ZhuoQi Devzhuoqidev.com← Back to deskRSSllms.txt
~/posts/social-publishing-inbox-apis-2026.md
Deep Dives~3,800 words · 17 min read

Letting an Agent Run a Dozen Overseas Social Accounts — About 60 Posting, Comment and DM APIs and MCP Servers Compared Cell by Cell (October 2026)

TL;DR

Ranked by integration completeness, Zernio leads the developer-facing unified APIs with 35.3 points out of 38, with SocialAPI.ai and Ayrshare at about 29 each. Among the established social media suites, only Vista Social and Eclincher can post, read the inbox and reply through a single MCP server. The only way to get more, such as LinkedIn personal DMs, is a session-based API that asks for your cookies, which is exactly what the platforms forbid in writing. First check what the platform gives you, then compare how much of it each tool carries.

Contents
  1. The short version
  2. Who this is for
  3. The minimal causal chain: tools are only carriers
  4. 1. What the platforms give you: check the ceiling first
  5. 2. How I scored
  6. 3. Developer-facing unified APIs (19 vendors)
  7. 4. Established social media suites (23 vendors)
  8. 5. Open source, self-hosted, and new vendors in MCP directories
  9. 6. Session-based APIs: the extra capability is exactly the forbidden part
  10. 7. One comment end to end (Zernio as the example)
  11. 8. Will it get you banned?
  12. 9. How the pricing works (second priority)
  13. 10. Which kind to pick when
  14. Facts, inference and what isn’t verified
  15. Sources (checked 2026-10-09)

Version scope: every product capability, price and platform rule was checked on 2026-10-09 against official documentation, pricing pages and API references. Prices are list prices in US dollars, without discounts or promotions. GitHub stars, last commits and licences were queried with gh api the same day. This field moves fast: X changed its API rules twice in 2026, Reddit’s public API closes in March 2027, and several of the MCP servers only appeared in September.


The short version

  1. The platform decides what is possible. Since 2026-02-23 X only lets a program reply to someone who mentioned or quoted you, and AI-generated replies posted automatically need X’s approval first. A LinkedIn personal profile can post, but its comments and DMs are open only to legal entities and partners. A Facebook personal profile cannot post through the API. Instagram needs a professional account. Threads and YouTube have no DM API at all. No tool gets around any of this.
  2. Developer-facing unified APIs (19 vendors): Zernio is first with 35.3. Without your own X developer key it reads and answers replies under your X posts and X DMs, connects all 17 accounts in the example, exposes comment and DM tools in its MCP server, and pushes new messages by webhook. Ayrshare (29.3) covers almost as much, but needs your own X key, needs a separate profile for each extra account on the same platform, and costs four times as much. SocialAPI.ai (29.5) is cheap, but posts only plain text to X and has no Reddit. OmniSocials (23.8) is the cheapest thanks to per-workspace pricing, but cannot read replies under your X posts.
  3. Established social media suites (23 vendors): only Vista Social (about $217–257 a month for the example accounts) and Eclincher ($134–149 a month, no Bluesky, some features unverified) can post, read the inbox and reply through MCP. Agorapulse’s MCP server can only save drafts. Hootsuite’s can only save drafts and read, and while it is switched on it blocks X, LinkedIn, Reddit and YouTube data. Metricool’s REST API can answer comments and DMs, but its MCP server cannot.
  4. Open source, self-hosted: none is complete. Postiz is the most popular but has no inbox. BrightBean Studio has the most complete inbox tools but no X. OpenPost handles X comments and DMs but is seven months old.
  5. Session-based APIs (they take your password or cookies) add only things the platforms forbid in writing: LinkedIn personal DMs, a way around X’s reply limit, a way around Instagram’s 24-hour DM window.
  6. Whatever you pick, test one X reply on a real account first. X’s documentation doesn’t say whether a reply under your own post counts as “mentioning you”, and that limit applies to every vendor.

Who this is for

Engineers who already use an Agent (Claude Code, Cursor or their own) and want it to take over social posting and replies too. You don’t need to know any platform’s API beforehand; you should know roughly what MCP is (the protocol an Agent uses to call external tools).

