AI & Agents Watch / Applications
In Brief
Metanet.page has added a Model Context Protocol endpoint that allows external AI agents to operate selected parts of a user’s social account through a time-limited, revocable authorization token rather than by handing the platform the user’s private key.
The current MCP interface lets compatible agents including Claude, ChatGPT, Cursor and other MCP clients search and read the Metanet feed, manage selected profile information, publish posts and replies, repost content, add reactions and inspect account activity. Actions are performed under the user’s account and remain subject to Metanet’s existing application rules.
The authorization token can last for no more than 30 days and can be revoked by the user. Metanet says the underlying private key does not reach its server during the browser-based token-minting process.
The current MCP interface does not expose payments or tips, on-chain minting, username transfers, premium-username management, apps or administrative functions, keeping agent access narrower than the wider Metanet developer SDK.
News Report
Metanet.page has opened part of its social platform to external AI agents through a new Model Context Protocol interface, allowing users to delegate selected account actions through revocable, time-limited credentials.
The system is designed around a distinction between giving an AI access to an application and giving that AI direct possession of the user’s underlying private key.
A signed-in Metanet user can mint an agent-access token in the browser and provide that token to a compatible MCP client. The agent then authenticates to Metanet through the MCP endpoint using the temporary credential while the private key itself remains outside the server.
Metanet describes the interface as suitable for Claude, ChatGPT, Cursor and other MCP-compatible clients or custom agents.
A Social Account an Agent Can Operate
The current MCP toolset gives agents substantial control over the social layer without exposing the full Metanet wallet environment.
Agents can retrieve platform capabilities, search posts, perform semantic searches by meaning, inspect trending posts, retrieve posts and comments, and list a user’s own posts, comments and sent tips.
Write access extends to several common social actions. An authorized agent can create posts and replies, repost existing material, delete the user’s own unminted posts and add or remove reactions such as likes, love, laughter, sadness or surprise.
Profile functions include reading the user’s profile, looking up other users, changing a short biography, selecting an active username and managing free usernames. Premium usernames remain outside the agent-access surface.
The practical result is that an AI agent can act as a social assistant inside Metanet rather than merely analyze exported content.
Temporary Authority Instead of the Private Key
The authorization model is one of the more important parts of the implementation.
Metanet’s documentation says a user can mint a time-limited MCP session token in the browser. The token is signed with the user’s key, but the private key itself does not leave the device during that process.
The resulting token is then supplied to the MCP client as a bearer credential.
Token lifetime is capped at 30 days. Users can revoke access before expiry, and Metanet says revocation invalidates tokens minted before that point, including renewed tokens derived from the same authorization.
Optional renewal can be enabled when a token is created, allowing the agent to keep a session alive while remaining bounded by the original authorization period and revocation controls.
This does not make the AI client itself trusted. A valid bearer token is still an authorization credential and must be protected accordingly. The design instead limits what has to be delegated: the agent can receive temporary application authority without necessarily receiving the user’s long-term private key.
Rate Limits Bound Automated Activity
Metanet also applies explicit limits to agent activity.
The current documentation sets ceilings of approximately:
- 120 reads per minute
- 30 writes per minute
- 20 posts per hour
- 120 reactions per hour
These limits matter because an AI agent can act more quickly than an ordinary human user.
Without application-level controls, a mistaken instruction or poorly behaved agent could generate large numbers of posts or reactions in a short period. Rate limiting therefore becomes part of the authorization model rather than merely an anti-spam measure.
Metanet also warns users that anything an agent writes through the account is public under that user’s name, placing responsibility on the account holder to decide what kind of agent behavior should be authorized.
Signed Posts Remain a Separate Layer
Metanet also distinguishes between an agent that merely possesses an MCP token and an agent that actually possesses the user’s signing key.
Posts can optionally carry a creator signature that the application verifies.
An agent that holds the underlying key can construct and sign that message itself. An agent operating only with the temporary MCP token cannot produce that signature on its own; instead, the resulting post can remain available for the user to sign separately.
That creates another useful boundary between permission to act through the account and ability to produce a cryptographic signature as the account owner.
The two capabilities do not automatically travel together.
The MCP Surface Is Intentionally Narrower Than Metanet’s SDK
Metanet’s broader developer environment exposes considerably more functionality than the MCP interface.
