# Build brief — a focused alternative to post2all

> **Verdict:** Partly, if you narrow it · **Buildability:** 53/100 · **Category:** Social Media
> **Source:** https://www.canitbevibecoded.com/post2all
> Independent editorial assessment from Can It Be Vibe Coded? Not affiliated with, endorsed by, or derived from post2all. Verify current pricing and capabilities before acting.

## Context

**post2all** — Social media scheduler for teams and agents with API and MCP access. It currently costs $9/mo.

The core loop (compose, queue, schedule, publish) is one-shottable for networks with open APIs such as Mastodon, Bluesky, Telegram, and Discord. What you cannot one-shot is the reason a multi-network scheduler exists: OAuth apps for Instagram, LinkedIn, TikTok, YouTube, and other major platforms are approval-gated or costly, and their APIs, media rules, and token lifecycles need ongoing maintenance. A personal replacement can cover a useful subset, but matching post2all's breadth is a permanent integration project.

This brief describes a focused, single-operator replacement for the part of post2all that is genuinely reproducible. It is deliberately narrower than the product it replaces, and it says so in writing. Build the useful core; do not pretend to have rebuilt the rest.

## What you are building

Compose posts into a scheduled queue, publish them through a few open social APIs, and keep a local history of successes and failures.

- Draft, queue, and track content for the few networks you actually use.
- A responsive interface with real empty, loading, success, and error states.

## Requirements

### Functional

- Always-on box for the scheduler.
- Database.
- Media storage.

### Data and integrations

- OAuth/API access per social network.

Each of these needs a real account, credential, or quota. Set them up before writing feature code.

### Non-functional

- Accessibility: semantic markup, labelled controls, visible focus, and reduced-motion support.
- Security: server-side secrets, validated input, and no credentials in the client bundle.
- Reliability: retries with backoff on external calls, and a clear failure state when a provider is down.
- Portability: the operator can export their data and leave without losing it.

## Implementation brief

Build me a personal social media scheduler to replace post2all.

- Use Node.js, TypeScript, Express, SQLite, and a small vanilla HTML/CSS/JS UI.
- Add a compose form with text, image/video attachment, per-network previews,
  character counters, a timezone, and either publish-now or scheduled delivery.
- Implement adapters for Bluesky, Mastodon, Telegram, and Discord using tokens
  from .env; keep one adapter per network and never store secrets in the database.
- Add a queue, retry failed deliveries three times with backoff, mark jobs before
  sending to avoid duplicates, and show the last 100 deliveries with permalinks.
- Store media locally, validate each network's text and file limits, and expose
  a simple local REST endpoint for creating and listing posts.
- Out of scope: Instagram, LinkedIn, TikTok, YouTube, Facebook, Pinterest, X,
  analytics, team accounts, billing, and AI features; explain in the README that
  those platforms need app review, business verification, paid access, or upkeep.
- Run on localhost with no telemetry, include setup instructions and a seed demo.

## Delivery standard

- Inspect the repository first, then write a short implementation plan before writing code.
- Deliver the smallest complete end-to-end workflow first; every primary control must work against persisted data.
- Use real validation and storage; never substitute fake dashboards, decorative controls, hard-coded success states, or mock integrations.
- Include responsive layouts plus genuine empty, loading, success, validation, and failure states.
- Keep secrets server-side in environment variables, provide .env.example, and never commit credentials or user data.
- Add structured logs around every external call and return actionable errors without leaking sensitive details.
- Write unit tests for the core logic and one automated test of the main user journey.
- Finish with a README covering setup, architecture, data location, backups, tests, deployment, and known limitations.

## Acceptance criteria

- [ ] A clean install starts the app using only the README and .env.example.
- [ ] The primary journey works from first visit through saved result, reload, edit, export, and deletion where applicable.
- [ ] Invalid input, missing configuration, provider failure, and an empty database each have a usable state.
- [ ] The interface works at 390px and 1440px, is keyboard navigable, and shows visible focus on every control.
- [ ] Tests, type checking, linting, and a production build all pass with no ignored failures.
- [ ] No part of the interface implies a live integration, security guarantee, or scale capability that was not actually built and verified.

## Non-goals

Do not build these, and do not claim to have replaced them:

- 12+ maintained platform integrations.
- Pre-approved OAuth apps for approval-gated networks.
- Per-platform media validation and publishing reliability.
- Team calendar, drafts, and collaboration workflow.
- Hosted API and MCP access for agent-driven publishing.

## What you still own after launch

- Secure credentials, rotate secrets, and handle provider rate limits.
- Run migrations, backups, restores, and dependency updates.
- Test the critical journey after every model, API, or hosting change.
- Monitor failures and fix the edge cases a first prompt will miss.
- Maintain every third-party integration as APIs and OAuth rules change.

## Risk

**Operational risk.** The code is achievable; dependable data, integrations, and ongoing operations are the real cost.

Editorial confidence in this assessment: high. No reviewed project implementation is linked yet.

## Existing alternatives

Before building, compare these checked options:

- [Postiz](https://postiz.com/) — Broad social scheduling in an open-source package; self-host it and inherit the stack and upkeep

---

Generated by [Can It Be Vibe Coded?](https://www.canitbevibecoded.com) · Full report: https://www.canitbevibecoded.com/post2all
