A1 Yandex Merchants MCP
A1 Яндекс Товары MCP
An MCP server that updates prices, discounts and product visibility in Yandex Merchants one item at a time, without rebuilding the YML feed
High risk
We rate an entry high when the tool writes to external systems, handles money, production databases or secrets, or runs arbitrary commands. The CLI installs it only with your consent.
Why this level
- Changes product prices and discounts, directly affecting the seller's revenue
- Can hide and unhide products in bulk, up to 500 per request
- After a connection failure the operation is not auto-retried, and the actual state cannot be read back through the API
Install
In your terminal, with SkillFoxx CLI
npx skillfoxx add mcp/a1-yandeks-tovary-mcpDetects the agents on your machine, checks the risk and pins the version.
Other ways to install
This entry is high risk, so there is no one-click install. Review the code and add the config by hand.
Run in a terminal
claude mcp add --transport stdio --env 'YANDEX_MERCHANTS_OAUTH_TOKEN=<your YANDEX_MERCHANTS_OAUTH_TOKEN>' mcp-yandex-merchants -- npx -y mcp-yandex-merchants@1.1.1Or add to the file .mcp.json, in the project
{
"mcpServers": {
"mcp-yandex-merchants": {
"command": "npx",
"args": [
"-y",
"mcp-yandex-merchants@1.1.1"
],
"env": {
"YANDEX_MERCHANTS_OAUTH_TOKEN": "<your YANDEX_MERCHANTS_OAUTH_TOKEN>"
}
}
}
}If the file already exists, add the server inside the mcpServers key.
Keys and settings
YANDEX_MERCHANTS_OAUTH_TOKENsecret, required- Yandex OAuth token with the products:partner-api scope, obtained under the login that uploaded the feed. Treat it as a secret.
YANDEX_MERCHANTS_BASE_URLoptional- API root override.
YANDEX_MERCHANTS_TIMEOUT_MSoptional- Per-request timeout in milliseconds.
YANDEX_MERCHANTS_MAX_RETRIESoptional- Retries on transient errors (429 always; 5xx/network for GET only).
Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.
Add to the file ~/.cursor/mcp.json, for all projects
{
"mcpServers": {
"mcp-yandex-merchants": {
"command": "npx",
"args": [
"-y",
"mcp-yandex-merchants@1.1.1"
],
"env": {
"YANDEX_MERCHANTS_OAUTH_TOKEN": "<your YANDEX_MERCHANTS_OAUTH_TOKEN>"
}
}
}
}If the file already exists, add the server inside the mcpServers key. For a single project, put the same block into .cursor/mcp.json.
Keys and settings
YANDEX_MERCHANTS_OAUTH_TOKENsecret, required- Yandex OAuth token with the products:partner-api scope, obtained under the login that uploaded the feed. Treat it as a secret.
YANDEX_MERCHANTS_BASE_URLoptional- API root override.
YANDEX_MERCHANTS_TIMEOUT_MSoptional- Per-request timeout in milliseconds.
YANDEX_MERCHANTS_MAX_RETRIESoptional- Retries on transient errors (429 always; 5xx/network for GET only).
Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.
Run in a terminal
code --add-mcp '{"name":"mcp-yandex-merchants","type":"stdio","command":"npx","args":["-y","mcp-yandex-merchants@1.1.1"],"env":{"YANDEX_MERCHANTS_OAUTH_TOKEN":"<your YANDEX_MERCHANTS_OAUTH_TOKEN>"}}'Or add to the file .vscode/mcp.json, in the project
{
"servers": {
"mcp-yandex-merchants": {
"type": "stdio",
"command": "npx",
"args": [
"-y",
"mcp-yandex-merchants@1.1.1"
],
"env": {
"YANDEX_MERCHANTS_OAUTH_TOKEN": "<your YANDEX_MERCHANTS_OAUTH_TOKEN>"
}
}
}
}If the file already exists, add the server inside the servers key.
Keys and settings
YANDEX_MERCHANTS_OAUTH_TOKENsecret, required- Yandex OAuth token with the products:partner-api scope, obtained under the login that uploaded the feed. Treat it as a secret.
YANDEX_MERCHANTS_BASE_URLoptional- API root override.
YANDEX_MERCHANTS_TIMEOUT_MSoptional- Per-request timeout in milliseconds.
