# Build brief — a focused alternative to Outstand

> **Verdict:** Partly, if you narrow it · **Buildability:** 67/100 · **Category:** Dev Tools
> **Source:** https://www.canitbevibecoded.com/outstand
> Independent editorial assessment from Can It Be Vibe Coded? Not affiliated with, endorsed by, or derived from Outstand. Verify current pricing and capabilities before acting.

## Context

**Outstand** — One API to post, schedule, and pull analytics across 11 social networks. It currently costs $19/mo.

Writing your own posting service is a contained build, and for the networks with open APIs (Bluesky, Mastodon, Telegram) it genuinely is: a queue, a cron tick, one adapter per network, done. The wall is not code. Instagram, TikTok, YouTube, LinkedIn, and Pinterest each require your own developer app and a platform review before they will accept a single post, X meters writes on a paid tier, and then eleven integrations keep changing under you: token refresh, media specs, rate-limit budgets, deprecated endpoints. You can build the API. You cannot one-shot permission to use it.

This brief describes a focused, single-operator replacement for the part of Outstand that is genuinely reproducible. It is deliberately narrower than the product it replaces, and it says so in writing. Build the useful core; do not pretend to have rebuilt the rest.

## What you are building

Run a small self-hosted service that takes a post plus target accounts over HTTP, queues it, publishes on schedule through one adapter per network, and records per-account delivery status.

- Build the focused developer workflow you use repeatedly, with local configuration.
- A responsive interface with real empty, loading, success, and error states.

## Requirements

### Functional

- Your own developer app per social network.
- Always-on box for the scheduler.
- Media storage.

### Data and integrations

- Paid X API tier for posting to X.

Each of these needs a real account, credential, or quota. Set them up before writing feature code.

### Non-functional

- Accessibility: semantic markup, labelled controls, visible focus, and reduced-motion support.
- Security: server-side secrets, validated input, and no credentials in the client bundle.
- Reliability: retries with backoff on external calls, and a clear failure state when a provider is down.
- Portability: the operator can export their data and leave without losing it.

## Implementation brief

Build me a self-hosted unified posting API to replace Outstand. Requirements:

- Node + Fastify + better-sqlite3, one headless service on localhost:8080.
  No web UI: my own apps are the only consumer, every key in .env.
- One normalized post shape in zod (text, media, targets, scheduledAt,
  idempotencyKey) and one adapter per network mapping it onto that
  platform's payload. Adapters export capabilities, publish, and metrics;
  nothing platform-specific leaks into the core.
- A capability table per adapter (character limit, media count, mime types,
  aspect ratios, max video seconds). POST /posts returns 422 naming which
  target rejected what, before a single network call goes out.
- Ship the three networks that need no app review: Bluesky (@atproto/api),
  Mastodon, Telegram. Adding a fourth must mean writing one adapter file
  and touching nothing else.
- A token-bucket limiter per network seeded with their published limits so
  calls queue instead of returning 429. POST /posts answers 202 with a job
  id and a worker drains the queue.
- Idempotency: replaying a POST with the same idempotencyKey returns the
  original job instead of posting twice, and every target gets its own
  delivery row so partial success is readable.
- GET /posts/:id/analytics folds each platform's metrics into one shape
  (impressions, likes, comments, shares) with null where a network does not
  report a field. Never invent a number to fill a gap.
- An MCP server over stdio exposing create_post, list_accounts, and
  get_analytics so Claude Code posts through it, plus an OpenAPI spec
  generated from the zod schemas at /openapi.json.
- Out of scope: Instagram, TikTok, YouTube, LinkedIn, Pinterest. Each needs
  my own developer app approved by the platform first, a review queue and
  not code. Say that in the README next to the three token setups.

## Delivery standard

- Inspect the repository first, then write a short implementation plan before writing code.
- Deliver the smallest complete end-to-end workflow first; every primary control must work against persisted data.
- Use real validation and storage; never substitute fake dashboards, decorative controls, hard-coded success states, or mock integrations.
- Include responsive layouts plus genuine empty, loading, success, validation, and failure states.
- Keep secrets server-side in environment variables, provide .env.example, and never commit credentials or user data.
- Add structured logs around every external call and return actionable errors without leaking sensitive details.
- Write unit tests for the core logic and one automated test of the main user journey.
- Finish with a README covering setup, architecture, data location, backups, tests, deployment, and known limitations.

## Acceptance criteria

- [ ] A clean install starts the app using only the README and .env.example.
- [ ] The primary journey works from first visit through saved result, reload, edit, export, and deletion where applicable.
- [ ] Invalid input, missing configuration, provider failure, and an empty database each have a usable state.
- [ ] The interface works at 390px and 1440px, is keyboard navigable, and shows visible focus on every control.
- [ ] Tests, type checking, linting, and a production build all pass with no ignored failures.
- [ ] No part of the interface implies a live integration, security guarantee, or scale capability that was not actually built and verified.

## Non-goals

Do not build these, and do not claim to have replaced them:

- Pre-approved platform apps for Instagram, TikTok, YouTube and LinkedIn.
- Eleven maintained integrations, kept alive as platforms change.
- Automatic token refresh and rate-limit queueing.
- Per-network media transcoding from a single upload.
- Connectors, OAuth flows, and vendor API changes require constant upkeep.

## What you still own after launch

- Secure credentials, rotate secrets, and handle provider rate limits.
- Run migrations, backups, restores, and dependency updates.
- Test the critical journey after every model, API, or hosting change.
- Monitor failures and fix the edge cases a first prompt will miss.
- Maintain every third-party integration as APIs and OAuth rules change.

## Risk

**Operational risk.** The code is achievable; dependable data, integrations, and ongoing operations are the real cost.

Editorial confidence in this assessment: high. No independent one-shot implementation is linked yet.

## Prior art

Working open-source software you can read, fork, or borrow from before starting:

- [postiz-app](https://github.com/gitroomhq/postiz-app) — AGPL social scheduler with a public API and per-network adapters, self-hostable as a starting point
- [mixpost](https://github.com/inovector/mixpost) — self-hosted social publishing app (Laravel) you point your own platform apps at

---

Generated by [Can It Be Vibe Coded?](https://www.canitbevibecoded.com) · Full report: https://www.canitbevibecoded.com/outstand
