# Linkvue API and MCP documentation

Linkvue is a link in bio platform for creators, with customizable pages, link analytics, custom domains and controls that protect creator links from automated scraping.

## Public endpoints

GET https://linkvue.uk/api/agent returns service metadata. GET https://linkvue.uk/api/agent/resources lists documentation resources. GET https://linkvue.uk/api/agent/resources/{name} reads one resource: docs, instructions or openapi. These read-only endpoints require no authentication. Each resource contains a resolvable uri, mimeType and nonempty text.

The [OpenAPI 3.1 specification](https://linkvue.uk/openapi.json) describes these REST operations with typed inputs and responses. Linkvue account automation uses MCP rather than a public GraphQL API. There is no public GraphQL introspection endpoint.

Example request:

```sh
curl -sS -i https://linkvue.uk/api/agent
curl -sS https://linkvue.uk/api/agent/resources/docs
curl -sS -H 'Accept: text/markdown' https://linkvue.uk/
```

## MCP connection

The public documentation server is https://linkvue.uk/mcp. It uses Streamable HTTP and exposes get_linkvue_documentation plus resources/list and resources/read. No credentials are needed. This is a read-only test surface with no creator data or write operations.

For account automation, connect your MCP client to https://mcp.linkvue.uk/mcp. It supports public discovery, but account tool calls require OAuth. A 401 response includes WWW-Authenticate with the protected-resource metadata URL. Follow that metadata to the authorization server and complete sign-in and consent in the account owner's browser. Clients should use OAuth discovery rather than hardcode token endpoints. Account approval, plan entitlements and per-tool permissions still apply.

After initialize and notifications/initialized, call tools/list for the current schemas. Use get_profile to inspect the account's default page, list_links to read its links, and get_analytics to read permitted metrics. Obtain the creator's approval before calling tools that publish, delete or change content. Owner-only admin tools are a separate restricted service.

For HTTP POST requests, send Content-Type: application/json and Accept: application/json, text/event-stream. Send the negotiated MCP-Protocol-Version on subsequent requests. The transport is stateless. Clients must support JSON and SSE responses. A GET may return 405 when the server does not provide an unsolicited event stream.

```sh
curl -sS https://linkvue.uk/mcp -H 'Content-Type: application/json' -H 'Accept: application/json, text/event-stream' --data '{"jsonrpc":"2.0","id":1,"method":"initialize","params":{"protocolVersion":"2025-11-25","capabilities":{},"clientInfo":{"name":"example","version":"1.0.0"}}}'
```

## Authentication and onboarding

Public documentation and protocol discovery are free and require no account or API key. Join the [waitlist](https://linkvue.uk/#waitlist) for product access. Existing users can [sign in](https://app.linkvue.uk/login) and connect an assistant through the dashboard. Production account access is subject to approval and plan entitlements. Linkvue does not currently offer a public account-write sandbox or self-serve developer API keys.

## Rate limits

Public documentation API and public MCP calls share a 120-request, 60-second allowance per client address per server instance. It is a burst limit, not a global quota. Authenticated MCP uses a shared database counter of 120 requests per 60 seconds per credential; unauthenticated requests to that endpoint use the client address.

Responses include RateLimit and RateLimit-Policy in the IETF HTTPAPI structured-field format, plus RateLimit-Limit, RateLimit-Remaining and RateLimit-Reset for compatibility. Reset values are seconds until the current window ends. The structured field format is an IETF draft, not a finalized RFC. A 429 also includes Retry-After in seconds. Wait at least that long before retrying. Do not automatically repeat a write whose outcome is unknown.

## Errors

REST failures use RFC 9457 application/problem+json. Read status, code, detail and resolution. Codes include not_found, method_not_allowed, not_acceptable, unauthorized and rate_limit_exceeded. MCP protocol errors retain their JSON-RPC envelope; application tool failures use isError. A transport error does not imply a tool ran.

## Command line

The repository contains the official read-only CLI in packages/cli. Run npm run build --prefix packages/cli, then node packages/cli/dist/index.js info. Other commands are docs, schema, resources and resource NAME. Registry installation instructions will be published after an npm package is released.

## Related resources

- [Agent instructions](https://linkvue.uk/agent.txt)
- [About Linkvue](https://linkvue.uk/about)
- [Contact](https://linkvue.uk/contact)
- [Privacy](https://linkvue.uk/privacy)