YANDEX_MERCHANTS_MAX_RETRIESoptional- Retries on transient errors (429 always; 5xx/network for GET only).
Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.
Run in a terminal
codex mcp add mcp-yandex-merchants --env 'YANDEX_MERCHANTS_OAUTH_TOKEN=<your YANDEX_MERCHANTS_OAUTH_TOKEN>' -- npx -y mcp-yandex-merchants@1.1.1Or add to the file ~/.codex/config.toml, for all projects
[mcp_servers.mcp-yandex-merchants]
command = "npx"
args = ["-y", "mcp-yandex-merchants@1.1.1"]
env = { YANDEX_MERCHANTS_OAUTH_TOKEN = "<your YANDEX_MERCHANTS_OAUTH_TOKEN>" }If the file already exists, append the block to the end.
Keys and settings
YANDEX_MERCHANTS_OAUTH_TOKENsecret, required- Yandex OAuth token with the products:partner-api scope, obtained under the login that uploaded the feed. Treat it as a secret.
YANDEX_MERCHANTS_BASE_URLoptional- API root override.
YANDEX_MERCHANTS_TIMEOUT_MSoptional- Per-request timeout in milliseconds.
YANDEX_MERCHANTS_MAX_RETRIESoptional- Retries on transient errors (429 always; 5xx/network for GET only).
Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.
Add to the file ~/.gemini/settings.json, for all projects
{
"mcpServers": {
"mcp-yandex-merchants": {
"command": "npx",
"args": [
"-y",
"mcp-yandex-merchants@1.1.1"
],
"env": {
"YANDEX_MERCHANTS_OAUTH_TOKEN": "<your YANDEX_MERCHANTS_OAUTH_TOKEN>"
}
}
}
}If the file already exists, add the server inside the mcpServers key.
Keys and settings
YANDEX_MERCHANTS_OAUTH_TOKENsecret, required- Yandex OAuth token with the products:partner-api scope, obtained under the login that uploaded the feed. Treat it as a secret.
YANDEX_MERCHANTS_BASE_URLoptional- API root override.
YANDEX_MERCHANTS_TIMEOUT_MSoptional- Per-request timeout in milliseconds.
YANDEX_MERCHANTS_MAX_RETRIESoptional- Retries on transient errors (429 always; 5xx/network for GET only).
Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.
Add to the file ~/.config/devin/mcp_config.json, for all projects
{
"mcpServers": {
"mcp-yandex-merchants": {
"command": "npx",
"args": [
"-y",
"mcp-yandex-merchants@1.1.1"
],
"env": {
"YANDEX_MERCHANTS_OAUTH_TOKEN": "<your YANDEX_MERCHANTS_OAUTH_TOKEN>"
}
}
}
}If the file already exists, add the server inside the mcpServers key. Legacy Cascade keeps the MCP config in ~/.codeium/windsurf/mcp_config.json.
Keys and settings
YANDEX_MERCHANTS_OAUTH_TOKENsecret, required- Yandex OAuth token with the products:partner-api scope, obtained under the login that uploaded the feed. Treat it as a secret.
YANDEX_MERCHANTS_BASE_URLoptional- API root override.
YANDEX_MERCHANTS_TIMEOUT_MSoptional- Per-request timeout in milliseconds.
YANDEX_MERCHANTS_MAX_RETRIESoptional- Retries on transient errors (429 always; 5xx/network for GET only).
Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.
Formerly Windsurf.
Add to the file cline_mcp_settings.json, for all projects
{
"mcpServers": {
"mcp-yandex-merchants": {
"command": "npx",
"args": [
"-y",
"mcp-yandex-merchants@1.1.1"
],
"env": {
"YANDEX_MERCHANTS_OAUTH_TOKEN": "<your YANDEX_MERCHANTS_OAUTH_TOKEN>"
}
}
}
}If the file already exists, add the server inside the mcpServers key. Open the settings file in Cline: MCP Servers tab, Configure MCP Servers.
Keys and settings
YANDEX_MERCHANTS_OAUTH_TOKENsecret, required- Yandex OAuth token with the products:partner-api scope, obtained under the login that uploaded the feed. Treat it as a secret.
YANDEX_MERCHANTS_BASE_URLoptional- API root override.
YANDEX_MERCHANTS_TIMEOUT_MSoptional- Per-request timeout in milliseconds.
YANDEX_MERCHANTS_MAX_RETRIESoptional- Retries on transient errors (429 always; 5xx/network for GET only).
Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.
Add to the file .roo/mcp.json, in the project
{
"mcpServers": {
"mcp-yandex-merchants": {
"command": "npx",
"args": [
"-y",
"mcp-yandex-merchants@1.1.1"
],
"env": {
"YANDEX_MERCHANTS_OAUTH_TOKEN": "<your YANDEX_MERCHANTS_OAUTH_TOKEN>"
}
}
}
}If the file already exists, add the server inside the mcpServers key.
Keys and settings
YANDEX_MERCHANTS_OAUTH_TOKENsecret, required- Yandex OAuth token with the products:partner-api scope, obtained under the login that uploaded the feed. Treat it as a secret.
YANDEX_MERCHANTS_BASE_URLoptional- API root override.
YANDEX_MERCHANTS_TIMEOUT_MSoptional- Per-request timeout in milliseconds.
YANDEX_MERCHANTS_MAX_RETRIESoptional- Retries on transient errors (429 always; 5xx/network for GET only).
Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.
A fork of Roo Code, same .roo folders.
Add to the file opencode.json, in the project
{
"mcp": {
"mcp-yandex-merchants": {
"type": "local",
"command": [
"npx",
"-y",
"mcp-yandex-merchants@1.1.1"
],
"environment": {
"YANDEX_MERCHANTS_OAUTH_TOKEN": "<your YANDEX_MERCHANTS_OAUTH_TOKEN>"
}
}
}
}If the file already exists, add the server inside the mcp key.
Keys and settings
YANDEX_MERCHANTS_OAUTH_TOKENsecret, required- Yandex OAuth token with the products:partner-api scope, obtained under the login that uploaded the feed. Treat it as a secret.
YANDEX_MERCHANTS_BASE_URLoptional- API root override.
YANDEX_MERCHANTS_TIMEOUT_MSoptional- Per-request timeout in milliseconds.
YANDEX_MERCHANTS_MAX_RETRIESoptional- Retries on transient errors (429 always; 5xx/network for GET only).
Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.
Add to the file ~/.config/zed/settings.json, for all projects
{
"context_servers": {
"mcp-yandex-merchants": {
"command": "npx",
"args": [
"-y",
"mcp-yandex-merchants@1.1.1"
],
"env": {
"YANDEX_MERCHANTS_OAUTH_TOKEN": "<your YANDEX_MERCHANTS_OAUTH_TOKEN>"
}
}
}
}If the file already exists, add the server inside the context_servers key.
Keys and settings
YANDEX_MERCHANTS_OAUTH_TOKENsecret, required- Yandex OAuth token with the products:partner-api scope, obtained under the login that uploaded the feed. Treat it as a secret.
YANDEX_MERCHANTS_BASE_URLoptional- API root override.
YANDEX_MERCHANTS_TIMEOUT_MSoptional- Per-request timeout in milliseconds.
YANDEX_MERCHANTS_MAX_RETRIESoptional- Retries on transient errors (429 always; 5xx/network for GET only).
Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.
Add to the file .codeassistant/mcp.json, in the project
{
"mcpServers": {
"mcp-yandex-merchants": {
"command": "npx",
"args": [
"-y",
"mcp-yandex-merchants@1.1.1"
],
"env": {
"YANDEX_MERCHANTS_OAUTH_TOKEN": "<your YANDEX_MERCHANTS_OAUTH_TOKEN>"
}
}
}
}If the file already exists, add the server inside the mcpServers key.
Keys and settings
YANDEX_MERCHANTS_OAUTH_TOKENsecret, required- Yandex OAuth token with the products:partner-api scope, obtained under the login that uploaded the feed. Treat it as a secret.
YANDEX_MERCHANTS_BASE_URLoptional- API root override.
YANDEX_MERCHANTS_TIMEOUT_MSoptional- Per-request timeout in milliseconds.
YANDEX_MERCHANTS_MAX_RETRIESoptional- Retries on transient errors (429 always; 5xx/network for GET only).
Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.
Add the server with claude mcp add --transport stdio --scope user yandex-merchants -- npx -y mcp-yandex-merchants@latest, then in the conversation ask it to connect Yandex Merchants and log in under the exact account the YML feed was uploaded with.
