
Research
/Security News
TensorLake npm SDK Compromised in ChainDrop Shai-Hulud Credential-Stealing Attack
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.
@posteverywhere/sdk
Advanced tools
Official PostEverywhere Node.js SDK: schedule and publish posts to Instagram, TikTok, YouTube, LinkedIn, Facebook, X (Twitter), Threads, Pinterest, Bluesky, Telegram, Discord and WordPress from code or AI agents.
The official Node.js / TypeScript SDK for PostEverywhere — schedule and publish posts to Instagram, TikTok, YouTube, LinkedIn, Facebook, X (Twitter), Threads, Pinterest, Bluesky, Telegram and Discord, plus blog posts to WordPress from a single API. Build social media scheduling, content automation, and AI agent workflows in minutes.
💡 Building an AI agent? Try the companion
@posteverywhere/mcppackage — a Model Context Protocol server that lets Claude Code, Claude Desktop, Cursor, and other MCP-compatible clients schedule posts using natural language.
| Resource | URL |
|---|---|
| 🌐 Homepage | posteverywhere.ai |
| 🛠️ Developers landing page | posteverywhere.ai/developers |
| 📖 API Documentation | posteverywhere.ai/docs |
| 📦 This SDK on npm | npmjs.com/package/@posteverywhere/sdk |
| 💻 This SDK on GitHub | github.com/posteverywhere/sdk |
| 🤖 MCP server (npm) | npmjs.com/package/@posteverywhere/mcp |
| 🤖 MCP server (GitHub) | github.com/posteverywhere/mcp |
| 🎛️ Dashboard | app.posteverywhere.ai |
| 🔑 Get an API key | app.posteverywhere.ai/developers |
| 💵 Pricing | posteverywhere.ai/pricing |
| 📚 Help Center | posteverywhere.ai/support |
| 🐛 Issues / bug reports | github.com/posteverywhere/sdk/issues |
| 📧 Support | support@posteverywhere.ai |
retryable flags on every error, idempotency keys, circuit breakerA modern, API-first alternative to legacy social media management tools — designed for developers, AI agents, and automation-heavy workflows.
npm install @posteverywhere/sdk
pnpm add @posteverywhere/sdk
yarn add @posteverywhere/sdk
import PostEverywhere from '@posteverywhere/sdk';
const client = new PostEverywhere({
apiKey: 'pe_live_your_api_key_here',
});
// List connected social accounts
const { accounts } = await client.accounts.list();
console.log(accounts);
// Publish to all accounts immediately
const post = await client.posts.create({
content: 'Hello from the PostEverywhere SDK! 🚀',
publish_now: true,
});
// Or schedule for later
const scheduled = await client.posts.create({
content: 'Tomorrow morning',
scheduled_for: '2026-04-30T09:00:00Z',
timezone: 'America/New_York',
});
// List all connected social accounts across all platforms
const { accounts } = await client.accounts.list();
// Get a single account by ID
const account = await client.accounts.get(123);
Each account has a health field showing token status and whether it can post — useful for surfacing reconnect prompts to your users.
The core of the SDK. Create, schedule, edit, retry, and delete posts across all platforms.
// Publish immediately to ALL connected accounts
const post = await client.posts.create({
content: 'My post content',
publish_now: true,
});
// Schedule for later (timezone-aware)
const scheduled = await client.posts.create({
content: 'Scheduled post',
scheduled_for: '2026-03-20T09:00:00Z',
timezone: 'America/New_York',
});
// Target specific accounts only
const targeted = await client.posts.create({
content: 'Just for Instagram and TikTok',
account_ids: [456, 789],
publish_now: true,
});
// Attach media (upload first, then reference)
const withMedia = await client.posts.create({
content: 'Check out this photo!',
media_ids: ['media-uuid-here'],
publish_now: true,
});
// Per-platform content overrides — same post, different copy per network
const customized = await client.posts.create({
content: 'Default content',
platform_content: {
twitter: { content: 'Short version for X' },
linkedin: { content: 'Longer professional version for LinkedIn...' },
},
publish_now: true,
});
// List posts with filters
const { posts } = await client.posts.list({ status: 'done', limit: 10 });
// Get per-platform publishing results (with platform_post_url for each)
const results = await client.posts.results('post-id');
// Retry failed destinations
await client.posts.retry('post-id');
// Update a scheduled or draft post
await client.posts.update('post-id', { content: 'Updated content' });
// Delete a post
await client.posts.delete('post-id');
Scheduled posts (with a future scheduled_for) bypass the per-minute publishing limit, so you can fire a month of content in parallel:
const posts = [
{ content: 'Monday morning', scheduled_for: '2026-04-01T09:00:00Z' },
{ content: 'Wednesday update', scheduled_for: '2026-04-03T12:00:00Z' },
{ content: 'Friday wrap-up', scheduled_for: '2026-04-05T16:00:00Z' },
];
const results = await Promise.allSettled(
posts.map(p =>
client.posts.create({
content: p.content,
account_ids: [2280, 2282],
scheduled_for: p.scheduled_for,
})
)
);
Two paths depending on where your file lives:
If your image is already at a public URL (web search result, OG image, hosted screenshot), this is the fastest path. Server fetches the bytes and returns a ready-to-attach media_id.
