Avito login MCP server over the mobile API
avito-mcp
An Avito login MCP server built on the unofficial mobile app protocol, with automatic token refresh and status checks
High risk
We rate an entry high when the tool writes to external systems, handles money, production databases or secrets, or runs arbitrary commands. The CLI installs it only with your consent.
Why this level
- Uses Avito's unofficial mobile app protocol instead of a public API, which may violate the service's terms
- Your account login and password are sent to the server and stored locally alongside the access tokens
Install
Manual install
pip install -r src/requirements.txt && python3 src/avito_auth.py loginInstalls dependencies and runs the interactive login, saving tokens to ~/.avito_mcp/config.json.
This is third-party code. Review the repository files before installing.
What it does
The project logs in to Avito using the same protocol as the official Android app: login and password, an SMS code (TFA) when required, after which access and refresh tokens are stored. Login runs through a separate CLI (avito_auth.py login/status/refresh/logout), and an SSE MCP server on port 8010 gives an agent two tools: avito_status to check whether you are logged in, and avito_refresh to force a token refresh. A SessionManager watches JWT expiry and refreshes tokens in the background 5 to 30 minutes before they expire. The auth protocol itself is documented separately in AVITO.md, reverse-engineered from observing the official Android app's traffic.
Who it is for. For developers building their own tools on top of an Avito account who need a ready, maintained authentication layer.
Good fit when
- You need a working Avito login with password and SMS code using the mobile app protocol
- You need an MCP server that keeps the session alive and refreshes the token on its own
- You are ready to extend the server yourself: right now it only handles auth, with no search or messaging
Not a fit when
- You need ready-made search, messaging or listing tools: this server currently has none, only auth
- You do not want to risk your account being flagged: access bypasses Avito's official API
- You need an official, vendor-supported login method
Example request
Check whether the Avito account is logged in on the server, and refresh the token if it is about to expireLimitations
The server implements only authentication: two tools, status and refresh, with no search, messaging or listings. The protocol is unofficial, reverse-engineered from the mobile app, and Avito can change it at any time. Your Avito login and password are sent and stored locally in ~/.avito_mcp/config.json. The repo has no README, only AVITO.md documenting the API and AGENTS.md with run instructions. It has zero stars and a single author.
How to disable. Run python3 src/avito_auth.py logout, stop docker compose, and remove the server from your MCP client config.
MCP
- Transport
- http
- Authentication
- not required
| Environment variables | |
|---|---|
| CONFIG_PATH | Path to the token file instead of the default ~/.avito_mcp/config.json |
Security check
- Uses Avito's unofficial mobile app protocol instead of a public API, which may violate the service's terms
- Your account login and password are sent to the server and stored locally alongside the access tokens
README in short
Instead of a README, the project is described in AGENTS.md (quick start, CLI commands, architecture, MCP tools, configuration) and in AVITO.md (a step-by-step breakdown of Avito's auth endpoints: login, TFA, token refresh, request headers and response format).
FAQ
What does the MCP server do besides login?
Nothing yet: only avito_status and avito_refresh are available. Search, messaging and other Avito features are not part of the project.
Is this an official way to log in to Avito?
No, it is an unofficial mobile app protocol documented from observed traffic, not a public Avito API.
Related
A skills library that gives coding agents a development process: brainstorming, planning, TDD, subagents and code review
Skills for real engineers by Matt Pocock
Skills For Real Engineers
Small composable skills for engineering with agents: plan grilling, TDD, bug diagnosis, code review and architecture
GitHub toolkit for spec-driven development: the specify CLI adds agent commands and skills to a project, from principles to implementation
Reference MCP servers
Model Context Protocol servers
Official reference MCP servers: Filesystem, Fetch, Git, Memory, Sequential Thinking, Time and Everything