This Model Context Protocol (MCP) server provides a lightweight, read-only-by-default interface for LLMs to explore and interact with the Fediverse. It targets ActivityPub-compatible services, including Mastodon, Misskey, Pleroma, and other compatible servers, with write tools available only when explicitly opted in.
🛠️ Key Features
MCP server for the Fediverse via ActivityPub
Read-only by default; write tools are opt-in
Supports exploration and interaction with existing Fediverse servers
🚀 Use Cases
Querying or browsing ActivityPub-based services from an LLM
Working with Mastodon, Misskey, Pleroma, and compatible servers
⚡ Developer Benefits
MCP integration for LLMs to interact with Fediverse resources
Clear default safety posture (read-only unless opt-in for writes)
Topics include activitypub, fediverse, and mcp-server
⚠️ Limitations
Write capability is not enabled by default; write tools require opt-in
Scope is limited to ActivityPub/Fediverse-compatible servers
A lightweight Model Context Protocol (MCP) server that lets an LLM explore and interact with the existing Fediverse — Mastodon, Misskey, Foundkey, Pleroma, and compatible servers. Read-only by default; write tools are opt-in.
Out of the box, only read tools are registered: discover actors, fetch timelines, search, get threads, explore instances, read trending content. No write tools exist in the MCP session, so injected fediverse content cannot trigger account actions.
Public read tools (no account needed): discover-actor, fetch-timeline, get-post-thread, get-instance-info, get-public-timeline, get-trending-hashtags, get-trending-posts, search, discover-instances.
Set ACTIVITYPUB_ENABLE_WRITES=true in the environment or MCP config env block. This registers the full set of mutation tools: post, reply, delete, boost, favourite, bookmark, follow, mute, block, vote, upload media, and scheduled posts. Read the threat model before enabling.
This runs OAuth (Mastodon-family) or MiAuth (Misskey) in your browser and saves credentials to ~/.config/activitypub-mcp/accounts.json. Multi-account is supported — use switch-account to change the active account.
Alternatively, set ACTIVITYPUB_DEFAULT_INSTANCE and ACTIVITYPUB_DEFAULT_TOKEN env vars for a single account without the CLI flow.
Platform support
discover-actor and fetch-timeline speak plain ActivityPub (WebFinger → actor → outbox), so they read any conformant ActivityPub server — Mastodon, Misskey, Foundkey, Pleroma/Akkoma, Lemmy (communities and users), PeerTube (channels and accounts), GoToSocial, and Pixelfed.
The instance-API read tools (search, get-trending-hashtags, get-trending-posts, get-public-timeline) and every write tool require a Mastodon- or Misskey-API instance, since they call those platforms' REST APIs. Login uses OAuth (Mastodon-family) or MiAuth (Misskey).
The model will call discover-actor to fetch the profile, then fetch-timeline to read recent posts.
See examples/ for copy-pasteable recipes — Fediverse research digests, scheduled threads, notification triage, image posts with alt text, and topic curation.
HTTP transport
In addition to stdio (default), the server supports HTTP mode with a bearer-gated /mcp endpoint and /health liveness check. Set MCP_HTTP_SECRET (min 16 chars) to enable.
To self-host it as a service, the repo includes a Dockerfile and a docker-compose.yml (HTTP mode):
This server fetches world-writable fediverse content — posts, bios, notifications — and feeds it to the LLM. That content can contain prompt-injection payloads. Notifications are an unsolicited channel: anyone can mention your account. The <untrusted-content> envelope and read-only default reduce the risk surface, but do not eliminate it.
See SECURITY.md for the full threat model, SSRF protections, credential handling, and reporting instructions.
Documentation
The full tool reference, resource list, prompt catalog, environment variable guide, and deployment notes live on the docs site: