
Company News
Free Business Plan Upgrades for Open Source Maintainers
Open source maintainers are under more pressure than ever. We're raising our open source program from the Team plan to the Business plan, free.
@miller-joe/youtube-mcp
Advanced tools
OAuth-authenticated YouTube MCP server for channel owners — edit video metadata, reply to and moderate comments, manage playlists, query channel analytics, and set AI-generated thumbnails via a ComfyUI bridge.
OAuth-authenticated YouTube MCP for channel owners. Edit video metadata, reply to and moderate comments, manage playlists, query channel analytics, and generate or set AI thumbnails via a ComfyUI bridge. Goes beyond the read-only Data API v3 wrappers that dominate this space.
Most existing YouTube MCPs use an API key against Data API v3. Search videos, fetch public metadata, read-only. This one uses OAuth 2.0 (Authorization Code + PKCE) so it can actually write to your channel: update video titles, descriptions and tags, reply to comments, moderate spam, manage playlists. It also hits the separate YouTube Analytics API for channel stats, and generates a thumbnail via ComfyUI and pushes it to YouTube in a single MCP call.
Claude, use generate_and_set_thumbnail on video abc123:
prompt: "cyberpunk hacker at keyboard, neon blue and pink, high contrast"
ComfyUI renders 1280×720, youtube-mcp fetches the bytes, and POSTs to thumbnails.set. Done.
# npx, no install
npx @miller-joe/youtube-mcp --help
# Docker
docker run -p 9120:9120 \
-e YOUTUBE_CLIENT_ID=... \
-e YOUTUBE_CLIENT_SECRET=... \
-e YOUTUBE_TOKEN_FILE=/token/token.json \
-v $PWD/token:/token \
ghcr.io/miller-joe/youtube-mcp:latest
Google account plus YouTube channel. Use a personal account, not a workspace one you might lose.
Google Cloud project at https://console.cloud.google.com. Call it whatever you want (e.g. youtube-mcp).
Enable APIs:
OAuth consent screen: External, App name, support email. In Scopes, add:
youtube.uploadyoutube.force-sslyt-analytics.readonlyStay in Testing mode. Add yourself as a test user (required). As the project owner, your refresh token won't expire.
Create OAuth Client ID: Application type = Desktop app. Download the JSON.
Run the interactive auth flow:
npx @miller-joe/youtube-mcp --auth --client-secret-file ./client_secret.json
A browser opens, you log in to the Google account tied to your YouTube channel, and grant the requested scopes. On success, a refresh token is saved to ~/.config/youtube-mcp/token.json.
Start the server:
npx @miller-joe/youtube-mcp --client-secret-file ./client_secret.json
Or provide the client credentials via env: YOUTUBE_CLIENT_SECRET_FILE, or YOUTUBE_CLIENT_ID + YOUTUBE_CLIENT_SECRET.
claude mcp add --transport http youtube http://localhost:9120/mcp
Or point your MCP gateway at the Streamable HTTP endpoint.
| CLI flag | Env var | Default | Notes |
|---|---|---|---|
--client-secret-file | YOUTUBE_CLIENT_SECRET_FILE | (none) | Path to Google OAuth JSON |
--client-id | YOUTUBE_CLIENT_ID | (none) | Alternative to the secret file |
--client-secret | YOUTUBE_CLIENT_SECRET | (none) | Alternative to the secret file |
--token-file | YOUTUBE_TOKEN_FILE | ~/.config/youtube-mcp/token.json | Refresh token storage |
--host | MCP_HOST | 0.0.0.0 | Bind host (HTTP mode only) |
--port | MCP_PORT | 9120 | Bind port (HTTP mode only) |
--stdio | MCP_TRANSPORT=stdio | (unset) | Speak MCP over stdio instead of HTTP. Use when launched as a subprocess by a stdio-first MCP client (Claude Desktop, mcp-inspector). |
--comfyui-url | COMFYUI_URL | (unset, bridge disabled) | ComfyUI HTTP URL for bridge tools |
| (no flag) | COMFYUI_DEFAULT_CKPT | sd_xl_base_1.0.safetensors | Default checkpoint for bridge tool |
The server speaks streamable HTTP by default (great for Claude Code, MetaMCP, raw fetch). Pass --stdio (or set MCP_TRANSPORT=stdio) to switch into stdio mode, which is what stdio-first clients like Claude Desktop and the MCP Inspector expect:
// claude_desktop_config.json
{
"mcpServers": {
"youtube": {
"command": "npx",
"args": ["-y", "@miller-joe/youtube-mcp", "--stdio"],
"env": {
"YOUTUBE_CLIENT_SECRET_FILE": "/path/to/client_secret.json",
"YOUTUBE_TOKEN_FILE": "/path/to/token.json"
}
}
}
}
Stdio mode skips the OAuth-token preflight check — the server boots even without a stored token and surfaces auth errors at tool-call time. Run youtube-mcp --auth --client-secret-file <path> once in HTTP mode to seed the refresh token before pointing Claude Desktop at it.