Its Shuriken SDK is described as supporting identity, feed posts, transactions, zero-knowledge proofs, geolocation, QR functions and payments involving BSV tokens, ICP and KDA. npm
The new MCP interface deliberately exposes only part of that capability set.
Payments and tips are not available to agents through the current MCP tools. Neither are on-chain minting, username transfers, premium-username management, application administration or general app execution.
That distinction means the current release should not be interpreted as allowing AI agents to autonomously spend BSV tokens from a Metanet wallet.
The agent can operate the social account, while financial and higher-authority actions remain outside the MCP boundary.
A Multi-Chain Platform With a BSV Layer
Metanet itself is broader than a BSV-only application.
The platform presents a self-managed wallet architecture spanning BSV Blockchain, Internet Computer and Kadena, while its developer SDK allows applications to request identity and payment capabilities across those environments.
The new MCP interface sits above that broader architecture.
For BSV TIMES, the relevant development is therefore not that Metanet has turned the BSV wallet into an autonomous agent wallet—it has not.
The more precise development is that a platform already supporting BSV Blockchain has introduced a controlled way for external AI systems to act on behalf of a user without exposing all of the underlying wallet capabilities.
MCP Turns Social Functions Into Agent Tools
Model Context Protocol provides a standardized way for AI clients to discover and call external tools rather than relying on screen scraping or one-off integrations. The official MCP project describes the protocol as a common interface connecting AI applications with external data sources and tools. GitHub
Metanet applies that model directly to a live social account.
Instead of teaching each AI client how to automate the Metanet web interface, the platform exposes structured operations such as search, profile lookup, post creation, replies and reactions through an MCP endpoint.
The agent can therefore interact with the application at the tool layer rather than pretending to be a person clicking through the user interface.
Another Model for Bounded Agent Authority
The implementation also fits a broader pattern emerging across agent-oriented BSV development, although Metanet’s MCP system is independent of wallet standards such as BRC-181.
The recurring problem is the same: giving software enough authority to do useful work without giving it unrestricted control over everything the user owns.
BRC-181 approaches that problem at the wallet layer by defining bounded spending authority for unattended agents.
BitPlan separates agent collaboration from wallet-authorized permanent publication.
Metanet is taking an application-level approach: a temporary token grants a defined set of social capabilities, while payments, minting and other higher-authority functions remain outside the current agent interface.
These systems are not implementations of the same standard, but they illustrate a common architectural direction: delegate the capability required for a task rather than hand the agent the user’s entire authority.
BSV TIMES Read
The significant part of Metanet’s MCP release is not simply that an AI can publish a social-media post.
Browser automation could already make software click buttons, fill forms and imitate human interaction.
The more important development is that Metanet has created a formal authorization layer specifically for agents.
A user can issue a temporary credential, allow the agent to operate a defined application surface, impose rate limits and revoke that authority without replacing the underlying identity key.
At the same time, the current design draws a meaningful boundary around what the agent cannot do. Social posting and account interaction are exposed; payments, tips, on-chain minting and other higher-authority operations are not.
That boundary may become more consequential than the individual MCP tools themselves.
As AI systems become capable of acting continuously on behalf of users, application design increasingly has to answer two different questions: what can the agent technically do, and what should the agent be authorized to do?
Metanet’s current implementation keeps those questions separate.
The AI gets enough authority to participate in the social platform, while the wallet and more sensitive financial functions remain outside that delegated surface.
That is a more useful model of agent integration than simply giving software access to everything the user can access.
Developer Context
ModernDeucalion
ModernDeucalion is the public founder and creator of Metanet.page, which evolved from the earlier Metanet.ninja social platform.
Related development includes:
- Metanet.page — the current multi-chain social and application platform
- Shuriken SDK — Metanet’s official developer SDK for identity, feed actions, BSV/ICP/KDA payments, transactions, ZK proofs and other application capabilities
- Metanet MCP — the new revocable agent-access layer covered in this report
The Shuriken SDK is published on npm under the metanet-platform developer identity. npm
Source Links
Metanet.page — Developer Documentation
Model Context Protocol — GitHub
Posted on October 4, 2026

Leave a comment