Seven terms first:

TermMeaning in this article
Official APIThe interface a platform publishes for developers; the platform decides what it can do and what it costs
Authorization token (OAuth token)The key a third-party service receives after you click “Allow” on the platform’s consent page. It can only do what you approved, and you can revoke it any time in the platform’s settings
Unified APIA service that wraps a dozen platforms’ official APIs into one interface, so you integrate with it alone
InboxComments, mentions and DMs: the three kinds of messages where someone reaches out to you
Session-based APIA service that logs in as you with your password or browser cookies, bypassing the official API
SummonedX’s rule: a program may reply to a post only if its author mentioned or quoted you
P / C / M / DTable shorthand: post / read and answer comments / read and answer mentions / read and send DMs

The minimal causal chain: tools are only carriers

Whichever tool you use, a call travels this chain:

Your Agent Claude Code etc. · MCP tool or REST API · Unified service holds the token you authorized · Platform's official API the platform decides what it can do · Your account · Session-based service holds your password or cookies · You browser or phone app · logs in as you, forbidden by platform terms · login session

Schematic: it shows call paths, not any vendor’s internals. Solid lines are the official route; dashed lines are the route session-based APIs take.

Three consequences follow, and the rest of the article rests on them:

  1. A unified service can never do more than the platform’s official API allows. Tools compete on how much of the official capability they carry, and how reliably.
  2. Anything beyond the official API means taking the dashed route, handing over your password or cookies. That route does unlock more, but platform terms forbid it in writing.
  3. A service calling the official API is not you logging in. In a platform’s security settings, “connected apps” and “devices / sessions” are two separate lists. A unified service calls the API from its own servers; that does not count as you logging in from another IP.

1. What the platforms give you: check the ceiling first

PlatformPost (P)Read and answer comments (C)DMs (D)Requirements / catches
XYesRead yes; reply only to people who mentioned or quoted youYes; DMs moved to encrypted X Chat can’t be read by the APIPay per use, no free tier; automatic AI replies need X’s prior approval
YouTubeVideos onlyYes; each reply costs 50 quota units, 10,000 units a day by defaultThe platform has no DMsWhether uploads from unaudited projects are locked to private: two official pages disagree
InstagramYesYesYes, but the other person must write first and you must answer within 24 hoursNeeds a creator or business account (free to switch)
ThreadsYesYesThe platform API has none—
FacebookPages onlyPages yesPages yesPersonal profiles never
LinkedIn personal profileYesCannot read: the permission to read comments is for “select developers” onlyNo: the Messages API is partners onlyCompany Pages can read comments
TikTokAn app you register yourself won’t pass the audit, and an unaudited app can only post privately; you need an already-audited serviceBusiness accountsBusiness accounts; not in the EU, UK or SwitzerlandThe audit rules explicitly reject “tools that upload for your own or your team’s accounts”
RedditYesYesYesNew API applications close on 2026-10-31; the public Data API shuts down in March 2027
Bluesky / MastodonYesYesYesFree, no review; on Bluesky, reply only to people who mention you first

X is the only platform here that charges per call (official pricing page, 2026-10-09):

OperationUnit price
Create a post$0.015
Create a post containing a link$0.20
Read a post$0.005
Read your own data (such as your own mentions)$0.001
Read a DM / send a DM$0.010 / $0.015

Saving your first card gives $20 of credit, and reads are capped at 3 million posts a month. For 30 posts a month (10 with a link), 500 replies read and 50 answered, the X part comes to about $3–6, mostly from the link posts.


2. How I scored

To compare like with like I fixed an example setup: one person with a personal and a brand account on each of 9 platforms, 17 accounts in total (two each on X, YouTube, Instagram, Threads, TikTok, Bluesky and Reddit; a personal profile plus a Company Page on LinkedIn; only the brand Page on Facebook, because personal profiles can’t be connected).

ItemMaxHow it’s scored
Posting coverage10Accounts it can connect and post to / 17 × 10; text-only X counts as half an account
Read and answer replies under your X posts4Weighted separately; X engagement depends on it most
X DMs2
Comments on the other 8 platforms81 point per platform
Other DMs51 point each for Instagram, Facebook, TikTok, Bluesky, Reddit
Mentions30.5 for each of 6 platforms
MCP3Dedicated tools for comments and DMs 3; comments only 2; one generic execute tool 1
Webhooks for new messages2New comments and new DMs 2; one kind only 1
Several accounts per platform together1No point if extra workspaces are needed

Features limited to posts published through the tool, read-only, beta, or with self-contradicting docs get half a point. These weights are mine; cutting “replies under your X posts” from 4 points to 1 leaves the top three unchanged.


