Before using the Mallary MCP Server:
- Sign up at https://mallary.ai
- Connect your social media accounts in the Mallary dashboard
- Approve the access requested by your app, or get a Mallary API key for a manual setup
OAuth
OAuth-ready clients discover Mallary’s authorization server automatically from:https://mallary.ai/oauth-connections.
Keep an App Connected
The app that runs the MCP client must renew its OAuth access tokens. Mallary cannot renew a token stored inside another app on that app’s behalf. Read the current endpoints from this discovery document. Do not guess paths such as/authorize.
S256:
https://mallary.ai/mcp as the OAuth resource for the standard MCP endpoint. Request only the scopes the integration needs. Uploading, publishing, scheduling, and reading results need mallary.publish and mallary.read.
Mallary issues refresh tokens to public PKCE clients registered for the refresh grant, even without offline_access. A registration that allows only authorization_code will not receive this capability. A client with a shared secret must also request offline_access to receive a refresh token.
The connector host must:
- Keep tokens and expiry details in its secure credential store. Never put them in prompts or logs.
- Use the returned
expires_invalue to renew shortly before expiry. - Allow only one refresh at a time for each connection. Other requests must wait for that refresh.
- Send
grant_type=refresh_tokento the discovered token endpoint with the registered client authentication and resource. - Save the new access token, rotated refresh token, and expiry together before resuming requests. Do not reuse the old refresh token.
- On
invalid_grant, stop and ask the user to reconnect. Do not keep retrying a revoked or expired grant.
OAuth Scope Reference
These scopes remain part of the OAuth protocol for client compatibility. They are not choices shown by the Mallary CLI.mallary.read: read posts, comments, analytics, profiles, platforms, settings, and webhooksmallary.publish: upload media and create or schedule postsmallary.engage: reply to commentsmallary.manage: change settings, profiles, webhooks, connections, and pending posts

