DEV Community

Usama Ejaz
Usama Ejaz

Posted on

Letting an agent write to your blog: what MCP servers allow

Most blogging platforms that have an MCP server only let it write if you're on a paid plan.

I built JustBlogged, a hosted blog platform, and I added a remote MCP server to it so Claude, Cursor and other clients can write to a real blog. Before deciding how mine should work, I went through what the other platforms do. I think three things decide whether you can actually let an agent write to your blog: whether the server can write at all, how it signs in, and which plan unlocks it. The third one is where most of them stop you.

The comparison

These are from each platform's own docs, checked October 10, 2026.

Platform Can write/publish? Auth Plan needed
WordPress.com Yes OAuth 2.1, read-only option Paid plan. Free sites: first 30 days only
Hashnode Yes Hashnode login Hashnode Pro
Inblog Yes OAuth Team plan or higher
Substack No, read-only Substack sign-in Bestseller publication
Ghost No official write server (docs search only) Community servers use an Admin API key n/a
Webflow Yes, CMS items and publish Connector sign-in, pick sites All Site plans, including free Starter
Sanity Yes, drafts and publish OAuth or API token A Sanity account
Notion Yes, create and update pages OAuth Not stated in the docs
JustBlogged (mine) Yes, drafts by default OAuth 2.1 + PKCE + dynamic client registration Free plan, no card

Write access

Substack's official server "cannot publish posts, send Notes, or modify your account". It gives you subscriber counts, traffic and revenue, and only for Bestseller publications. Useful, but an agent can't write anything there.

Ghost's official MCP server searches the Ghost developer docs and doesn't touch your site. To write to a Ghost blog you'd use a community server built on the Admin API, like ghost-publisher-mcp. That works, but you're running someone else's code with a key that has full access to your site.

Sanity and Notion can both write. Sanity is a headless CMS though, so you need your own front end, and Notion is a blog only if you publish it through another service.

Auth

Almost everyone on the list now uses OAuth in the browser, which I think is right. An API key pasted into a JSON config file sits in plain text on every machine you set the client up on.

For JustBlogged I went with OAuth 2.1 with PKCE and dynamic client registration. The client registers itself, opens a browser window, you sign in, done. No key to copy anywhere. tools/list also works without signing in, so you can see all 48 tool schemas before you give anything access.

Plan gating

WordPress.com's server is the most complete one here. It splits read and write tools, offers a read-only grant at sign-in, asks for confirmation on writes and respects user roles. But on a free site it works for the first 30 days, then you need a paid plan. Hashnode's FAQ says "Connecting is free. Your publication needs Hashnode Pro." Inblog needs Team or higher.

Webflow is the exception. Its server works on the free Starter plan, and it can create CMS items and publish the site. It's a site builder rather than a blog host, so your blog is a CMS collection you design yourself, but if you already have a Webflow site it's a good free option.

I made MCP and the REST API work on the JustBlogged free plan, no card. I think gating it makes sense for a platform where MCP is an add-on to an existing paid product. For me the agent is one of the main ways people would write to the blog, and I don't want someone paying before they've seen it work once.

Tradeoffs I made (and the ones I haven't solved)

Draft by default. Posts created over MCP are drafts unless you explicitly ask to publish. Hashnode went the other way: their create_post publishes immediately, and they recommend asking the agent to save a draft first. I'd rather the agent need one extra instruction to go public than one missed instruction to accidentally go public.

One scope. This is the one I'm least happy with. Right now a single OAuth scope, blogs:manage, covers everything, including deleting a blog and changing domains. WordPress.com lets you grant read-only at sign-in and I don't have that yet.

The obvious split is read vs write. I'm not sure that's enough. Deleting a blog and fixing a typo in a draft are both "write". Maybe it's read / write drafts / publish / destructive. Maybe it's per blog. Every extra scope is also one more thing on the consent screen that people click through without reading, so I don't know where the line is.

HTML only. Content goes in as HTML. Agents are fine at writing HTML, but Markdown would be shorter and easier to review.

Images. The MCP upload_image tool takes base64, which burns a lot of tokens on a large file. The REST API takes a normal multipart upload and a post's featured image can be set from a URL, but over MCP there's no upload-from-URL yet.

Setup for Claude, Cursor, Claude Code, VS Code, Gemini CLI and ChatGPT is at justblogged.com/ai if you want to try it.

If you've let an agent write to something public, what permission split would you actually want before connecting it? Read vs write, or something finer

Top comments (0)