Back to Browse

Moysklad MCP Server

Developer ToolsModerate5.2MCP RegistryLocal
Free

Server data from the Official MCP Registry

MCP server for MoySklad — warehouse, inventory, orders, reports (Russia)

About

MCP server for MoySklad — warehouse, inventory, orders, reports (Russia)

Security Report

5.2
Moderate5.2Moderate Risk

This is a well-structured MCP server for MoySklad API integration with proper authentication, comprehensive input validation via Zod schemas, and appropriate rate limiting. The codebase demonstrates good security practices with credentials sourced from environment variables and no hardcoded secrets. Minor code quality observations exist around error handling specificity and test coverage, but these do not constitute security vulnerabilities. Supply chain analysis found 3 known vulnerabilities in dependencies (0 critical, 3 high severity). Package verification found 1 issue.

7 files analyzed · 8 issues found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Required

This plugin requests these system permissions. Most are normal for its category.

env_vars

Check that this permission is expected for this type of plugin.

HTTP Network Access

Connects to external APIs or services over the internet.

file_system

Check that this permission is expected for this type of plugin.

How to Install

Add this to your MCP configuration file:

{
  "mcpServers": {
    "io-github-theyahia-moysklad-mcp": {
      "args": [
        "-y",
        "@theyahia/moysklad-mcp"
      ],
      "command": "npx"
    }
  }
}

Documentation

View on GitHub

From the project's GitHub README.

@theyahia/moysklad-mcp

MCP server for MoySklad (МойСклад) warehouse / ERP / CRM API. 60 tools covering the full trade and warehouse lifecycle: products & catalog, stock, counterparties, customer & purchase orders, shipments, supplies, stock moves, inventory, write-offs/enters, returns, invoices, payments & cash, reports, audit log, and webhooks.

npm license

Part of WWmcp — a set of MCP servers for emerging markets — and the russian-mcp series.

Quick Start

Claude Desktop

Add to your claude_desktop_config.json:

{
  "mcpServers": {
    "moysklad": {
      "command": "npx",
      "args": ["-y", "@theyahia/moysklad-mcp"],
      "env": {
        "MOYSKLAD_TOKEN": "your-bearer-token"
      }
    }
  }
}

To use login/password instead of a token, replace the env block with:

"env": { "MOYSKLAD_LOGIN": "you@example.com", "MOYSKLAD_PASSWORD": "your-password" }

Claude Code

claude mcp add moysklad --env MOYSKLAD_TOKEN=your-bearer-token -- npx -y @theyahia/moysklad-mcp

Cursor / Windsurf

Add to MCP settings:

{
  "moysklad": {
    "command": "npx",
    "args": ["-y", "@theyahia/moysklad-mcp"],
    "env": { "MOYSKLAD_TOKEN": "your-bearer-token" }
  }
}

Auth

VariableDescription
MOYSKLAD_TOKENBearer token (preferred)
MOYSKLAD_LOGIN + MOYSKLAD_PASSWORDHTTP Basic auth

Get a token in MoySklad: Settings → Users → Access tokens (POST /security/token also works with Basic auth). Generating a new token revokes the previous one.

Required permissions: the user/token needs access to the entities you intend to use. Read tools need view rights; create/update tools need edit rights for that document type. Webhooks and some reports require a paid MoySklad plan.

Prices

The MoySklad API stores money in kopecks (1 ruble = 100 kopecks). This server converts automatically:

  • Input: pass prices/amounts in rubles (e.g. 1500.50)
  • Output: prices/amounts are returned in rubles
  • (The get_dashboard report is passed through verbatim, so its money values are still in kopecks.)

When a product carries a sale price, MoySklad requires a price type. The server attaches your account's default price type automatically (from list_price_types); pass price_type_href to choose a specific one.

Tools (60)

Products & catalog

ToolDescription
search_productsSearch products by name or article
get_productGet a product by UUID (raw for the full object)
create_productCreate a product (price type attached automatically)
update_pricesUpdate sale/buy/min prices
search_assortmentUnified search across products, variants, services, bundles
list_price_typesList price types (first is the default)
search_variants / search_bundles / search_servicesSearch modifications / kits / services
create_serviceCreate a service

Stock

ToolDescription
get_stockCurrent stock (quantity, reserve, in-transit)
get_stock_by_storeStock broken down by warehouse
get_stock_currentFast current-stock snapshot

Counterparties

ToolDescription
get_counterpartiesSearch by name, INN, or phone
get_counterpartyGet full details (raw for the full object)
create_counterpartyCreate customer/supplier

Orders & shipments

ToolDescription
create_customer_order / get_orders / get_customer_order / update_customer_order_statusCustomer order lifecycle
create_purchase_order / get_purchase_ordersPurchase orders to suppliers
create_demandShipment (demand) linked to an order and warehouse
create_supplyIncoming supply (purchase receipt)
create_sales_return / create_purchase_returnReturns from customers / to suppliers