3. Developer-facing unified APIs (19 vendors)

RankProductScoreReplies under your X postsX DMsAccounts (/17)MCP has comment + DM toolsMonthly price for 17 accounts (second sort key)
1Zernio (formerly Late)35.3Yes, including posts not made through itYes17Yes$69 + X passed through at official rates
2SocialAPI.ai29.5Yes (your own X key)Yes15 (X text only)Yes$29 + your own X costs
3Ayrshare29.3Yes (your own X key)Yes17Yes (no mentions)$299 ($249 yearly) + $0.09 per DM conversation
4OmniSocials23.8NoYes15 (no Reddit)YesTwo workspaces, $20–24
4Aidelly23.8Docs contradictPartly15Yes$29–39
6Postproxy23.3NoNo15Yes$49
7RelayAPI22.0Docs unclearDocs unclear17Generic execute tool onlyFrom $5
8Outstand21.0Only posts made through itNo17Comments only$19 + your own X key
9Upload-Post20.8Docs conflictNo15 (Reddit posting returns 503)Yes$16–24
10bundle.social19.0Docs contradict themselvesNo17Comments only$90–100

Ranks 11–19 are UniPost, Mallary, Postqued, PostFast, Blotato, Post for Me, Post Bridge, Unipile and Typefully: they either only post, or only see comments on posts published through them.

The leaders platform by platform (P post, C comments, M mentions, D DMs; ½ partial, ? docs unclear):

ProductXLinkedIn personalLinkedIn PageYouTubeInstagramFacebook PageThreadsTikTokBlueskyReddit
ZernioP C D M½PP C M½P CP C D M½P C DP CP C D½P C DP C D
SocialAPI.aiP½ C D M½PP C½P CP C D M½P C D MP C M½PP C D M—
AyrshareP C D M½P C?P CP C½P C D M½P C DP C?P CP C½P C¼
OmniSocialsP DPP C MP CP C D MP C D MP C MP CP—
PostproxyPPPP CP C DP C DP CP CP C½ D—

Easy things to miss:

  • “Your own X key” is a different way of paying. Zernio and bundle.social use their own X app and pass X’s price through. Ayrshare (mandatory since 2026-03-31), SocialAPI.ai and Outstand make you create an app in X’s developer console, add a card and pay X yourself. With your own key, reading your own mentions costs $0.001; Zernio passes reads through at $0.005 each.
  • OmniSocials prices differently: $10–12 a month per workspace with unlimited accounts, but only one account per platform per workspace; it pays for X posts without links itself. Its inbox documentation says outright that comments and mentions on X are not part of the inbox.
  • Newer vendors often contradict their own docs: Aidelly, bundle.social and Upload-Post all have features that the marketing page lists and the API docs do not. RelayAPI’s documented MCP install command installs an unrelated maintainer’s npm package of the same name, a supply-chain risk. SocialAPI.ai is a one-engineer personal company with no public changelog.
  • Zernio has catches too: the X inbox must be switched on by hand; the X comment list returns only the first page, reply threads are cached for 2 minutes, and the comment list can lag by up to 10 minutes; Threads has no new-comment webhook; TikTok DMs can be answered but not started.

4. Established social media suites (23 vendors)

These have mature web inboxes. The question is whether a program can drive the inbox:

ProductHow Claude Code connectsPostingComments read / replyDMs read / replyMonthly for the 17 accounts (monthly / yearly)
Vista SocialOfficial MCPPublishes directlyYes / yesYes / to be confirmed (the reply endpoint says “public reply”)$257 / $217
EclincherOfficial MCPPublishes directlyYes / yesYes / yes (X DMs unverified)$149 / $134 (no Bluesky)
AgorapulseOfficial MCP (beta)Drafts onlyYes / yesYes / yes$282 / $247 (X needs a $69 add-on per account)
MetricoolPosting via MCP, inbox via RESTYesREST yes (replies under X posts are not in the inbox)REST yes (X DMs included)$87 / $73
StatusbrewMCPDrafts onlyRead onlyRead only$429 / $359
HootsuiteMCP + RESTREST publishes, MCP saves draftsMCP read-only, and it blocks X, LinkedIn, YouTube and RedditSameFrom $199 (per seat, yearly)
Sprout SocialREST (enabled by sales); MCP for ChatGPT onlyDrafts onlyAPI read-onlyAPI read-onlyAbout $399
SocialPilotOfficial MCPPublishes directlyNoNo$50 / $42.5 (cheapest posting-only option)
Buffer / Publer / Zoho SocialMCP or RESTYesNo (web only)No$59–98

Later, Loomly, SocialBee and Sendible have neither a public API nor MCP and are out. Brandwatch, Khoros, Emplifi, Sociality.io and NapoleonCat need an enterprise contract for API access.