Other ways from the author
claude mcp add --transport stdio --scope user yandex-merchants -- npx -y mcp-yandex-merchants@latestNo token is needed up front; login happens in the conversation.
This is third-party code. Review the repository files before installing.
What it does
The server connects an agent to the Yandex Merchants partner API and gives it 13 actions: checking access and listing uploaded feeds, changing one product's price and discount, bulk price changes for up to 2,000 products per request, hiding and unhiding up to 500 products per request, and a direct call to any raw API method. Account connection happens right in the conversation via OAuth with PKCE: the agent gives a login link under the exact Yandex account the feed was uploaded with, the user sends a one-time code, and a token scoped to just products:partner-api is stored locally at ~/.config/mcp-yandex-merchants/credentials.json. Before sending, the server validates required fields, list sizes, id length, positive prices and the discount range, and after sending it checks the status field in the API response, since an HTTP 200 alone does not mean the write succeeded. After a connection drop, the operation is not retried automatically, because this API offers no way to read a product's current state.
Who it is for. For Yandex Merchants sellers who need to make targeted price and visibility changes without rebuilding the whole YML feed.
Good fit when
- You need to quickly change the price or discount of one or several products without redoing the feed
- You need to temporarily hide products, for example when out of stock, and unhide them later
- You need a bulk price recalculation for up to 2,000 products in one call
Not a fit when
- You need to read the current price, status or list of hidden products: the API does not expose this, the server only writes
- You need to create, delete or reload the feed itself: that only happens in the dashboard or Webmaster, the server works on top of an already-uploaded feed
Example request
In feed 1069, prepare a new price for SKU-123: 1490 rubles instead of 1990, show me the change firstLimitations
The Yandex Merchants API offers no way to read current prices, the list of hidden products, or feed status, so a change log must be kept on the user's side. Managing the feeds themselves is not possible through the server. It works only in rubles, product ids up to 50 characters, up to 2,000 prices and up to 500 hides or unhides per request, with a limit of 50,000 operations per minute. After a connection failure the write result can stay unknown, with no way to verify it through the API.
How to disable. Tell the agent to disconnect Yandex Merchants, or remove the server from your MCP client config, and revoke access in Yandex ID under security settings.
MCP
- Transport
- stdio
- Authentication
- OAuth
| Environment variables | |
|---|---|
| YANDEX_MERCHANTS_OAUTH_TOKEN secret | A pre-issued OAuth token scoped to products:partner-api for CI and non-interactive installs, takes priority over conversational login |
Security check
- Changes product prices and discounts, directly affecting the seller's revenue
- Can hide and unhide products in bulk, up to 500 per request
- After a connection failure the operation is not auto-retried, and the actual state cannot be read back through the API
README in short
The Russian README describes the server as connecting an AI app to the Yandex Merchants partner API for targeted price, discount and visibility changes without rebuilding the feed. It shows an example conversation preparing and confirming a price change, a table of 13 actions flagged by whether they change data, a list of pre- and post-write checks, setup instructions for Codex, Claude Code, Claude Desktop and Cursor via npx, and the OAuth-with-PKCE mechanics scoped to just products:partner-api. A dedicated limitations section honestly lists that the API cannot read current state, works only in rubles, and does not auto-retry after a failure. It links to detailed per-tool docs in docs/capabilities.
FAQ
Can a change be previewed before it's confirmed?
Yes, but confirmation depends on the AI app: ask the assistant to first prepare and show the feedId, product id and new values, then execute only with a follow-up command.
Can the current price be read before changing it?
No, the Yandex Merchants API does not return current prices or feed status; the server is write-only.
Related
Salesforce's official DX MCP server: work with orgs, metadata, data, users and Apex tests from your agent
Yandex Kit skills for store management
kit-skills
Yandex's official skill set: catalog, prices, stock, orders, storefront and a weekly checkup for a Yandex Kit store, through Claude Code or Codex
YouGile MCP by Indalo
YouGile MCP
Full 65-operation YouGile API coverage with configurable permissions, write confirmation and a shared company rate limit
Bitrix24 portal MCP server
MCP-сервер портала Битрикс24
Bitrix24's official per-portal MCP: an external agent uses OAuth or a token to read and change tasks, deals, meetings and mail