Nuelink API/MCP Changelog
1.3.0-alpha (2026-10-05)
Section titled “1.3.0-alpha (2026-10-05)”Post updates and deletion, the weekly schedule, and published results.
The API contract is now version 1.2.0, published at /openapi-v1.2.0.yaml. Six new operations bring it to 17, and the MCP server, CLI, and Agent Skills cover every one of them. The previous contract stays available at /openapi-v1.0.1.yaml.
API: six new endpoints
GET /auth- validate a token. Same response as/me.GET /brands/{brand_id}/schedule- every weekly queue slot in the brand, grouped by day, in the brand’s timezone.GET /brands/{brand_id}/posts- posts across every collection in a brand.PATCH /brands/{brand_id}/posts/{post_id}- reschedule, re-queue, or draft a post, or move it to the front or back of its queue. Content isn’t editable.DELETE /brands/{brand_id}/posts/{post_id}- permanently delete a post. A sensitive action, refused unless the account owner enables it in Settings → API.GET /brands/{brand_id}/published-posts- what went out to each channel: delivery status, the platform link, and likes, comments, and shares.
API: other changes
- Post lists filter on the server:
view,status,post_type,posting_type,created_from,created_to,sort_by, andsort_order. Results are newest first, in a deterministic order. - Collections return their queue:
status,evergreen,maxRepublish,timezone, andqueueswith each slot’sdayandtime. The list addspostsCount. - Brands return
queueStatus,ACTIVEorPAUSED. - New post option
autoThreadText, and a caption split by triple newlines becomes a thread of up to 10 segments. - Automation defaults are now documented:
titleis{{title}},loadOldPostsandaddPostsAsDraftarefalse, andrefreshRateis24. - Rate limits are documented as two layers: 60 requests per minute per client IP on every route, and 30 per minute on resource endpoints.
/authand/mecount only against the first. See Rate Limits. - The API accepts the key as an
api_keyquery parameter, for compatibility. TheAuthorizationheader remains the way to send it. See Authentication.
API: corrections to previously documented behavior
If you built against the older pages, check these:
postDateis UTC, formattedY-m-d H:i:s. It’s not ISO 8601, and it’s not the brand-local time you send inscheduledAt. See Dates and timezones.- A post created with
IMMEDIATEreads back withpostingType: NOW. - A
422can carrystatus: "error". Business-rule failures, such as ascheduledAtunder 10 minutes away, return422with string-valuederrors. That case was documented as400. See Errors. - Creating or updating a post in a brand you’re not a member of returns
403, not404. maxRepublishis the evergreen interval:0turns evergreen off, andNre-adds published posts afterNweeks. It was documented as a recycle count.- Queue slots: verified users can create up to 10 per collection per day, unverified users up to 5. Duplicate slots aren’t rejected.
- The X channel type is
X, notX/Twitter.Social Mediais also a channel type. - On
GET /channels,pagination.totalis counted before channels in other states are filtered out, so a page can be short or empty. commentneeds bothdelayandcomment, on every surface.
Breaking changes and migrations
-
Automation fields are renamed, in requests and responses:
1.2.0-alpha 1.3.0-alpha title(the automation’s name)nametype: "FEED"andsubTypetype, which now holds the feed sourcedynamicTitletitledynamicBodycaptiondescriptionRemoved titlekeeps its name but changes meaning: it’s now the title template. Template placeholders use double braces, such as{{title}}and{{link}}. -
webpuploads are no longer accepted.POST /mediatakes JPEG, PNG, BMP, MP4, MOV, and PDF, up to 100 MiB. -
CLI 1.4.5 renames the
automations:createflags to match:--titleis now--name,--sub-typeis now--type,--dynamic-titleand--dynamic-bodyare now--titleand--caption, and--descriptionis gone. Scripts written for CLI 1.4.1 need updating. -
nuelink_create_automationtakes the new field names:name,type,title,caption. -
Code that matches
400for a too-soonscheduledAtshould match422.
