Ozon buyer account MCP
Ozon MCP
An MCP server for one ozon.ru buyer account: orders, cart, favorites, selections, and, when explicitly allowed, placing and paying for an order
High risk
We rate an entry high when the tool writes to external systems, handles money, production databases or secrets, or runs arbitrary commands. The CLI installs it only with your consent.
Why this level
- With OZON_ENABLE_ORDERS on it can spend money and place orders
- With OZON_ENABLE_WRITES on it changes the cart, favorites, lists and cancels orders
- The MCP endpoint does not check who connects to it
Install
Manual install
docker build -t ozon-mcp . && docker run -i --rm --shm-size=1g -v /opt/ozon-mcp:/data ozon-mcpBuild the image and run over stdio with a persistent volume for the Chromium profile.
This is third-party code. Review the repository files before installing.
What it does
The server talks to the same internal composer-api and entrypoint-api endpoints Ozon's own frontend uses, under your authenticated session. It reads orders, purchase history, returns, the cart, favorites, selections, the Ozon Card balance and points, searches the catalog and compares prices. State changes (cart, lists, order cancellation) and placing a paid order are disabled by default and turned on with separate environment variables. The session lives in a persistent Chromium profile: a browser passes the Variti anti-bot check once, then requests go straight over HTTP with a Chrome fingerprint.
Who it is for. For people who want an agent to handle their own orders, favorites and cart on Ozon as a buyer, not a seller.
Good fit when
- You need to parse your own order history, returns and delivery status
- You want to build a cart and, after deliberately enabling writes, place an order
- You want to track price drops in your favorites
Not a fit when
- You need seller access, not a buyer account
- You have no Russian IP: Ozon blocks datacenter and VPN egress
- Multiple agents need to write to the same account at once: the server does not separate concurrent writes
Example request
Show my recent Ozon orders and what I ordered but never picked upLimitations
Ozon has no public personal API, the server relies on scraping internal endpoints and can break when they change. You need a Russian IP, a real Chromium (headless is detected, the image runs Xvfb) and at least 1 GB of /dev/shm. The Chromium profile is effectively a credential for the account and must never be committed. The endpoint has no authentication: whoever reaches the port gets the account. Per the README, scraping a personal account is against Ozon's terms of service, the project is stated for personal, low-volume use.
How to disable. Stop and remove the ozon-mcp Docker container and delete the server from your MCP client config.
MCP
- Transport
- stdio, http, sse
- Authentication
- not required
| Environment variables | |
|---|---|
| OZON_ENABLE_WRITES | Allows changing the cart, favorites, lists and cancelling orders |
| OZON_ENABLE_ORDERS | Separately allows place_order, which spends money |
| OZON_PROFILE_DIR secret | Persistent Chromium profile directory holding the account session |
Security check
- With OZON_ENABLE_ORDERS on it can spend money and place orders
- With OZON_ENABLE_WRITES on it changes the cart, favorites, lists and cancels orders
- The MCP endpoint does not check who connects to it
README in short
The README describes the tools by group (orders and returns, catalog, cart, favorites and selections, checkout, session and money), explains Ozon's non-obvious behavior (what counts as an order, the gap between today's charge and the order total, partial pay-on-delivery) and lists a table of environment variables. It separately notes limits: only saved addresses, no selection cover upload, and a card charge finishes on Ozon's own bank domain outside the server.
FAQ
Can the server spend money on its own?
Only if OZON_ENABLE_ORDERS is explicitly set, placing an order is disabled separately from other writes by default.
What happens if the session dies?
Every call reports it through session_status, and start_login plus submit_login_code restore it with a one-time code.
Related
A self-hosted knowledge base with block-level references and a built-in MCP server for connecting AI agents to your notes
A CLI for every Google Workspace API with JSON output and agent skills: Drive, Gmail, Calendar, Sheets and more
Local search over Markdown notes, docs and meeting transcripts: keywords, semantic search and reranking, with an MCP server
A task manager for AI-driven development: breaks a PRD into dependent tasks and guides the agent through them via MCP or CLI