Back to Browse

Secondhand MCP Server

Developer ToolsUse Caution3.8MCP RegistryLocal
Free

Server data from the Official MCP Registry

Search Facebook Marketplace, eBay, Depop, and Poshmark from AI — filters, photos, full listings.

About

Search Facebook Marketplace, eBay, Depop, and Poshmark from AI — filters, photos, full listings.

Security Report

3.8
Use Caution3.8High Risk

The Secondhand MCP server implements marketplace search functionality with reasonable security posture for its intended purpose. However, there are notable concerns around credential handling in environment variables passed through config files, browser automation security (Puppeteer with stealth plugins suggests circumventing detection), and incomplete input validation on user-supplied parameters. The server's permissions (network access, browser control, file I/O) are appropriate for its marketplace-scraping purpose, but credential storage practices and browser fingerprinting techniques warrant improvement. Supply chain analysis found 7 known vulnerabilities in dependencies (0 critical, 3 high severity). Package verification found 1 issue.

5 files analyzed · 16 issues found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Required

This plugin requests these system permissions. Most are normal for its category.

env_vars

Check that this permission is expected for this type of plugin.

HTTP Network Access

Connects to external APIs or services over the internet.

process_spawn

Check that this permission is expected for this type of plugin.

File System Read

Reads files on your machine. Normal for tools that analyze or process local data.

File System Write

Writes or modifies files on your machine. Check that this is expected for the tool.

What You'll Need

Set these up before or after installing:

eBay API client ID (only needed for eBay search)Required

Environment variable: EBAY_CLIENT_ID

eBay API client secret (only needed for eBay search)Required

Environment variable: EBAY_CLIENT_SECRET

eBay regional marketplace, e.g. EBAY_US (default)Optional

Environment variable: EBAY_MARKETPLACE_ID

How to Install

Add this to your MCP configuration file:

{
  "mcpServers": {
    "io-github-jlsookiki-secondhand-mcp": {
      "env": {
        "EBAY_CLIENT_ID": "your-ebay-client-id-here",
        "EBAY_CLIENT_SECRET": "your-ebay-client-secret-here",
        "EBAY_MARKETPLACE_ID": "your-ebay-marketplace-id-here"
      },
      "args": [
        "-y",
        "secondhand-mcp"
      ],
      "command": "npx"
    }
  }
}

Documentation

View on GitHub

From the project's GitHub README.

MseeP.ai Security Assessment Badge Verified on MseeP

Secondhand MCP

A Model Context Protocol (MCP) server that lets AI assistants search secondhand marketplaces. Search Facebook Marketplace, eBay, Depop, and Poshmark for used and secondhand items — filter by price, category, condition, size, and color, then get full listing details with photos, descriptions, and seller info.

Works with Claude Desktop, Claude Code, Cursor, and any MCP-compatible client.

[!TIP] Want to skip the setup? Try Secondhand MCP Cloud — the hosted version that connects to Claude.ai and ChatGPT in 30 seconds. No install or Chrome required. Free tier included.

Supported Marketplaces

MarketplaceAuth RequiredNotes
Facebook MarketplaceNoLocation-based search
eBayYes (API keys)Official Browse API
DepopNoRequires Chrome installed
PoshmarkNoRequires Chrome installed

Setup

Claude Desktop

Add to ~/Library/Application Support/Claude/claude_desktop_config.json:

{
  "mcpServers": {
    "secondhand": {
      "command": "npx",
      "args": ["-y", "secondhand-mcp"],
      "env": {
        "EBAY_CLIENT_ID": "your-ebay-client-id",
        "EBAY_CLIENT_SECRET": "your-ebay-client-secret",
        "EBAY_MARKETPLACE_ID": "EBAY_US"
      }
    }
  }
}

Claude Code

Add to ~/.claude/.mcp.json:

{
  "mcpServers": {
    "secondhand": {
      "command": "npx",
      "args": ["-y", "secondhand-mcp"],
      "env": {
        "EBAY_CLIENT_ID": "your-ebay-client-id",
        "EBAY_CLIENT_SECRET": "your-ebay-client-secret",
        "EBAY_MARKETPLACE_ID": "EBAY_US"
      }
    }
  }
}

eBay, Depop, and Poshmark are all optional — if eBay API keys are missing or Chrome isn't installed, those marketplaces are automatically disabled and the rest still work.

Depop & Poshmark / Chrome Requirement

Depop and Poshmark require a headless browser. If Google Chrome or Chromium is installed on your system, both are automatically enabled — no config needed. If Chrome isn't found, they are silently skipped.

On macOS, the first time you search Depop or Poshmark, you may see a system prompt asking to allow Node.js to control Chrome. This is expected — puppeteer needs to launch Chrome in headless mode. Allow it once and it won't ask again.

The browser runs invisibly in the background and only launches when you actually search Depop or Poshmark.

