicit confirmation, a retried call cannot publish twice, and every post can be checked against each network's rules first. Posts waiting for client approval do not go out. The remaining risk is the wording the assistant writes, so review captions before they are scheduled.
- What does the MCP server cost?
- Nothing extra: it is included in the Pro and Studio plans of Preflight. You still pay for the assistant you use it with, such as a Claude or ChatGPT subscription, and posts count against the plan's monthly allowance as usual.
- Which plans include MCP?
- Pro and Studio. The Free and Starter plans do not include API keys, webhooks or the MCP server. A key issued on Pro or Studio keeps working if the workspace later moves down a plan.