const media = await client.media.uploadFromUrl({
url: 'https://example.com/hero.webp',
});
await client.posts.create({
content: 'Photo post!',
account_ids: [123],
media_ids: [media.media_id],
});
For local files or videos, client.media.upload(...) handles the full presign → PUT → complete dance internally.
import fs from 'fs';
const media = await client.media.upload(
fs.readFileSync('photo.jpg'),
{ filename: 'photo.jpg', contentType: 'image/jpeg' }
);
await client.posts.create({
content: 'Photo post!',
media_ids: [media.id],
publish_now: true,
});
// List your media library
const { media: files } = await client.media.list({ type: 'image' });
// Delete media
await client.media.delete('media-id');
📖 Media requirements per platform →
Generate images from text prompts using state-of-the-art models, then post them directly.
const image = await client.ai.generateImage({
prompt: 'A professional social media banner with abstract green shapes',
model: 'flux-schnell',
aspect_ratio: '16:9',
});
await client.posts.create({
content: 'AI-generated visual!',
media_ids: [image.media_id],
publish_now: true,
});
Available models: nano-banana-pro, ideogram-v2, gemini-3-pro, flux-schnell
Aspect ratios: 1:1, 16:9, 9:16, 4:3, 3:4, 4:5, 5:4
The PostEverywhere API is designed to be agent-friendly:
retryable: false on every permanent error — agents know when to stop retrying422 with permanent_failure_circuit_breaker) so runaway loops can't burn rate limitsvalidation_errorsUsing a Claude/MCP-style agent? Skip this SDK and use @posteverywhere/mcp instead — natural-language scheduling via the Model Context Protocol. Works with Claude Code, Claude Desktop, Cursor, and other MCP-compatible clients.
📖 LLM agent system prompt template →
import PostEverywhere, {
AuthenticationError,
RateLimitError,
ValidationError,
InsufficientCreditsError,
PostEverywhereError,
} from '@posteverywhere/sdk';
try {
await client.posts.create({ content: 'Hello!' });
} catch (error) {
if (error instanceof AuthenticationError) {
console.error('Invalid API key — check your key at posteverywhere.ai/developers');
} else if (error instanceof RateLimitError) {
console.error('Rate limited, retry after:', error.retryAfter, 'seconds');
} else if (error instanceof ValidationError) {
console.error('Bad request:', error.details);
} else if (error instanceof InsufficientCreditsError) {
console.error('Not enough AI credits — upgrade or wait for monthly reset');
} else if (error instanceof PostEverywhereError) {
console.error('API error:', error.message, error.requestId);
}
}
Every error includes a retryable boolean — use it instead of inferring retry behavior from status codes.
const client = new PostEverywhere({
apiKey: 'pe_live_...', // Required
timeout: 120000, // Default: 120s (AI generation can be slow)
maxRetries: 2, // Default: 2 — automatic retry on 429/5xx with backoff
});
| Resource | Per minute | Per hour | Per day |
|---|---|---|---|
| General API calls | 60 | 1,000 | — |
| Posts | 60 | 200 | 1,000 |
| AI generation | — | 60 | — |
The SDK auto-retries on 429 with exponential backoff, respecting the Retry-After header. See Rate Limits for the full breakdown.
All 12 platforms work on every plan, with no per-network add-ons:
retryable flagEvery plan includes every platform — these are the per-platform landing pages:
@posteverywhere/mcp — MCP server for Claude Code, Claude Desktop, and Cursor (npm)MIT — see LICENSE.
Built by the team at PostEverywhere. The smarter way to schedule social media posts to Instagram, TikTok, YouTube, LinkedIn, Facebook, X, Threads, Pinterest, Bluesky, Telegram, Discord and WordPress from one place.
FAQs
Official PostEverywhere Node.js SDK: schedule and publish posts to Instagram, TikTok, YouTube, LinkedIn, Facebook, X (Twitter), Threads, Pinterest, Bluesky, Telegram, Discord and WordPress from code or AI agents.
The npm package @posteverywhere/sdk receives a total of 167 weekly downloads. As such, @posteverywhere/sdk popularity was classified as not popular.
We found that @posteverywhere/sdk demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Research
/Security News
Tensorlake npm SDK version 0.5.144 was compromised in a ChainDrop / Shai-Hulud attack, delivering credential-stealing malware.

Research
/Security News
Socket found 16 malicious Firefox extensions designed to steal crypto wallet recovery phrases and private keys using cloned Rabby and OKX interfaces.

Product
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.