5. Open source, self-hosted, and new vendors in MCP directories

ProjectState (2026-10-09)InboxInbox tools in MCPCatch
Postiz36,914★, AGPL-3.0, latest v2.25.0None; its MCP docs say it cannot read or answer commentsNone18 security advisories in 2026, several critical and exploitable without authentication
Mixpost ProClosed source, $299 one-offYes (comments and mentions on FB, IG, Threads, X)None; replies only in the web app—
BrightBean Studio2,421★, AGPL-3.0, free hosted versionYes: comments, mentions, DMsMost complete: list, draft and send are separate permissionsNo X
OpenPost659★, created March 2026Yes, including X comments and DMsComments only; DMs only in the HTTP APIIts hosted version says it “hasn’t finished final live checks”
Chatwoot37,646★DMs only; the X channel isn’t merged yetCommunity servers onlyDoesn’t post

In the official MCP Registry, Smithery, Glama and Anthropic’s connector directory I also found a few vendors with inbox tools that appeared around September: Ignix (174 tools, about $121 a month for the 17 example accounts; its help page and landing page disagree on which platforms have DMs), PostLake (the cleanest inbox API, but X, Instagram, Facebook and Threads aren’t open to the public yet), Pinlyx (DMs only) and SocialClaw (Instagram only). None covers as much as the leaders in section 3.


6. Session-based APIs: the extra capability is exactly the forbidden part

Unipile, Linked API, Beeper, twitterapi.io and similar services ask you to log in to your account on their page or hand over your browser cookies. They add only four things over the official route:

Extra capabilityWhat the platform says
LinkedIn personal DMs and personal-post commentsUser Agreement 8.2 prohibits “bots or other unauthorized automated methods”
Instagram DMs without the “they write first, 24 hours” limitThe Terms of Use prohibit unauthorized automated access
X replies without the “summoned” limit, at about 1/10 of the official priceAutomation rules: non-API automation may lead to permanent suspension

Unipile’s own documentation admits some endpoints are non-public and that account restrictions are an “expected failure”; Beeper’s warns that sending too many messages can get accounts suspended. If the account matters to you, stay away from this category.


7. One comment end to end (Zernio as the example)

Take the top-ranked Zernio and follow what happens between someone replying under your X post and your reply going out.

Someone replies under your X post · 1. The unified service pulls comments from X the X inbox must be switched on; each read is billed at X's $0.005 · 2. The Agent lists comments through MCP first posts with comments, then one post's comments · 3. The Agent drafts a reply · 4. You approve before it goes out · 5. Call the reply tool X charges one post, $0.015 · 6. X checks whether you were summoned if not, it refuses; to be tested · edit · send

Schematic: the steps come from Zernio’s documentation and X’s pricing page. Step 4 is my addition, a human approval that satisfies X’s rule that automatic AI replies need prior approval. Only the existence of the tools in step 2 has been tested.

The tested part (2026-10-09, free): I created an API key in the Zernio dashboard and connected the MCP server to Claude Code with one command:

bash
claude mcp add --transport http -s user zernio https://mcp.zernio.com/mcp --header "Authorization: Bearer <your Zernio API key>"

claude mcp list showed it connected, but the tools did not appear in the current session; they only show up in a new one. Rather than wait for a new session, I spoke MCP directly: first initialize, then list the tools:

http
POST https://mcp.zernio.com/mcp
Authorization: Bearer <your Zernio API key>
Content-Type: application/json
Accept: application/json, text/event-stream

{"jsonrpc":"2.0","id":2,"method":"tools/list"}

What came back (a summary, not the raw response):

ObservationDetail
52 tools listed directly13 posting tools (posts_create, posts_cross_post, posts_publish_now and others), plus accounts, scheduling and analytics
Comment tools are in the listcomments_list_inbox_comments, comments_get_inbox_post_comments, comments_reply_to_inbox_post
Mention tools are in the list, but narrowmentions_list_inbox_mentions currently returns LinkedIn Company Pages only; mentions_reply_to_mention supports Instagram only
DM tools are not in the listYou first call search_tools, then call_tool; the search finds messages_list_inbox_conversations, messages_send_inbox_message and messages_create_inbox_conversation

The documentation doesn’t mention that last point: an Agent that only reads the tool list will conclude Zernio has no DM support.

