mcp.json
What it is
One endpoint, no session
Streamable HTTP at
https://mcp.nylon.dev. Every call carries its own key and nothing is stored between them, so there is no session to open, keep alive or recover.Your API key
The same
nylon_live_ key the REST API takes. No OAuth grant against your Nylon login, no second credential to rotate.Fourteen tools
Publishing, scheduling, profiles, connections, network capabilities and validation. Every tool is one endpoint.
The same contract
Each tool calls the endpoint that implements it. Same validation, same rate limits, same error codes, same line in your request log.
Why it is a thin surface
The tools are not a second implementation of Nylon for agents.create_post is POST /v1/posts — the tool takes the endpoint’s own request schema, hands it to the endpoint’s own handler, and returns the endpoint’s own response.
That has a consequence worth relying on: anything an agent can do, your backend can do, with identical semantics. An agent that schedules a post and a nightly job in your own code that schedules the same post produce the same row, the same targets and the same errors. When you move a workflow from a conversation into your own code, nothing about it changes except who is calling.
It also means the reference for what a tool accepts is the reference for the endpoint. Publishing explains how a post is normalised per network; the API reference documents every field.
What is not exposed
Inbox
Live on Facebook and Instagram in the product, with no endpoints yet — and so no tools yet.
Analytics
In build. Nothing in the API or the MCP server returns analytics data today.
Next
Connect a client
Claude, Cursor, VS Code, ChatGPT, or raw JSON-RPC.
Tools
All fourteen, with their arguments and what they return.
Scope and safety
What a key reaches, what an agent cannot do, and how failures come back.