MCP: six new tools, 17 in total:
nuelink_validate_token→GET /authnuelink_get_schedule→GET /brands/{id}/schedulenuelink_list_brand_posts→GET /brands/{id}/postsnuelink_update_post→PATCH /brands/{id}/posts/{id}nuelink_delete_post→DELETE /brands/{id}/posts/{id}nuelink_list_published_posts→GET /brands/{id}/published-posts
nuelink_list_posts takes the new post filters, and nuelink_create_post takes autoThreadText.
CLI 1.4.5
- Six new commands:
auth:validate,schedule,brand-posts,posts:update,posts:delete, andpublished-posts.posts:updateandposts:deletesupport--dry-run, like every other API mutation. poststakes the new filter flags, andposts:createtakes--auto-thread-text.- Upload validation now matches the API:
jpg,jpeg,png,bmp,mp4,mov, andpdf. CLI 1.4.1 acceptedgifandwebpand rejectedbmpandpdf.
Agent Skills
nuelink-cli-publishcovers post updates, deletion, and published results, and asks for a separate confirmation immediately before anyposts:delete.nuelink-cli-setupchecks the key withauth:validate.- The contract tests run seven network-blocked mutation dry-runs, adding
posts:updateandposts:delete.
Docs
- Endpoints reorganized by resource, with every request example in cURL, JavaScript, and PHP, and a table of the API’s date formats and timezones.
- Rate Limits and Errors rewritten for the two rate limits and four error shapes.
- Available Tools expanded to seventeen tools, and Example Prompts gained prompts for changing posts and reviewing results.
1.2.0-alpha (2026-08-19)
Section titled “1.2.0-alpha (2026-08-19)”OAuth for MCP, five new endpoints, an official CLI, and an Agent Skills pack.
This is the largest release since the alpha opened. The API surface grew from 6 endpoints to 11, the MCP server from 6 tools to 11, and there are now two new ways to reach Nuelink: a command-line tool and a skills pack for coding agents.
MCP server v1.1.0
Streamable HTTP transport, protocol version 2025-06-18.
MCP: OAuth
OAuth is the recommended path for new MCP connections. Configure https://mcp.nuelink.com/mcp without an API key in the URL; discovery, dynamic registration, and the S256 PKCE handoff are operational.
- Authorization code flow with PKCE (S256). Discovery metadata also advertises the
refresh_tokengrant; end-to-end token issuance and refresh remain awaiting final acceptance certification. - Dynamic client registration (RFC 7591) at
https://mcp.nuelink.com/register. No app to create, no client ID to manage. - Standard discovery documents at
/.well-known/oauth-authorization-serverand/.well-known/oauth-protected-resource. - The
api_keyquery parameter is deprecated. It remains temporarily available so existing connections keep working, but it must not appear in new integrations. No removal date is set; we’ll announce one with notice. See MCP Authentication for the migration steps. - Errors now surface properly. Validation failures and downstream API failures come back with
isError: true, alongside the underlyingstatus,message, anderrors.
Known MCP limitations in this release
- The OAuth lifecycle is not fully certified. Discovery, dynamic registration, and the S256 PKCE authorization handoff are operational and verified as of 2026-08-19. The complete logged-in consent, code-exchange, access-token, refresh, and revocation lifecycle still needs final acceptance certification.
- Session termination can return HTTP
500with Cloudflare Worker Error 1101, after an otherwise successful session.
MCP: five new tools, 11 in total:
nuelink_create_collection→POST /brands/{id}/collectionsnuelink_list_automations→GET /brands/{id}/automationsnuelink_create_automation→POST /brands/{id}/automationsnuelink_list_media→GET /brands/{id}/medianuelink_list_posts→GET /brands/{id}/collections/{id}/posts
MCP: platform option parity
platforms.tiktok.autoAddMusic and platforms.googlemybusiness.uploadToPhotosSection are now exposed through the MCP tool schema, so all three surfaces accept the same platform options.
