Connecting AI Agents

Let Claude or any MCP-compatible agent use your fewer.photos account — browse your feed, post your frame, and manage your profile.

fewer.photos speaks MCP (Model Context Protocol), the open standard AI tools use to work with apps on your behalf. Connect an agent and it can do what you do — read your Home feed, browse Discover and Featured, post your frame for the cycle, like, follow, comment, and handle your follow requests — as you, with your permission, under the same rules.

There are no API keys to create or paste. Connecting is a consent screen, and disconnecting is one click in Settings.

The app has its own summary of all this at fewer.photos/agents, including the current list of what an agent can and can’t do. This page covers the same ground in more detail.

Connecting

Point any MCP-compatible client at:

https://fewer.photos/api/mcp
  • Claude.ai — Settings → Connectors → Add custom connector, then paste the URL.
  • Claude Codeclaude mcp add --transport http fewer-photos https://fewer.photos/api/mcp
  • Any other MCP client that supports remote servers works the same way.

The client sends you to fewer.photos, where you sign in with your usual magic link if you aren’t already, and land on a consent screen.

The screen tells you three things:

  • What the app calls itself. App names are self-reported — fewer.photos can’t verify them, so check the return address shown below the name before approving.
  • Where you’ll be sent back to. For Claude, that’s claude.ai.
  • What you’re granting. By default a connection is read-only: the agent can look at everything you can see, and change nothing. Ticking “Allow posting and making changes on your behalf” is what lets it post, like, follow, comment, and edit your profile. Leave it unticked if you only want an agent that can look things up.

What a Connected Agent Can Do

With full access, an agent can do nearly everything you can do in the app, and nothing you can’t. It posts into the same one-frame-per-cycle limit, its comments are follow-gated like yours, its captions can’t contain links, and it shares your rate limits.

Reading, available to every connection:

  • Your Home feed, Discover, and the Featured wall
  • Anyone’s profile and the frames of theirs you’re allowed to see
  • A single frame with its likes and its comment thread
  • Who you follow, who follows you, and who’s waiting for approval

Every frame an agent reads reports which cycle it belongs to, including its color, so an agent can answer “show me everything I posted in the indigo cycle last week”.

Changing, only if you allowed it:

  • Post your frame for the current cycle
  • Like and unlike, follow and unfollow, comment and delete comments
  • Approve or deny a follow request
  • Change who can see one frame, or your whole account
  • Edit your bio, website, handle, and email settings

Two things are off the table no matter what you grant: an agent can never delete your account, and it can’t change your profile photo. Both stay behind the website’s own confirmation screens.

Agents and Privacy

An agent connection is bound to you, so it sees exactly what you see and nothing more. A private account you haven’t been approved for is as invisible to your agent as it is to you.

Three details are worth knowing if you run a private account:

  • Asking to follow someone private is a request, not a follow. An agent that follows a private account is told the request is pending, so it won’t report access it doesn’t have.
  • Your agent can work your request queue. It can list who’s waiting and approve or deny them by handle. Denying removes the request and records nothing, the same as denying it yourself.
  • It can set visibility per frame, or for the account. An agent can post a frame private, flip an existing frame public or private, or set it back to matching your account default. The account-wide switch behaves exactly as it does in Settings: going private makes past frames followers-only unless they were explicitly set public, and going public approves everyone already waiting.

None of this is a separate permission. It’s all part of “allow posting and making changes”, so grant that only to an agent you’d trust with the switch itself.

Managing and Revoking

Settings → Connected agents lists every app you’ve approved, with when you connected it and when it last did anything. Revoke severs the connection immediately — the agent’s access dies with it, and reconnecting means going through consent again from the start.

Without an Agent

Some things are just addresses, and anything that can fetch a URL can use them — no MCP client, no connection, no consent screen. Your contact sheet and the ambient display are both plain image URLs, and the RSS feeds are plain XML.