wbcli: a CLI for the Wildberries Seller API

wbcli

A conservative CLI and skill for the official Wildberries Seller API: token checks, ping, seller-info and read-only raw requests

CLI

Low risk

We rate an entry low when it mostly gives the agent instructions and reference material.

Why this level

  • The first version only reads data and makes GET requests; there are no write operations yet
All reasons and checks
Russian stack

dapi/wbcli

Install

Manual install

npm install -g github:dapi/wbcli

Installs the CLI straight from GitHub; the package is not yet published to the npm registry.

This is third-party code. Review the repository files before installing.

What it does

wbcli is a small Node.js and TypeScript CLI over the official Wildberries REST API with no third-party SDK. The first version is deliberately limited to safe commands: token:decode parses a JWT locally, ping checks connectivity, seller-info returns seller data, and raw makes an arbitrary request to a given endpoint as an escape hatch. Commands can show WB's X-Ratelimit headers and, with a flag, wait and retry once on a 429. The token is read from WB_TOKEN or .env and is never logged. Write commands are planned for later and will need a separate --write flag. The repo ships a SKILL.md with safe-usage rules for agents.

Who it is for. For developers who want a lightweight CLI to check Wildberries Seller API access without a third-party SDK.

Good fit when

  • You want to quickly check a token and its WB API access
  • You need a raw request to an arbitrary WB endpoint for debugging
  • You want to see rate-limit headers instead of hitting 429 blind

Not a fit when

  • You need broad write coverage: the first version has none
  • You need a published npm registry package rather than a GitHub install

Example request

Check my Wildberries token with wbcli ping and show the remaining rate limit

Limitations

The project is early stage; the README describes it as an intentionally limited MVP. Write operations are not implemented in the first version and are planned to require a separate flag. The package is not published to the npm registry, install is straight from GitHub. You need a seller token from the WB dashboard.

How to disable. Remove the global package with npm uninstall -g wbcli, or delete your local copy.

Security check

  • The first version only reads data and makes GET requests; there are no write operations yet

README in short

The README explains the Node.js and TypeScript stack choice, the MVP command list and the plan for further read-only endpoints and --write-gated write commands, install via npm install -g github:dapi/wbcli or npx, working with rate-limit headers, and an official access model limited to a seller token with no scraping of private dashboard pages.

SKILL.md

---
name: wbcli
description: "Use when working with the official Wildberries Seller API through the wbcli command-line tool: checking token scopes, testing connectivity, reading seller info, exploring read-only WB endpoints, planning data exports for Google Sheets, or debugging WB API access. This skill is for authorized seller API access only; do not use it for scraping private cabinet endpoints, bypassing permissions, or handling tokens insecurely."
---

# wbcli

Use wbcli for authorized, token-based access to the official Wildberries Seller API.

## Safety Rules

- Use only official WB Seller API tokens created in the seller cabinet.
- Never print, commit, paste, or send the token to online JWT decoders.
- Prefer read-only tokens for analytics work.
- Do not scrape private cabinet endpoints or reuse browser sessions.
- Store the token in WB_TOKEN or .env; keep .env out of git.

FAQ

Can wbcli change data in the WB dashboard?

No, the current version only reads and makes raw GET requests; write commands are planned for later behind a separate flag.

Where does the token come from?

Only an official Wildberries Seller API token from the seller dashboard; the skill explicitly forbids scraping private cabinet pages or reusing a browser session.

Official

Salesforce's official DX MCP server: work with orgs, metadata, data, users and Apex tests from your agent

MCP serverHigh risk483Repository stars
Official

Yandex's official skill set: catalog, prices, stock, orders, storefront and a weekly checkup for a Yandex Kit store, through Claude Code or Codex

PluginHigh riskRussian stackNo VPN needed28Repository stars
Editors’ pick

Full 65-operation YouGile API coverage with configurable permissions, write confirmation and a shared company rate limit

MCP serverHigh riskRussian stackNo VPN needed

Bitrix24 portal MCP server

MCP-сервер портала Битрикс24

Official

Bitrix24's official per-portal MCP: an external agent uses OAuth or a token to read and change tasks, deals, meetings and mail

MCP serverHigh riskRussian stackNo VPN needed
Foxx AIwbcli: a CLI for the Wildberries Seller API

I am Foxx AI and I have already vetted this tool. Ask about install, setup or anything else, and I will keep it simple.