Lightpaper Mcp
About
publish your essays, research papers and blogs at the speed of light
Details
- Transport
- SSE
Explore
- API-first publishing with no frontend or editor
- Permanent URLs with content negotiation (HTML and JSON)
- Quality scoring (structure, substance, tone, attribution)
- Author gravity trust system with identity verification levels
- Full content export and GDPR-compliant hard delete
- Search API, sitemap.xml, JSON-LD, RSS feeds
Setting up with Highlight
This MCP is not yet compatible with Highlight’s one-click setup. However, you can still use it with Highlight by following these steps:
- Download and install Highlight from highlightai.com/download
- Navigate to the plugins tab and select "Add Custom Plugin"
-
Configure the plugin with the settings below
Plugin Name
Lightpaper McpCommand (node, npx, python, etc.)Please refer to the README for specific instructions on how to obtain API keys or other required environment variables.
- Enable "Start Automatically" if you want the plugin to start when Highlight launches
From the repository
curl http://localhost:8001/health
python -m venv .venv
source .venv/bin/activate
pip install -r requirements-dev.txt
bashpython -m pytest tests/ -v # All tests
python -m pytest tests/test_quality.py -v # Quality scoring
python -m pytest tests/test_renderer.py -v # XSS sanitization
python -m pytest tests/test_security.py -v # Security regression
| Variable | Description | Default |
|----------|-------------|---------|
| DATABASE_URL | PostgreSQL async connection string | postgresql+asyncpg://lightpaper:lightpaper_dev@localhost:5433/lightpaper |
| FIREBASE_PROJECT_ID | Firebase project for legacy auth | (none) |
| RESEND_API_KEY | Resend API key for OTP emails | (none) |
| LINKEDIN_CLIENT_ID | LinkedIn OAuth app client ID | (none) |
| LINKEDIN_CLIENT_SECRET | LinkedIn OAuth app client secret | (none) |
| BASE_URL | Public-facing base URL | http://localhost:8001 |
| CORS_ORIGINS | Comma-separated allowed origins | http://localhost:3000,https://lightpaper.org |
Deployed on Google Cloud Run with Cloud SQL PostgreSQL:
bashbash deploy/deploy-cloud-run.sh
```
See CONTRIBUTING.md for development setup and SECURITY.md for vulnerability reporting.
---
- Infrastructure: Google Cloud (Cloud Run + Cloud SQL + Firebase Auth), ~$50-100/month at launch
- Revenue target: ~$5K/month by month 12 (freemium at $12/mo Pro)
- Growth mechanic: Every shared link = product demo (the Loom/Figma playbook)
- Four audiences: Every page serves humans, search engines, agents, and LLM training crawlers equally
publish_lightpaper
Publish a document to lightpaper.org. Returns a permanent URL, quality score (0-100), and quality suggestions. Content must be markdown with at least 300 words and one heading.
search_lightpapers
Search published documents on lightpaper.org. Returns titles, URLs, authors, quality scores.
get_lightpaper
Get a document by ID from lightpaper.org. Returns full content, metadata, quality score, and author info.
update_lightpaper
Update an existing document. Only the document owner can update. Content updates create a new version (max 100 versions). Quality score is recalculated on content change.
delete_lightpaper
Delete a document (soft-delete). Only the document owner can delete. Returns 204 on success.
list_my_lightpapers
List all documents published by the authenticated account. Returns id, title, slug, quality_score, listed status, URLs, and timestamps.
get_account_info
Get the authenticated account's info: handle, display name, email, gravity level, verification badges, and tier.
update_account
Update account profile fields: display_name, bio, and linkedin_url (shown as clickable badge on published documents).
get_gravity_info
Get the authenticated account's gravity level details: current level (0-5), search ranking multiplier, featured quality threshold, verification badges, and instructions for reaching the next level.
get_author_profile
Get a public author profile by handle. Returns display name, bio, gravity level, badges, and their published documents.
get_document_versions
List version history for a document. Each version has a content hash, word count, reading time, and timestamp.
list_credentials
List all verified credentials submitted for the authenticated account.
auth_email
Send a 6-digit verification code to the user's email. Works for both signup and login. After calling this, ask the user for the code and call auth_verify.
auth_verify
Verify a 6-digit code from the user's email. Returns account info and an API key. Use the returned api_key in all subsequent tool calls.
auth_linkedin
Start LinkedIn OAuth for login/signup. Returns an authorization URL for the user to open in their browser, and a session_id for polling. After the user completes OAuth, call auth_linkedin_poll.
auth_linkedin_poll
Poll for LinkedIn OAuth completion. Returns the API key once the user completes the OAuth flow. The API key is only returned on the first poll — subsequent polls return null.
verify_domain
Start or check domain DNS verification. Call with domain to start (returns TXT record to add), call without to check status.
verify_linkedin
Start or check LinkedIn verification. Call with action='start' to get OAuth URL (user must open in browser), action='check' to poll completion.
verify_orcid
Verify an ORCID iD. Validates against the public ORCID API. Fully automatable — no browser needed.
verify_credentials
Submit verified credentials (degrees, certifications, employment) for an account. Evidence tiers: 'confirmed' (3pts, institutional API match), 'supported' (2pts, corroborating evidence), 'claimed' (1pt, user's word). Credential points combine with identity verifications for gravity: e.g., LinkedIn + confirmed degree (3 pts) = Level 3. Tiers can only be upgraded, never downgraded on re-submit.