Warehouse documents

ToolDescription
create_move / get_movesStock transfer between warehouses
create_enter / get_entersStock enter (оприходование)
create_loss / get_lossesWrite-off (списание)
create_inventory / get_inventoriesInventory count (инвентаризация)

Finance

ToolDescription
create_payment_in / create_payment_outIncoming / outgoing bank payments
create_cash_in / create_cash_outCash receipt / expense orders
create_invoice_out / create_invoice_in / get_invoices_outSales / supplier invoices

Reports

ToolDescription
get_profit_reportProfit by product (revenue, cost, margin)
get_sales_reportSales by product (quantity, revenue)
get_dashboardDay/week/month dashboard metrics
get_turnoverProduct turnover over a period
get_money_reportCurrent money balances by account/cash

Reference & audit

ToolDescription
list_stores / list_organizationsWarehouses / legal entities
list_employees / list_currencies / list_product_foldersReference data
get_metadataEntity metadata (states, attributes) — find order-state hrefs here
get_audit / get_entity_auditAccount event log / single-entity history

Webhooks & generic

ToolDescription
list_webhooks / create_webhook / update_webhook / delete_webhookManage webhooks (CREATE/UPDATE/DELETE/PROCESSED)
get_documents / get_documentGeneric list/get for any entity type not covered above

HTTP Transport

HTTP_PORT=3000 npx @theyahia/moysklad-mcp
# or
npx @theyahia/moysklad-mcp --http 3000

Endpoints: POST /mcp (JSON-RPC), GET /health (status). CORS is off by default — the HTTP endpoint acts on your MoySklad token, so set MOYSKLAD_HTTP_CORS_ORIGIN only if a trusted browser origin needs it.

Configuration (env)

VariableDefaultDescription
MOYSKLAD_TOKENBearer token
MOYSKLAD_LOGIN / MOYSKLAD_PASSWORDBasic auth
MOYSKLAD_RATE_BUCKET20Requests allowed per 3-second window
MOYSKLAD_MAX_CONCURRENT5Max parallel requests (MoySklad allows 5/user)
MOYSKLAD_HTTP_CORS_ORIGINAllowed CORS origin for the HTTP transport
HTTP_PORTStart the Streamable HTTP transport on this port

Rate Limiting

MoySklad uses a weight-per-3-seconds model (≈45 units for a solution token, fewer for login/password, and the get_stock/get_stock_by_store reports cost 5 units each). The built-in limiter is a token bucket charged by request weight, kept conservative by default (MOYSKLAD_RATE_BUCKET=20) because the API can temporarily disable access after repeated 429s. It retries 429/5xx with backoff, honoring MoySklad's X-Lognex-Retry-After header. Solution-token users can raise the bucket toward 45.

Troubleshooting

SymptomCause / fix
Auth not configuredSet MOYSKLAD_TOKEN (or MOYSKLAD_LOGIN + MOYSKLAD_PASSWORD).
auth error 401/403Token invalid/expired or the user lacks rights for that entity. A new token revokes old ones.
MoySklad HTTP 412 …A required field is missing (e.g. an outgoing payment may need an expense item — pass expense_item_href). The error message includes the parameter.
Many 429 / slowLower request volume or rely on the built-in limiter; raise MOYSKLAD_RATE_BUCKET only with a solution token.
HTTP 415The runtime isn't sending gzip — use Node ≥18 (its fetch handles gzip automatically).
Webhooks / some reports failRequire a paid MoySklad plan.

E-commerce Stack

ServiceMCP ServerWhat it does
MoySklad@theyahia/moysklad-mcpWarehouse, products, orders
CDEK@theyahia/cdek-mcpDelivery, tracking
DaData@theyahia/dadata-mcpAddress validation
YooKassa@theyahia/yookassa-mcpPayments

Demo Prompts

"Show me all products with low stock (less than 10 units) and their current prices"

"Create a customer order for counterparty 'OOO Roga i Kopyta' with 50 units of 'Widget Pro' at 1500 rubles each, then create a shipment from the main warehouse"

"Move 20 units of SKU LP15 from the main warehouse to the store, then pull the profit report for this month"

Development

npm install        # installs deps + git hooks (husky)
npm run build      # tsc -> dist/
npm run lint       # eslint
npm run typecheck  # tsc --noEmit
npm test           # vitest (requires Node >=20)
npm run coverage   # vitest with coverage

The published runtime supports Node ≥18; the test tooling requires Node ≥20.

API Reference

Based on MoySklad JSON API 1.2.

License

MIT

Reviews

No reviews yet

Be the first to review this server!

Moysklad MCP Server - MCP server for MoySklad — warehouse, inventory, orders, | MCP Marketplace