github gitroomhq/postiz-app v2.25.0
Preview comments, self-hosted MCP connector, responsive app & 50+ provider fixes

8 hours ago

Highlights

This release brings inline comments on post previews (with replies, resolving and anonymous commenting), a self-hosted MCP connector so a self-hosted Postiz can be used from the Postiz Cloud Claude connector, a responsive layout pass across the app, and renaming channel groups. Instagram Reels and TikTok videos now get proper cover images, and a large sweep of provider fixes turns dozens of "Unknown Error" failures into readable, correctly retried or non-retried errors.

Important

This release changes the Prisma schema (new columns on Comments, a new OAuthSelfHostedAuthorization table, new indexes) and adds optional environment variables. No Temporal workflow versions changed. See Upgrade notes.

✨ Features

Preview comments

  • Inline comments on the post preview page — select text to anchor a comment to it, reply in threads, resolve comments, and let people without a Postiz account comment anonymously (#2079)
  • Optional invisible reCAPTCHA v2 on anonymous comments (RECAPTCHA_SITE_KEY / RECAPTCHA_SECRET_KEY)
  • Live cursor highlighting on the preview page

MCP / agents

  • Self-hosted connector — the MCP consent screen gets a "Use self-hosted" option: Postiz Cloud relays the connection's tool calls to your own Postiz instance using its API key (enabled on the cloud with MCP_SELF_HOSTED_RELAY; leave unset on self-hosted installs)
  • The schedule-post tool now returns a previewUrl for every created post, so the agent can share a link to it
  • New GET /public/v1/me endpoint returns the organization and, for OAuth app tokens, the user who approved the connection
  • OAuth token endpoint now answers 200 (RFC 6749) so strict clients like Canva accept it, and a new CANVA_APP_ORIGIN CORS setting for running your own Postiz Canva app

App

  • Responsive layout across the launch modal, analytics, plugs, public API, third-party and media screens
  • Rename a channel group from the channel menu (#2183)
  • Instagram Reels: a custom thumbnail is used as the reel cover (#1855)
  • TikTok: video cover timestamp is sent on Direct Post video uploads (#2174)
  • Facebook: optional title for feed video posts (#2155)
  • Admin stats now show connected clients

🛡️ Reliability

  • Media reads can no longer hang a publish — reads that stall after the headers are bounded (two minutes before being treated as stalled), fail instead of repeating the publish, and go through the SSRF-safe client (#2193)
  • TikTok analytics: the public post id is resolved and persisted for FILE_UPLOAD and photo posts, keeping the full id instead of a rounded number (#2180, #2182, #2186)
  • Local-storage uploads honor HTTP Range requests again, so video uploads work on local storage (#2095), and an over-long Range end is clamped instead of answering 416
  • A failed token refresh sends a single notification instead of duplicates (#1678)
  • Sentry SDK pinned to 10.56.0 to pick up the span/scope leak fix (#2101)

🔌 Provider fixes

  • Instagram: curated container processing errors (2207082 silent-video hint, 2207085 video format), disconnect the channel on Meta checkpoint and disconnect-mapped container errors (#2123, #2137, #2152)
  • Facebook: five recurring Graph API rejections mapped instead of "Unknown Error", subcodes matched on word boundaries, temporary posting-rate block (368 / 1390008) retried, clean reconnect failure when the page has no page token (#2127, #2144, #2167)
  • X: readable messages for remaining known errors and exhausted rate-limit retries, channel marked for reconnect on Unauthorized media uploads (#2130, #2132, #2133)
  • Threads: retry publish when the container is not found yet (4279009), friendly message for UNKNOWN container errors (#2124, #2150)
  • Pinterest: board validated as a numeric id with the board-name rejection mapped, "not permitted to access that resource" mapped (#2125, #2129, #2179)
  • Reddit: retry the submit after a RATELIMIT rejection, only when it is the sole error (#2126)
  • Telegram: 400 rejections mapped to non-retryable errors; post text no longer logged on publish (#2140, #2166)
  • Nostr: hex private key converted to bytes before signing posts (#2141)
  • VK: API errors surfaced instead of marking posts completed (#2131)
  • Lemmy: API errors surfaced instead of crashing; community search routed through the provider fetch (#2128)
  • Dribbble: 4xx shot rejections mapped to non-retryable errors (#2134)
  • WordPress: requests send a Postiz User-Agent (#2172)
  • LinkedIn / Moltbook: settings DTOs wired correctly, Moltbook submolt kept optional (#1880)

🐛 Fixes

  • Uploads: one failed file no longer drops the rest of the batch, in-flight uploads are not wiped when an earlier one finishes, uploads are cancelled cleanly on error, and the upload step fails when the backend returns an error (#2145, #2149, #2163, #2171, #2177)
  • Posts: a failed save is no longer reported as successful (#2161); the edit modal closes instead of crashing when the post's channel is not loaded (#2178); opening a calendar tile whose post group was deleted no longer crashes (#2146)
  • Billing / payments: clear message when Stripe.js fails to load (#2151); the 402 payment dialog tolerates non-JSON bodies, keeps you on Add Channel when cancelled, and stops the web3, custom-fields and extension connect flows (#2159)
  • Auth: activation no longer reads the response body after the onboarding redirect started (#2153)
  • Tags: deleting a tag cleans up its post assignments, and soft-deleted tags no longer match (#1827)
  • Browser extension: guard the chrome global and read chrome.runtime.lastError in messaging callbacks (#2143, #2148)
  • React render crashes are reported to Sentry from the crash screen (#2102); noise from uppy, MetaMask and the PostHog recorder no longer opens the Sentry report dialog (#2122, #2142, #2147, #2162)
  • Duplicate 'use client' directive removed from the VK provider (#2164)

Upgrade notes

Database. The Prisma schema changed. If you run the official Docker image, the schema is pushed on startup as usual. Otherwise run pnpm run prisma-db-push. Changes:

  • Comments: userId is now nullable (anonymous comments); new columns displayName, parentId, anchorStart, anchorEnd, anchorQuote, resolvedAt
  • New OAuthSelfHostedAuthorization table
  • New index on UserOrganization.organizationId

New optional environment variables (all can stay unset):

  • RECAPTCHA_SITE_KEY, RECAPTCHA_SECRET_KEY — invisible captcha on anonymous preview comments
  • CANVA_APP_ORIGIN — only if you run your own Postiz Canva app
  • MCP_SELF_HOSTED_RELAY — Postiz Cloud only; leave unset on self-hosted installs

Workflows. No Temporal workflow versions changed in this release.

Full Changelog: v2.24.0...v2.25.0

Don't miss a new postiz-app release

NewReleases is sending notifications on new releases.