Configuration

Choosing Marketplaces

By default all marketplaces are enabled. To limit which are active, set the MARKETPLACES env var (comma-separated):

{
  "env": {
    "MARKETPLACES": "facebook,ebay"
  }
}

Valid values: facebook, ebay, depop, poshmark

eBay API Keys

eBay uses the official Browse API. You need a free eBay developer account:

  1. Create an account at developer.ebay.com
  2. Create an application to get a Client ID and Client Secret
  3. Add them to your MCP config as EBAY_CLIENT_ID and EBAY_CLIENT_SECRET

eBay Marketplace / Region

By default the server targets the US eBay site. To search a different regional marketplace, set the EBAY_MARKETPLACE_ID environment variable:

{
  "env": {
    "EBAY_MARKETPLACE_ID": "EBAY_DE"
  }
}

Common values:

ValueSite
EBAY_USebay.com (default)
EBAY_DEebay.de
EBAY_GBebay.co.uk
EBAY_AUebay.com.au
EBAY_FRebay.fr
EBAY_ITebay.it
EBAY_ESebay.es
EBAY_CAebay.ca

The full list is available in the eBay API docs.

Tools

search_marketplace

Search for items across marketplaces.

ParameterRequiredDefaultDescription
queryYesSearch terms
marketplaceNofacebookfacebook, ebay, depop, poshmark, or all
locationNosan franciscoCity to search in (Facebook only)
maxPriceNoMaximum price
minPriceNoMinimum price
limitNo20Max results
showSoldNofalseInclude sold items (Facebook only)
includeImagesNofalseInclude image URLs in output
sortNorelevanceSort order (Depop, Poshmark): relevance, newest, most_popular, price_low_to_high, price_high_to_low
conditionNoItem condition. eBay: new, like_new, good, fair. Depop: new, like_new, excellent, good, fair, used. Poshmark: new (NWT), like_new (NWOT), good, fair
categoryNoProduct category. Depop: tops, bottoms, dresses, coats-jackets, footwear, accessories, bags, jewellery, activewear, swimwear. Poshmark: Jackets_&_Coats, Dresses, Shoes, Accessories, etc.
brandNoBrand filter (Poshmark only): e.g. "Nike", "Levi's", "Gucci"
departmentNoDepartment filter (Poshmark only): Women, Men, Kids
sizesNoSize filter (Depop, Poshmark): e.g. ["S", "M", "L"] or ["US 9", "US 10"]
colorsNoColor filter (Depop, Poshmark): black, white, red, blue, green, yellow, orange, pink, purple, brown, grey, cream, multi, silver, gold

Data returned per marketplace:

FieldFacebookeBayDepopPoshmark
TitleYesYesYesYes
PriceYesYesYesYes
LocationCityCity, State
ConditionYes
Photo count1 thumbnail1 thumbnail1 thumbnail1 thumbnail
SellerYesYes

get_listing_details

Get full details for a specific listing using an ID from search results.

ParameterRequiredDefaultDescription
listingIdYesListing ID from search results
marketplaceNofacebookfacebook, ebay, depop, or poshmark

Data returned per marketplace:

FieldFacebookeBayDepopPoshmark
DescriptionYesYesYesYes
All photosYesYesYesYes
LocationCityCity, State, Country
SellerNameUsernameUsernameUsername
Delivery typesYes
ShippingYes/NoService codesYes/NoAlways included

list_marketplaces

List all enabled marketplaces and their status.

search / fetch (deep research)

Convenience pair following the ChatGPT Deep Research tool contract — exact names, a single string argument each:

  • search(query) — searches every enabled marketplace at once and returns { results: [{ id, title, text, url }] }, where id is marketplace:listingId
  • fetch(id) — returns full listing details for a search result ID as { id, title, text, url, metadata }

Useful for research-style clients that expect these standard tool names; for filtered searches use search_marketplace.

How It Works

Facebook Marketplace — Searches listings by location, price, and query. Resolves city names to coordinates. No login or browser needed.

eBay — Uses the official eBay Browse API with OAuth 2.0 client credentials. Tokens are cached and auto-refreshed. The target regional marketplace is controlled by EBAY_MARKETPLACE_ID (default: EBAY_US).

Depop — Uses a headless browser to search listings with support for category, condition, size, and color filters. The browser instance is shared across requests.

Poshmark — Uses a headless browser to search listings with support for condition, size, color, sort, and price filters. Poshmark is not location-based — all items ship nationally.

Development

git clone https://github.com/jlsookiki/secondhand-mcp.git
cd secondhand-mcp
npm install
npm run build

Adding a Marketplace

  1. Create a new file in src/marketplaces/
  2. Extend BaseMarketplace and implement search() and optionally getListingDetails()
  3. Add the constructor to allMarketplaces in src/marketplaces/index.ts

Limitations

  • Facebook: May break if Facebook changes their frontend
  • eBay: Requires developer API keys (free tier available)
  • Depop: Requires Chrome/Chromium installed; slower than Facebook/eBay (~5s per search)
  • Poshmark: Requires Chrome/Chromium installed; no official API so relies on page scraping
  • Rate limiting: Don't make too many requests too quickly

License

MIT

Reviews

No reviews yet

Be the first to review this server!