list_my_videos: paginated list of the authenticated channel's uploads.get_video: full detail for one video.update_video_metadata: title, description, tags, category, privacy.delete_video: permanently delete a video. Requires confirm_video_title to match the current title exactly, as a guard against deleting the wrong video.list_captions: list caption tracks on a video (language, name, status, draft flag).upload_caption: upload an SRT or WebVTT caption track to a video.delete_caption: delete a caption track.list_my_shorts: find Shorts in recent uploads (filters by duration ≤60s).get_shorts_analytics: YouTube Analytics query restricted to Shorts (creatorContentType==SHORTS).create_playlist: create a playlist (default private).add_to_playlist: add a video to an existing playlist.list_comments: top-level comment threads on a video.reply_to_comment: reply to a top-level comment.moderate_comment: hold, approve, or reject a comment.query_channel_analytics: date-ranged metrics with optional dimensions and filters.COMFYUI_URL is configured)generate_and_set_thumbnail: generate a thumbnail via ComfyUI and set it on a video in one call.YouTube Data API free tier = 10,000 units/day. Key operation costs:
videos.list, commentThreads.list: 1 unit each.videos.update, comments.insert, thumbnails.set: 50 units each.videos.insert (upload): 1,600 units, so about 6 uploads per day on the free tier.Most creator-ops workflows stay well under the free cap.
┌────────────────┐ ┌──────────────────┐ ┌─────────────────┐
│ MCP client │────▶│ youtube-mcp │────▶│ YouTube APIs │
│ (Claude etc.) │◀────│ (this server) │◀────│ (Data/Analytics)│
└────────────────┘ └────────┬─────────┘ └─────────────────┘
│
│ (bridge tools only)
▼
┌──────────────────┐
│ ComfyUI │
│ (txt2img) │
└──────────────────┘
OAuth refresh tokens are cached locally and refreshed just-in-time before expiry. The bridge tool downloads image bytes from ComfyUI internally, so ComfyUI does not need to be publicly reachable.
git clone https://github.com/miller-joe/youtube-mcp
cd youtube-mcp
npm install
npm run dev
npm run build
npm test
Requires Node 20+.
Shipped:
list_my_shorts (duration filter) and get_shorts_analytics (creatorContentType==SHORTS).generate_and_set_thumbnail.Planned:
video_upload) with resumable-upload support.MIT © Joe Miller
If this saves you time, consider supporting development:
FAQs
OAuth-authenticated YouTube MCP server for channel owners — edit video metadata, reply to and moderate comments, manage playlists, query channel analytics, and set AI-generated thumbnails via a ComfyUI bridge.
The npm package @miller-joe/youtube-mcp receives a total of 29 weekly downloads. As such, @miller-joe/youtube-mcp popularity was classified as not popular.
We found that @miller-joe/youtube-mcp demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Company News
Open source maintainers are under more pressure than ever. We're raising our open source program from the Team plan to the Business plan, free.

Security News
The supply chain control that delays freshly published gems now covers lockfile generation and gem vendoring in Ruby projects.

Security News
During a UK cyber test, a Mythos 5 agent used sockpuppets, social engineering, and prompt injection to try to get a maintainer to merge malware.