Hermoso is a marketing MCP server: 850+ tools over one OAuth’d endpoint that let an agent research the ads already running in a market, generate finished image and video ads, publish them, and build the paid campaigns behind them. OpenClaw reaches all of it through one connection. This page is about one slice of that — what OpenClaw can actually do on Bluesky, and what Bluesky will not let it do.
Connect Hermoso to OpenClaw
- Install and sign in.
Your browser opens once. Nothing to create and nothing to paste: the credential is stored owner-only innpm install -g hermoso && hermoso auth login~/.hermoso/config.json. On a machine with no browser,hermoso auth login --token hmk_…takes a key from MCP & CLI → Terminal & API keys instead. - Add it to
~/.openclaw/openclaw.json. No key goes in the file, becausehermoso mcpreads the sign-in above:{ "mcp": { "servers": { "hermoso": { "command": "npx", "args": ["-y", "hermoso", "mcp"] } } } } - Ask your agent for something. “Pull my three closest competitors’ longest-running ads and remix the best hook into a 9:16 video,” or “post this render to the channel.” The agent picks the tools; you approve the spend.
Hermoso has no special relationship with OpenClaw and does not claim one. The shape above is quoted from OpenClaw's own MCP reference at docs.openclaw.ai/cli/mcp, read on 2026-08-23; it is documented rather than run here, which is why it is the published file shape and not a bespoke install command.
Then connect Bluesky itself, once, under Settings → Connectors in Hermoso, with your handle and a Bluesky app password. There is no consent screen: the app password is made in Bluesky’s own settings, and it can be revoked there without touching your real password.
The Bluesky tools OpenClaw gets
post_to_bluesky— publishes a post as the connected account: up to 300 characters, with up to four images and alt text, or one MP4 video with optional caption tracks. A link with no media gets a preview card, which Hermoso builds because Bluesky does not fetch one.schedule_post— queues it on the calendar every other channel shares, with the 300-character cap checked when it is queued rather than when it fires.list_bluesky_posts— the account’s own recent posts with their AT-URIs and live counts, marking reposts so someone else’s post is never read as yours.bluesky_post_metrics / bluesky_account— likes, reposts, replies, quotes and bookmarks per post, and followers, following and post count for your account or any public one.list_bluesky_convos / read_bluesky_dm / send_bluesky_dm— read and answer direct messages, including message requests from people the account does not follow.manage_bluesky_convo / react_to_bluesky_dm / mark_bluesky_convo_read— accept a request, mute, lock or leave a conversation, react with one emoji, and clear unread counts.delete_bluesky_post— removes a post, after a first call that deletes nothing and reads back what would go.
Bluesky connects with an app password rather than a sign-in screen: create one in Bluesky’s settings and paste it with the handle under Settings → Connectors. Tick direct-message access when you create it, or the DM tools will tell you the password cannot chat, which is a property of the password and not a broken connection. Two more Bluesky rules Hermoso checks before sending: a video needs a confirmed email on the Bluesky account, and a link card and an image cannot share a post. Publishing costs no credits, because Bluesky charges nothing per call.
Bluesky limits worth knowing before you automate anything
| Text | A Bluesky post is capped at 300 characters and, separately, at 3,000 bytes, so an emoji-heavy post can be under 300 characters and still too long. It is enforced when the post is created or queued — refused while you are still there to fix it, rather than silently cut on the way out. |
|---|---|
| Visibility | Public only. A Bluesky post is a public record on the AT Protocol, and there is no unlisted, private or draft form of one. The review happens before the call, never after it. |
| Carousel | 2 to 4 images, images only. Four is Bluesky’s own number, from the AT Protocol lexicon for an image embed, and a fifth is refused rather than dropped. A video is a different embed that carries exactly one clip, and a post has a single embed, so a Bluesky post is images, one video or a link card: one of the three. |
| Which account | None, unless the brand has connected more than one Bluesky account. Then account names which, and several with none named is refused by name rather than guessed. |
Try it in OpenClaw
Ask for it in ordinary language — these are sentences, not a DSL:
“Every morning: read new Bluesky DMs and message requests, summarise who wants what, and draft replies for me to approve before anything is sent.”
