Back to Browse

Lamatok MCP Server

Developer ToolsModerate7.2MCP RegistryLocal
Free

Server data from the Official MCP Registry

TikTok data via LamaTok: profiles, videos, comments, followers, hashtags, search, downloads.

About

TikTok data via LamaTok: profiles, videos, comments, followers, hashtags, search, downloads.

Security Report

7.2
Moderate7.2Low Risk

lamatok-mcp is a well-structured MCP server that wraps the LamaTok TikTok API with proper authentication, input validation, and safe credential handling. The server correctly requires an API key, validates URLs against a trusted host list, implements response size limits, and marks all tools as read-only. Minor code quality improvements around error handling and logging could be made, but the security posture is solid. Supply chain analysis found 1 known vulnerability in dependencies (0 critical, 1 high severity). Package verification found 1 issue.

7 files analyzed · 6 issues found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Required

This plugin requests these system permissions. Most are normal for its category.

HTTP Network Access

Connects to external APIs or services over the internet.

env_vars

Check that this permission is expected for this type of plugin.

What You'll Need

Set these up before or after installing:

LamaTok access key — get one at https://lamatok.com (100 free requests on signup)Required

Environment variable: LAMATOK_KEY

core (default): 23 curated tools, one per task. all: every endpoint.Optional

Environment variable: LAMATOK_TOOLS

How to Install

Add this to your MCP configuration file:

{
  "mcpServers": {
    "io-github-subzeroid-lamatok-mcp": {
      "env": {
        "LAMATOK_KEY": "your-lamatok-key-here",
        "LAMATOK_TOOLS": "your-lamatok-tools-here"
      },
      "args": [
        "-y",
        "lamatok-mcp"
      ],
      "command": "npx"
    }
  }
}

Documentation

View on GitHub

From the project's GitHub README.

lamatok-mcp

npm version npm downloads License: MIT

MCP server for LamaTok — TikTok data API. Available on npm: lamatok-mcp.

Generates MCP tools from the LamaTok OpenAPI spec at startup. Tools map 1:1 to REST endpoints (GET /v1/user/by/username → get_v1_user_by_username). By default you get a core set of ~23 tools, one per task, each with a description that tells the assistant when to use it; LAMATOK_TOOLS=all exposes every non-deprecated endpoint.

Get 100 Free API Requests

Sign up with this link and get 100 free LamaTok requests — no credit card required. Enough to wire up the MCP server, try a few prompts in Claude/Cursor/Codex, and evaluate the data quality before committing.

Get your free 100 requests here

Quick start

  1. Get an API key at lamatok.com.
  2. Add the server to your AI assistant.
  3. Ask your assistant something like:
    • "Get the TikTok profile for @nasa."
    • "List the last 10 videos by user_id 6707206320333226502."
    • "Find recent TikTok videos for the hashtag photography."

Claude Code

claude mcp add lamatok -e LAMATOK_KEY=your-api-key -- npx -y lamatok-mcp

Claude Desktop

Add to claude_desktop_config.json:

{
  "mcpServers": {
    "lamatok": {
      "command": "npx",
      "args": ["-y", "lamatok-mcp"],
      "env": {
        "LAMATOK_KEY": "your-api-key"
      }
    }
  }
}

Cursor / Windsurf

Same shape as Claude Desktop — put the block under mcpServers in the app's MCP config file.

Zed

Add to ~/.config/zed/settings.json:

{
  "context_servers": {
    "lamatok": {
      "command": "npx",
      "args": ["-y", "lamatok-mcp"],
      "env": {
        "LAMATOK_KEY": "your-api-key"
      }
    }
  }
}

OpenAI Codex

Append to ~/.codex/config.toml:

[mcp_servers.lamatok]
command = "npx"
args = ["-y", "lamatok-mcp"]

[mcp_servers.lamatok.env]
LAMATOK_KEY = "your-api-key"

Tools

Tools are generated at startup from the live LamaTok OpenAPI spec. The default core set keeps one endpoint per task and drops version duplicates:

GroupToolsExamples
Profiles and audience12get_v1_user_by_username, get_v2_user_medias_by_secUid, get_v1_user_followers_by_username
Videos and comments4get_v1_media_by_url, get_v1_media_by_id, get_v1_media_comments_by_id
Download links4get_v1_media_video_download_by_url, get_v1_media_music_download_by_id
Hashtags and search3get_v1_hashtag_info, get_v1_hashtag_medias, get_v2_search

Core tools carry hand-written descriptions (what the tool does, when to prefer a sibling, pagination, billing) and every tool is annotated read-only. The list lives in src/curated.ts.

Set LAMATOK_TOOLS=all to expose every non-deprecated endpoint instead — same tool names as before, so existing prompts keep working. Tool names mirror their endpoint (GET /v1/user/by/username → get_v1_user_by_username); call tools/list over MCP for the current list with parameter schemas. /sys, Legacy, and System tag groups are excluded in both modes.

Configuration

VariableDescriptionRequired
LAMATOK_KEYYour LamaTok access key (sent as x-access-key header)yes
LAMATOK_URLBase URL. Default: https://api.lamatok.comno
LAMATOK_SPEC_URLOpenAPI spec URL. Default: ${LAMATOK_URL}/openapi.jsonno
LAMATOK_TOOLScore (default): curated set, one tool per task. all: every non-deprecated endpointno
LAMATOK_TAGSWhitelist: only include operations with these tags (comma-separated)no
LAMATOK_EXCLUDE_TAGSBlacklist: additional tags to exclude (on top of Legacy, System, /sys)no
LAMATOK_TIMEOUT_MSPer-request timeout for API calls. Default: 30000no
LAMATOK_SPEC_TIMEOUT_MSTimeout for the startup spec fetch. Default: 60000no
LAMATOK_SPEC_RETRY_DELAY_MSBase delay between the 3 startup spec fetch attempts. Default: 2000no
LAMATOK_MAX_RESPONSE_BYTESMax bytes read from each API response. Default: 10485760 (10 MB)no
LAMATOK_MAX_SPEC_BYTESMax bytes read from the OpenAPI spec. Default: 8388608 (8 MB)no

Legacy, System, and /sys tags are excluded by default. Deprecated operations are also skipped.

If LAMATOK_URL points to a host other than api.lamatok.com, the server prints a warning on startup — your key will be sent there, so only use it for a self-hosted or proxied LamaTok.

Requests are sent with User-Agent: lamatok-mcp/<version>.

How it works

AI Assistant ←stdio→ lamatok-mcp ──https──> api.lamatok.com
                          │
                          └─ fetches /openapi.json once on startup,
                             builds one MCP tool per GET endpoint
                             (core set by default)

Tool arguments map to the endpoint's query and path parameters. The response body is returned as-is (JSON text). Non-2xx responses are surfaced as tool errors with the HTTP status and body.

Development

git clone https://github.com/subzeroid/lamatok-mcp.git
cd lamatok-mcp
npm install
npm run build
LAMATOK_KEY=your-key node dist/index.js

Run in watch mode:

LAMATOK_KEY=your-key npm run dev

Run tests (unit + stdio smoke tests against a local mock server, no network/API key required):

npm test

License

MIT

Reviews

No reviews yet

Be the first to review this server!