Syndroodocs

Platforms

Five official providers ship with the candidate: Bluesky, Threads, LinkedIn and Mastodon publish text, and DEV.to publishes articles. Each has its own guide, and each guide states only what the provider's source and the recorded provider evidence support.

No live call has been made.

Every provider here is fixture-tested against recorded API evidence. No Syndroo account has been connected and no post has been published to a real account from this project, so "the code supports it" is not "your account accepts it".

The five providers

ProviderContentCredential fieldsDeclared egress
BlueskyText postidentifier, passwordhttps://bsky.social
ThreadsText postclient_id, client_secrethttps://www.threads.net, https://graph.threads.net
LinkedInMember text postclient_id, client_secrethttps://www.linkedin.com, https://api.linkedin.com
MastodonPublic status textNone: the flow is browser authorizationFederated: the instance you name
DEV.toArticleapiKeyhttps://dev.to

"Declared egress" is the origin list a provider writes in its manifest. The runtime builds the outbound allowlist from that declaration, so a provider cannot quietly call a host it did not declare. Build explains the rule.

Provider ids

A request names the provider with its id, and the id is also the package name suffix and the registry key: bluesky, threads, linkedin, mastodon and devto. The display name is only presentation.

Unresolved before these guides are complete

This page does not paper over the gaps in the recorded evidence. The following are marked UNRESOLVED in the guides and must be re-verified against the provider before they are presented as fact:

  • Bluesky: the exact settings path for creating an app password.
  • Threads: whether the API host is graph.threads.net or graph.threads.com, the text limit, the error table and the revoke flow.
  • LinkedIn: the commentary length limit, the error format and the token revocation procedure.
  • Mastodon: the full error entity and each instance's own character limit.
  • DEV.to: the API-key issuance and regeneration path, and the v1 rate limits.