API: five new endpoints
POST /brands/{brand_id}/collections- create a collection with its channels and weekly queue.GET /brands/{brand_id}/automations- list feed automations.POST /brands/{brand_id}/automations- create a feed automation across 27 source types.GET /brands/{brand_id}/media- list a brand’s media library, with an optional type filter.GET /brands/{brand_id}/collections/{collection_id}/posts- list posts in a collection.
API: other changes
- Base URL is now
https://app.nuelink.com/api/public/v1.nuelink.comstill works, so nothing breaks, but new integrations should useapp.nuelink.com. - Rate-limit headers (
X-RateLimit-Limit,X-RateLimit-Remaining,X-RateLimit-Reset) are documented on successful and429responses. - New post option:
platforms.googlemybusiness.uploadToPhotosSection.platforms.instagram.trialReel,platforms.instagram.shareToFeed,platforms.youtube.playlists, and the poll quiz fields (correctOptionIndex,explanation) already existed; this release documents them more fully. - Documented limits: 15,000 posts per brand, 10 posts per collection per day,
scheduledAtat least 10 minutes ahead.
API: corrections to previously documented behavior
These bring the docs in line with the 1.0.1 OpenAPI contract. If you built against the older pages, check these:
- Default
per_pageis25, not10. Passper_pageexplicitly if your code assumed the old default. 422and429bodies have nostatusfield. Only business-rule errors (400,401,403,404,500) carrystatus: "error". A parser that keys offstatuswill miss validation and rate-limit failures. See Errors.- Collections do not return a
statusfield, and channels embedded in a collection returnid,name,status, andtypewithout timestamps. The standaloneGET /channelsstill returnscreatedAtandupdatedAt.
Media: expanded upload formats
POST /brands/{brand_id}/media accepts jpg, jpeg, png, bmp, webp, mp4, mov, and pdf, up to 100 MB. PDF publishes to LinkedIn as a document post; other platforms in the collection skip it.
The CLI validates uploads against its own list before sending, which is not the same set: CLI 1.4.1 rejects bmp and pdf locally and accepts gif. See CLI commands for that guard, and use the REST API or MCP for formats the CLI blocks.
New: Nuelink CLI
@nuelink/nuelink-cli on npm, MIT licensed, Node 18.17+.
- Full command coverage for profile, brands, channels, collections, automations, media, and posts.
--dry-runon every API mutation,--jsonfor machine-readable output, and--quietfor API-request scripts.- Auth via
--api-keyflag,NUELINK_API_KEY, or an encrypted local config, resolved in that order. - Strict local validation for required strings, booleans, URLs, dates, enums, pagination bounds, and raw JSON payloads.
- One structured JSON value on stdout for both successes and failures in
--jsonmode. - Retries
GETonly, on429and5xx, honoringRetry-Afterand backing off with jitter. Mutations are never retried. - Ships and passes its packaged test suite.
New: Agent Skills
Nuelink/nuelink-agent, installed with npx skills add Nuelink/nuelink-agent.
- Three canonical skills:
nuelink-cli-setup,nuelink-cli-manage,nuelink-cli-publish. - Native plugin manifests for Claude Code and Codex, plus bundled remote MCP config.
- Nine compatibility aliases kept as opt-in migration paths, excluded from default installer discovery.
- Safety-first defaults: discover before mutating, preview with
--dry-run, default toDRAFT. - CI covers skill structure, the Agent Skills reference validator, behavior fixtures, network-blocked contract tests, installer discovery, and markdown lint.
Docs
- New CLI and Agent Skills sections.
- MCP Authentication rewritten around OAuth, with an API-key migration guide.
- Available Tools expanded to eleven tools.
- Introduction reframed around four surfaces instead of two.
Breaking changes and migrations
One genuine break, and three things worth updating:
-
Breaking: a REST API key in the MCP
Authorizationheader is now rejected. 1.1.0 documented this as a supported option; it now returns401. Move those connections to OAuth, or to the deprecated?api_key=query parameter as a stopgap. -
MCP clients using
"type": "sse"should switch to"type": "http". The server uses streamable HTTP. -
MCP connections using
?api_key=should migrate to OAuth. They still work for now. -
Move new integrations to
app.nuelink.com.