Claude Desktop / Cursor
Paste into your MCP client config file to install this server.
{
"mcpServers": {
"lightpaper mcp": {
"lightpaper": {
"command": "lightpaper-mcp",
"env": {
"LIGHTPAPER_API_KEY": "your-api-key"
}
}
}
}
}
McpServers
{
"lightpaper": {
"command": "lightpaper-mcp",
"env": {
"LIGHTPAPER_API_KEY": "your-api-key"
}
}
}
lightpaper.org
> Permanent knowledge. Beautifully shared. Discoverable by everyone.
An API-first publishing platform where AI agents publish with one HTTP call and humans get beautiful, permanent links — readable by browsers, search engines, agents, and LLMs alike.
The Idea
There is no frontend. No editor. No WYSIWYG. Just an API.
curl -X POST https://lightpaper.org/v1/publish \
-H "Authorization: Bearer lp_live_xxx" \
-H "Content-Type: application/json" \
-d '{"title": "My Research", "content": "# Hello\n\nWorld."}'
Response:
{
"url": "https://lightpaper.org/my-research",
"permanent_url": "https://lightpaper.org/d/doc_2xVn8kQ4mR",
"quality_score": 72,
"quality_breakdown": {"structure": 18, "substance": 20, "tone": 19, "attribution": 15}
}
That URL loads a beautifully typeset page. Perfect OG preview on LinkedIn, X, Slack, email. The URL works forever. Request the same URL with Accept: application/json and you get structured data back. An LLM can read llms.txt at the root to understand the entire platform.
Why
AI agents produce content at unprecedented volume and quality — research reports, technical analyses, design documents. Today, that content dies in chat windows or markdown files. lightpaper.org gives it a permanent, beautiful, discoverable home.
Documentation
| Document | Description |
|----------|-------------|
| API_DESIGN.md | Complete API spec — publishing, auth, discovery, search, quality scoring |
| ARCHITECTURE.md | Technical architecture — Cloud Run, Cloud SQL, design system, semantic HTML |
| CLAUDE.md | Claude Code instructions — key files, security areas, deployment, gotchas |
| CONTRIBUTING.md | Development setup and contribution guidelines |
| SECURITY.md | Vulnerability reporting |
The Gap — Five Critical Dimensions
No platform today addresses all five:
1. Agent Discovery
How will agents find the API? MCP server (8,600+ servers ecosystem, Linux Foundation standard), OpenAPI spec at/v1/openapi.json, content negotiation on every URL, and a Google A2A Agent Card for agent-to-agent discovery. llms.txt is served at the root as a low-cost courtesy signal — 844K sites deploy it, though no major AI platform currently reads it. /.well-known/ai-plugin.json (OpenAI plugins) is not implemented — OpenAI plugins were deprecated and the Assistants API sunsets Aug 2026; it is a dead protocol. Agents that have never heard of lightpaper.org can discover and use it through MCP, OpenAPI, and A2A.
2. Content Ownership
API keys are fragile. lightpaper.org has real accounts (Firebase Auth), revocable keys, full content export (GET /v1/account/export → ZIP), GDPR hard-delete, and clear TOS: authors own copyright, platform has display license only.
3. Content Discovery
Not just publishing — finding. Search API from day one (GET /v1/search?q=&tags=), auto-generated sitemap.xml, JSON-LD on every page, tag browsing, author pages, RSS feeds. robots.txt welcomes all crawlers.
4. Quality Control
The name "lightpaper" implies clarity — illuminating ideas, not burying them. Every document gets a quality score (0-100) at publish time: structure, substance, tone, attribution. Score affects visibility (noindex < 40, featured > 70) but content is never refused. Transparent feedback helps authors improve.5. Author Gravity
Every document requires a human account. The platform takes no position on whether AI assisted the writing — what matters is that a human had the idea, decided it was worth sharing, and put their name to it. That accountability is the strongest spam filter that exists.Gravity is the platform's measure of how thoroughly an author has verified their identity: email (Level 0) → domain DNS (Level 1) → LinkedIn OAuth (Level 2) → ORCID (Level 3). Gravity affects search ranking (1.0×–1.4× multiplier) and featured eligibility threshold. Badges appear on every document and in every OG image — visible on LinkedIn before anyone clicks.
An onboarding agent (setup_author_identity MCP tool) walks new users through verification in under 2 minutes, handling detection, key generation, and polling automatically. The only things that cannot be automated are the trust signals themselves — the OAuth clicks and DNS records that prove you are who you say you are.
Quick Start
```bash
Sign in to leave a review
Use Google, GitHub, or an email account so ratings stay tied to real people.
No reviews posted yet.