The same flow carries over to other services, because an inbox has these four steps and only the names differ:

StepZernioOmniSocialsAyrshare
List what’s pendingcomments_list_inbox_commentsget_next_unanswered (hands you the next unanswered item)get_comments
Read the contextcomments_get_inbox_post_commentsget_inbox_conversation (includes the original post)get_comments
Replycomments_reply_to_inbox_post (supports an idempotency key, so a retry never posts twice)reply_to_inboxreply_comment
Send a DMmessages_send_inbox_messagereply_to_inboxsend_message

If you build it yourself, keep three things: record what you have handled (polling will fetch the same comment twice); send replies with an idempotency key; keep a human approval step before anything goes out.


8. Will it get you banned?

  • A unified service calling the official API is not you logging in from elsewhere. Ban risk comes from behaviour, not from the tool. X forbids several accounts posting the same or very similar content (translations into another language are allowed), automatic replies to people who didn’t mention you, automatic likes and bulk following. LinkedIn rejects duplicate posts outright, and Meta treats repeated content as a spam signal.
  • Multiple IPs affect your own logins. Logging in through proxy exits that keep changing country makes X ask for verification or lock the account temporarily, Facebook and Instagram show security checks, and LinkedIn restricts the account temporarily. The platforms don’t publish the details; this comes from third-party sources. Sticking to one exit and turning on two-factor authentication avoids most of the trouble.
  • One person, several accounts, has limits: X allows up to 10 accounts per person, each with a distinct purpose, and a violation may mean keeping one and losing the rest. LinkedIn’s User Agreement allows one account per person, so the brand needs a Company Page. Facebook also allows one personal account; the brand uses a Page.
  • When you drop a service, revoke its access in the platform’s connected-apps settings. One user reported that disconnecting inside a service did not actually revoke its access.

9. How the pricing works (second priority)

Pricing modelExampleFor the 17 accounts
Graduated per connected accountZernio: first 2 free, accounts 3–10 at $6 each, 11–100 at $3$69
Per workspace, unlimited accounts, one per platformOmniSocials: $10–12 per workspaceTwo workspaces (personal, brand): $20–24
Per profile tierAyrshare: Launch$249–299
Per plan or per seatVista Social, Hootsuite, Sprout$200–400

Almost every vendor charges for X separately: passed through at X’s price, paid by you with your own key, or converted into credits. SocialPilot and Upload-Post include it in the plan; the cost at Upload-Post is that links are stripped from posts by default.


10. Which kind to pick when

What matters most to you? · Reading and answering replies under your X posts → Zernio; or SocialAPI.ai, Ayrshare (your own X key) test the summoned rule on a real account first · A web inbox, team workflow, an established vendor → Vista Social (expensive), Eclincher Agorapulse's MCP only saves drafts · Many accounts, mostly IG, Threads, YouTube, LinkedIn Pages X only for posting → OmniSocials (per-workspace pricing) · Posting only, no replies → SocialPilot, Buffer, Post for Me · Full control in your own hands → open source: BrightBean (no X), OpenPost (very new) · Programmatic LinkedIn personal DMs are a must → no compliant option; handle them by hand

Schematic: compiled from the documentation of 2026-10-09, not a tested ranking.


Facts, inference and what isn’t verified

  • Tested: Zernio’s read-only REST endpoints return 200; after the MCP handshake it lists 52 tools, and the DM tools have to be found through search_tools; after connecting it to Claude Code the tools appear only in a new session.
  • Official documentation: each platform’s limits, X’s prices and “summoned” rule, every vendor’s prices, the MCP tool names.
  • My inference: Vista Social and Metricool may read LinkedIn personal comments through partner permissions; the scoring weights.
  • Not verified, to be tested:
    • whether a reply under your own post counts as “summoned”;
    • whether Vista Social can answer DMs;
    • Eclincher’s X DMs;
    • Ignix’s and Aidelly’s contradictory docs;
    • whether YouTube uploads from unaudited projects are locked to private.

The platform sets the ceiling; tools compete on how much of it they carry. The extra bit a session-based API offers is exactly the part the platform won’t let you use.


Sources (checked 2026-10-09)

Say hi on WeChat

Liu ZhuoQi's WeChat QR code

Scan it in WeChat, or long-press it on your phone

Mention why you're reaching out, or I might miss it.

Scroll or pinch to zoom · drag to pan · double-click to toggle