1.1.0-alpha (2026-05-12)
Section titled “1.1.0-alpha (2026-05-12)”Introducing the Nuelink MCP Server.
You can now connect Nuelink to Claude, ChatGPT, Cursor, Manus, Codex, Cline, and any other MCP-compatible AI assistant. Instead of writing code against the REST API, describe what you want in plain English and the assistant calls the right tools for you:
“Queue this product photo to my Product Launches collection, with the caption I just wrote.”
What shipped
- MCP server endpoint:
https://mcp.nuelink.com/mcp - At launch, two API-key methods were documented:
?api_key=YOUR_API_KEYand a REST API key in theAuthorizationheader. As of 1.2.0-alpha, only the query-key method remains as a deprecated compatibility path; the MCP endpoint rejects a REST API key supplied as a bearer token. See the current authentication section above. - Six tools, each mapping 1:1 to an existing API endpoint:
nuelink_get_me→GET /menuelink_list_brands→GET /brandsnuelink_list_collections→GET /brands/{id}/collectionsnuelink_list_channels→GET /brands/{id}/channelsnuelink_create_post→POST /brands/{id}/collections/{id}/postsnuelink_upload_file→POST /brands/{id}/media
- Direct-URL media support: in addition to uploaded files, you can pass a stable HTTPS URL that returns media bytes without login, cookies, an HTML viewer, or short-lived authorization.
Docs
- New MCP Server section with Overview, Quick Start, Authentication, Available Tools, and Example Prompts.
- Rewritten Introduction with two-surface framing (API + MCP).
Underlying API
No breaking changes to the REST API. The MCP server is a thin wrapper over the same public endpoints, anything you can do via MCP, you can also do via the API, and vice versa.
1.0.0-alpha (2026-04-21)
Section titled “1.0.0-alpha (2026-04-21)”- Initial alpha release.
- Endpoints included:
GET /meGET /brandsGET /brands/{id}/collectionsGET /brands/{id}/channelsPOST /brands/{id}/mediaPOST /brands/{id}/collections/{id}/posts
Known gaps in alpha
Section titled “Known gaps in alpha”Resolved in 1.3.0-alpha
Updating or deleting posts→PATCH /brands/{id}/posts/{id}reschedules, re-queues, or drafts a post;DELETEremoves it, as a sensitive actionRetrieving post performance→GET /brands/{id}/published-postsreturns likes, comments, and shares per channelPer-channel publishing status→GET /brands/{id}/published-postsreturns each channel’s delivery status and platform link, onestatusper requestFiltering posts on the server→ post lists takeview,status, type, and date filters
Resolved in 1.2.0-alpha
Listing posts→GET /brands/{id}/collections/{id}/postsListing previously uploaded media→GET /brands/{id}/mediaNo way to create collections or automations programmatically→ both now available
Still not available
- Editing a post’s content.
PATCHchanges when or whether a post publishes, not its caption, media, or options. Edit content in the Nuelink dashboard. - Updating or deleting collections, automations, or media. They’re create-and-read only. Change and remove them in the dashboard.
- Analytics beyond per-post likes, comments, and shares.
- Webhooks for publish success / failure events. Poll
GET /published-postsinstead. - Targeting a subset of channels within a collection. Posts go to every channel in the collection.
- Per-platform caption or comment customization. Caption and auto-comment are global; non-content options like Instagram collabs and YouTube tags can be set per platform.
- Idempotency keys on creation endpoints. Don’t auto-retry a timed-out mutation.
MCP-specific limitations
The MCP server has its own open items, including OAuth lifecycle certification and defective session termination. They’re listed once, in MCP Overview → Current limitations, so the two lists can’t drift apart.
If any of these are blockers for your integration, let us know and we’ll prioritize accordingly.