# Build brief — a focused alternative to posterly

> **Verdict:** Partly, if you narrow it · **Buildability:** 50/100 · **Category:** Social Media
> **Source:** https://www.canitbevibecoded.com/posterly
> Independent editorial assessment from Can It Be Vibe Coded? Not affiliated with, endorsed by, or derived from posterly. Verify current pricing and capabilities before acting.

## Context

**posterly** — Social scheduler for 18 platforms built agent-first: an MCP server and API let AI agents draft, learn your voice, and post directly. It currently costs $15/mo.

A basic compose-queue-publish loop against open-API networks (Mastodon, Bluesky, Telegram) is a contained build, same as any scheduler. What's specific to posterly and harder to fake is the agent-native layer: an MCP server exposing tools like generate_captions, get_learned_voice, and find_available_slot so a coding agent can draft and post on your behalf, plus a voice model that's actually learned from your posting history and its own performance data rather than a one-off few-shot prompt. Add Google Business Profile review management, per-platform video transcoding, and client approval workflows for agencies, and the moat is upkeep and depth, not the initial compose/publish loop.

This brief describes a focused, single-operator replacement for the part of posterly that is genuinely reproducible. It is deliberately narrower than the product it replaces, and it says so in writing. Build the useful core; do not pretend to have rebuilt the rest.

## What you are building

A local API and compose queue that publishes to open-API networks on a schedule, with a caption endpoint an agent can call directly instead of a UI-only AI button.

- Draft, queue, and track content for the few networks you actually use.
- A responsive interface with real empty, loading, success, and error states.

## Requirements

### Functional

- Always-on box for the scheduler.
- Database.
- Media storage.

### Data and integrations

- OAuth/API access per social network.
- LLM API key for caption generation.

Each of these needs a real account, credential, or quota. Set them up before writing feature code.

### Non-functional

- Accessibility: semantic markup, labelled controls, visible focus, and reduced-motion support.
- Security: server-side secrets, validated input, and no credentials in the client bundle.
- Reliability: retries with backoff on external calls, and a clear failure state when a provider is down.
- Portability: the operator can export their data and leave without losing it.

## Implementation brief

Build me a personal social scheduler an AI agent can drive, to replace posterly. Requirements:

- Node + Express + better-sqlite3, with both a localhost compose page and
  a small local HTTP API (list_slots, create_post, get_recent_posts) so a
  coding agent can call it directly instead of only a human using the UI.
- Three open-API targets: Mastodon (access token), Bluesky (app password
  via @atproto/api), and a Telegram channel (bot token). One adapter file
  per network so a fourth is addable later.
- A /caption endpoint: given a topic, call an LLM API (key in .env) with
  my last ~20 published posts as style examples, so drafts sound like me
  instead of a generic AI voice. Cache the examples so it's not refetching
  the DB on every call.
- Slot-based queue: posting times per weekday in my timezone, new posts
  fill the next free slot, or pin an exact datetime; duplicate a post
  across networks with per-network text.
- A node-cron tick every minute publishes due posts, marks each row sent
  or failed before sending (no double-posts), retries failures 3 times.
- Attached images in media/ next to the database, resized per network
  with sharp; a history page of the last 100 sent posts linking out.
- Runs on my always-on box; localhost only, no accounts, no telemetry.
- Out of scope: Instagram, LinkedIn, TikTok, Facebook, and Google Business
  Profile (approval-gated APIs, say so in the README), review management,
  client approvals, video transcoding, and analytics.
- README: getting a Mastodon token, a Bluesky app password, a Telegram
  bot token, and pointing a coding agent at the local API.

## Delivery standard

- Inspect the repository first, then write a short implementation plan before writing code.
- Deliver the smallest complete end-to-end workflow first; every primary control must work against persisted data.
- Use real validation and storage; never substitute fake dashboards, decorative controls, hard-coded success states, or mock integrations.
- Include responsive layouts plus genuine empty, loading, success, validation, and failure states.
- Keep secrets server-side in environment variables, provide .env.example, and never commit credentials or user data.
- Add structured logs around every external call and return actionable errors without leaking sensitive details.
- Write unit tests for the core logic and one automated test of the main user journey.
- Finish with a README covering setup, architecture, data location, backups, tests, deployment, and known limitations.

## Acceptance criteria

- [ ] A clean install starts the app using only the README and .env.example.
- [ ] The primary journey works from first visit through saved result, reload, edit, export, and deletion where applicable.
- [ ] Invalid input, missing configuration, provider failure, and an empty database each have a usable state.
- [ ] The interface works at 390px and 1440px, is keyboard navigable, and shows visible focus on every control.
- [ ] Tests, type checking, linting, and a production build all pass with no ignored failures.
- [ ] No part of the interface implies a live integration, security guarantee, or scale capability that was not actually built and verified.

## Non-goals

Do not build these, and do not claim to have replaced them:

- 18 maintained platform integrations, including approval-gated ones (Instagram, LinkedIn, TikTok, Facebook, Google Business Profile).
- A voice model trained on your actual post history and what performed well, not a static prompt template.
- Google Business Profile review replies and photo management.
- Client approval portal and content-plan review for agencies managing multiple brands.
- Connectors, OAuth flows, and vendor API changes require constant upkeep.
- Years of history, configuration, and habits make migration costly.

## What you still own after launch

- Secure credentials, rotate secrets, and handle provider rate limits.
- Run migrations, backups, restores, and dependency updates.
- Test the critical journey after every model, API, or hosting change.
- Monitor failures and fix the edge cases a first prompt will miss.
- Maintain every third-party integration as APIs and OAuth rules change.

## Risk

**Operational risk.** The code is achievable; dependable data, integrations, and ongoing operations are the real cost.

Editorial confidence in this assessment: high. No independent one-shot implementation is linked yet.

## Prior art

Working open-source software you can read, fork, or borrow from before starting:

- [Postiz](https://github.com/gitroomhq/postiz-app) — Open-source social scheduler, self-hostable, covers much of the DIY core for open-API networks

---

Generated by [Can It Be Vibe Coded?](https://www.canitbevibecoded.com) · Full report: https://www.canitbevibecoded.com/posterly
