I'm Alex. I build Fuxux on my own. It's a social media scheduler: you write a post once and it goes out to Instagram, TikTok, YouTube, LinkedIn, X, Threads, Bluesky, Pinterest and a few more, each with its own caption.
I wanted one thing: to open Claude, type "schedule this for LinkedIn tomorrow at 9", and have it actually happen. Fuxux already had an MCP server, but it worked with an API key you paste into your client. Fine for Cursor. Useless for Claude's directory and for ChatGPT, because there is nowhere to paste a key. They want your server to handle sign-in.
Most of the work turned out to be small things nobody tells you. So here they are, in the order I hit them.
1. My server was failing the wrong way
When a request came in without credentials, I returned a 200 with an error message inside. Felt reasonable. It isn't. A client that supports sign-in only starts the flow when it gets a real 401 plus a header telling it where to look:
HTTP/1.1 401 Unauthorized
WWW-Authenticate: Bearer resource_metadata="https://www.fuxux.com/.well-known/oauth-protected-resource", scope="mcp"
Without that header the client just says the connection failed and gives you nothing else to go on.
2. Two small JSON files that have to be exactly right
-
/.well-known/oauth-protected-resourcesays "this is the resource, and this server protects it". Theresourcevalue must be the exact URL people connect to. Mine ishttps://www.fuxux.com/api/mcp. A missingwwwor an extra slash at the end is enough to break it, and nothing tells you why. -
/.well-known/oauth-authorization-serverlists your authorize, token and registration endpoints, says you support PKCE withS256, and that public clients are fine (token_endpoint_auth_methods_supported: ["none"]).
3. Claude and ChatGPT don't register the way I expected
I expected every client to register itself with dynamic client registration, because that's what the older examples show. Then I connected Claude and it never called it.
Claude sends a client id that is a URL. You fetch that URL and it gives you a small document with the client's name and where to send the user back. ChatGPT does the same thing with its own document. So you need to support both ways:
-
Client ID Metadata Documents, for Claude and ChatGPT. Put
client_id_metadata_document_supported: truein your metadata. - Dynamic registration, for the tools that still use it. Don't skip it: when I submitted to another catalog recently, I saw a company pull their own submission because their server didn't have it.
ChatGPT had one more surprise for me. Its document says token_endpoint_auth_method: "private_key_jwt" and lists ["none", "private_key_jwt"] as supported. My code only accepted none as the method, so ChatGPT users got my "this sign-in request is not valid" page. The fix was to accept any client that lists none as supported, and treat it as a public client with PKCE.
And their review scan checks your tools. Every tool has to say readOnlyHint, destructiveHint and openWorldHint out loud. It flagged my "update post" tool because I had marked it as not destructive. Fair. Editing a post can overwrite a caption you can't get back.
4. Not every app comes back to an https address
Claude Code and other terminal tools listen on http://localhost and pick a new port each time. If you compare the return address as an exact string, a sign-in works once and fails the next time. For localhost you have to ignore the port (it's in RFC 8252).
Some apps come back to their own scheme, like something://callback. I don't accept those yet, only https and localhost. So those apps still use an API key with Fuxux for now. I wrote that on the setup page instead of pretending.
5. Turning sign-in on took one of my listings down
This one I didn't see coming. A directory that checks my server every hour suddenly marked it as unhealthy. Nothing was broken. Their check calls the server with no credentials, which used to get a 200 and now got a 401. I had to go into their dashboard and authorise a test account. I only knew because they emailed me.
If you're listed anywhere, check your listings the day you switch.
6. The consent screen has to be true
When someone connects Claude to Fuxux, the screen tells them what Claude will be able to do. I made sure the code enforces it, not just the text:
- a connected assistant gets 8 tools: your posts (list, read, create, edit, delete), your connected accounts, your dashboard, and "who am I"
- it can't touch your plan, billing, password or connected accounts
- you can remove it in Settings and it stops working right then
I also cut down what the tools send back. "Who am I" returns your email, name and plan. Nothing else leaves.
7. The part that had nothing to do with OAuth
The listing went live and I had my best day ever: 12 sign-ups, 10 of them from Claude. That's more than I usually get in a week.
Two days later I looked at what those people had done. One of the 12 had connected a social account. One.
It took me a while to see why. You find Fuxux in Claude's directory, click connect, sign in on my consent screen, approve, and you're sent straight back to Claude. You now have a Fuxux account and you have never seen Fuxux. No onboarding. Nobody asked you to connect Instagram. So you ask Claude to schedule a post and there's nothing to post to.
What I changed:
- if a tool is called and you have no accounts connected, the answer now tells you what to do next instead of giving back an empty list
- one email, sent once, after you approve the connector with nothing connected
What's still on my list is a "connect your first account" step right after you approve.
So if you're building for one of these directories: test it as someone who has never been on your site. That's who shows up.
What you can do with it now
Once it's connected, this is the kind of thing you can ask:
- "What do I have scheduled this week, and did anything fail?"
- "Write a post about our new pricing page, one version for LinkedIn and one for Bluesky, and save both as drafts"
- "Move tomorrow's Instagram post to Friday at 9"
It works from Claude (it's in Claude's directory), Claude Code, ChatGPT and Cursor, and there's a setup page for Codex too. Each one takes about a minute:
There's a free plan: 3 social accounts and 5 posts a month, no card. Enough to try the whole thing from your assistant and see if it fits how you work.
If you're building your own MCP server and get stuck on any of the steps above, ask in the comments. I've probably hit it.
Top comments (1)
tr.ee/dev-to