overOne for AI agents

Give an AI agent the same hands you have in overOne: read your brand, feed, inbox and analytics, write captions in your voice, and publish or schedule to your connected accounts. Two ways in — an MCP server for Claude, ChatGPT and other agents, and a REST API for your own code. Both run the same 18 actions with the same permissions and plan limits as the app.

MCP server

https://overone.app/mcp

REST base URL

https://overone.app/v1

Connect Claude or ChatGPT

Claude and ChatGPT connect with OAuth: you add overOne once, sign in, and choose what the assistant may do. There is no key to copy.

Claude (claude.ai, Desktop, mobile)

  1. Open Settings → Connectors and choose Add custom connector.
  2. Name it overOne and paste https://overone.app/mcp. Leave the advanced OAuth fields empty.
  3. Select Connect. You're sent to overOne — sign in, pick the workspace and what Claude may do, then Allow.
  4. In a chat, enable overOne from the tools menu and ask, for example: “What's in my overOne inbox today?”

On Team and Enterprise plans an owner adds the connector for the organisation first; members then connect their own overOne account.

ChatGPT

  1. Settings → Apps & Connectors. If you don't see Create, turn on Developer mode under Advanced settings.
  2. Back in Apps & Connectors, choose Create, name it overOne, paste https://overone.app/mcp and pick OAuth authentication.
  3. Accept the prompt, then sign in to overOne and Allow.
  4. Start a chat, add overOne from the + menu, and ask away.

Anything that posts or replies publicly asks you to confirm first. Disconnect at any time from Account menu → API & AI agents.

API keys & Claude Code

For your own agents, scripts, automation tools and Claude Code, create a key in Account menu → API & AI agents. Each key belongs to one workspace, has the permissions you tick, and can expire. It's shown once — keep it in a secret store, never in code or a shared chat.

Claude Code:

claude mcp add --transport http overone https://overone.app/mcp \
  --header "Authorization: Bearer $OVERONE_API_KEY"

Other MCP clients that take a JSON config with headers (Cursor, VS Code and similar):

{
  "mcpServers": {
    "overone": {
      "type": "http",
      "url": "https://overone.app/mcp",
      "headers": { "Authorization": "Bearer ${OVERONE_API_KEY}" }
    }
  }
}

REST API

Send the key (or an OAuth access token issued for the REST API) in the Authorization header. JSON in, JSON out.

curl https://overone.app/v1/me \
  -H "Authorization: Bearer $OVERONE_API_KEY"

Schedule a post (use the accountId values from GET /v1/accounts):

curl -X POST https://overone.app/v1/posts \
  -H "Authorization: Bearer $OVERONE_API_KEY" \
  -H "Content-Type: application/json" \
  -H "Idempotency-Key: launch-2026-10-01" \
  -d '{
    "content": "We just shipped dark mode.",
    "accountIds": ["<accountId>"],
    "scheduledFor": "2026-10-01T09:00:00-04:00",
    "timezone": "America/New_York"
  }'

Retrying with the same Idempotency-Key never posts twice. OpenAPI 3.1 spec

Endpoints

Each endpoint is also an MCP tool with the same name, arguments and permission.

EndpointMCP toolNeeds
GET /v1/me

Get workspace and brand settings

get_workspaceread
GET /v1/feed

Get a day's Scroll To Post feed

get_content_feedread
GET /v1/accounts

List connected social accounts

list_social_accountsread
GET /v1/posts

List posts

list_postsread
POST /v1/posts

Publish or schedule a post

publish_postpublish
POST /v1/feed/videos/{videoId}/publish

Publish a Scroll To Post video

publish_feed_reelpublish
POST /v1/drafts

Save a draft post

create_draftwrite
DELETE /v1/posts/{postId}

Cancel a scheduled post

cancel_scheduled_postpublish
GET /v1/inbox

Read the inbox

get_inboxread
POST /v1/inbox/{itemId}/reply

Reply to a comment or message

reply_to_inboxpublish
GET /v1/analytics

Get post analytics

get_analyticsread
GET /v1/automations

List automations

list_automationsread
PATCH /v1/automations/{automationId}

Pause or resume an automation

set_automation_statuswrite
GET /v1/library

List the content library

list_libraryread
GET /v1/usage

Get plan usage

get_usageread
GET /v1/hashtag-sets

List saved hashtag sets

list_hashtag_setsread
POST /v1/hashtag-sets

Save a hashtag set

save_hashtag_setwrite
POST /v1/captions

Write captions

write_captionswrite
PATCH /v1/brand/voice

Update brand voice settings

update_brand_voicewrite

Discover tools and their JSON schemas at runtime with GET /v1/tools, and call any of them with POST /v1/tools/{name}.

Permissions

  • read — brand settings, content feed, library, posts, inbox, analytics, automations and usage. Every key and connection has it.
  • write — write captions, edit brand voice settings, save drafts and hashtag sets, pause or resume automations.
  • publish — publish and schedule posts, cancel scheduled posts, reply to comments and messages. Public, under your name.

Never available through the API: deleting your account, changing your plan or billing, connecting or disconnecting social accounts, and downloading library media in bulk.

Errors & limits

Errors return { "error": { "code": "…", "message": "…" } } with a matching status: 400 invalid input · 401 missing or revoked credential · 403 permission missing · 404 not found · 409 conflict (e.g. a published post can't be cancelled) · 423 account pending deletion · 429 rate or plan limit.

Each key or connection may make 120 requests a minute; the RateLimit-* headers show what's left and 429 responses carry Retry-After. Posts, replies, captions and X actions also count against your plan's allowances exactly as they do in the app.

Security

  • OAuth 2.1 with PKCE (S256) and dynamic client registration; tokens are bound to the resource they were issued for.
  • Access tokens last an hour; refresh tokens rotate on every use, and a reused refresh token revokes the connection.
  • Keys and tokens are stored only as SHA-256 hashes. Keys carry a checksum and the ovr_ prefix so leaked keys can be detected.
  • Every call is scoped to one workspace, re-checked on each request, and recorded in an audit log (never the content).
  • Found a vulnerability? Email support@overone.app.