That walks get_brand → generate_image → post_to_bluesky → bluesky_post_metrics. How much a run asks you is OpenClaw’s setting, not ours.
OpenClaw on Bluesky: the part that bites
Bluesky DMs need more than the connection that posts. They work only with a privileged app password, one created with direct-message access ticked, and Hermoso says exactly that if the saved one cannot chat. Message requests from people the account does not follow sit in their own folder until accepted, so a morning triage should read both, and send_bluesky_dm always names one recipient; there is no broadcast form.
On a long autonomous loop the hermoso CLI is the token-cheap path — the agent shells out per command instead of carrying an 850+ tool manifest through every turn.
Research Bluesky before you post
There is no Bluesky ad library and no Bluesky search in Hermoso, so competitor research there comes down to one honest thing: bluesky_account reads any public account’s followers, following and post count, which is enough to size a competitor and chart it week by week. Everything else in the research surface (the Meta, Google and LinkedIn ad libraries, organic TikTok, Instagram, YouTube, Reddit and Threads) is unaffected.
The paid half
There is no Bluesky ads product in Hermoso, and we do not imply one. Bluesky here is organic: publish, schedule, read, reply and measure. The paid tools cover Meta, Google Ads, Microsoft Advertising, Reddit Ads, LinkedIn, Pinterest, X Ads, TikTok Ads, Snapchat Ads, ChatGPT Ads and Apple Search Ads.
What OpenClaw cannot do on its own
An agent with a budget is only useful if the blast radius is bounded, so the fence is in the server rather than in a prompt. Every ad campaign, ad set, ad group and ad is created paused, and the status switches that arm real money refuse to run without an explicit confirmation flag. Every render is quoted first — hermoso_capabilities publishes each model’s exact credit cost before anything spends — and credits are reserved before the first provider call and settled at the exact cost afterwards, so a failed dispatch refunds rather than leaving you billed for nothing. Deletes are confirm-gated too, and every campaign tree is read back from the ad platform before your agent tells you what it built.
One step is deliberately yours: creating the Bluesky app password and connecting it once. Everything after that is a tool call.
The rest of the matrix
From OpenClaw, post to: Facebook · Instagram · Threads · TikTok · YouTube · X · LinkedIn · Pinterest · Telegram — or see everything OpenClaw can publish to.
Post to Bluesky from: Claude · ChatGPT · Claude Code · Cursor · Codex · Cline · Grok Bot · Hermes · Gemini CLI · Perplexity · Le Chat
Frequently asked questions
Can OpenClaw post to Bluesky?
Yes, through Hermoso's MCP server. Run npm install -g hermoso && hermoso auth login, then add hermoso under mcp.servers in ~/.openclaw/openclaw.json with command npx and args -y hermoso mcp. The browser sign-in stores the credential, so no key goes in the file. OpenClaw then has 850+ tools, including the ones that publish to Bluesky — and the ones that research the ads already running in your market and render the creative in the first place.
How do I connect Bluesky to OpenClaw?
Two steps, once each. Run npm install -g hermoso && hermoso auth login, then add hermoso under mcp.servers in ~/.openclaw/openclaw.json with command npx and args -y hermoso mcp. The browser sign-in stores the credential, so no key goes in the file. Then create an app password in Bluesky's settings (tick direct-message access if you want the DM tools) and paste it with your handle under Settings → Connectors in Hermoso. After that OpenClaw publishes to Bluesky as an ordinary tool call.
Can OpenClaw post privately or as a draft to Bluesky?
No. A Bluesky post is a public record on the AT Protocol, with no unlisted, private or draft form, so the review belongs before the call. Hermoso refuses a visibility Bluesky cannot honour at the moment you ask for it, rather than quietly publishing something weaker.
What does it cost to post to Bluesky from OpenClaw?
Publishing to Bluesky costs no credits; Bluesky charges nothing per call. Credits are spent on generating the creative. Plans are $19, $49 and $149 a month for 1,000, 3,000 and 10,000 credits, and every feature is on every plan including Free — the only exception is enterprise SSO.
Start free — 30 credits at signup and 250+ more to earn, and every feature on every plan. Credits are spent only on AI models and Ad Spy research; posting, scheduling, ads management and analytics are free.
Start free → See pricing