Avito Monitor MCP

A remote MCP server with a single Avito search tool that returns only listings new since the last run

MCP server

Medium risk

We rate an entry medium when the tool runs code, makes network calls or reads project files. Check what exactly it does before installing.

Why this level

  • Bypasses Avito's protection by mimicking browser TLS fingerprints, which may violate the site's terms
  • The bearer token defaults to a 365-day lifetime and grants server access without signing in again
All reasons and checks
Russian stack

fisyuk/avitomcp

Install

Manual install

cp .env.example .env && python -m venv .venv && .venv/bin/pip install -e '.[dev]' && .venv/bin/python -m avito_mcp

Local run: first generate ACCESS_CODE and TOKEN_SECRET with the commands shown in the README.

This is third-party code. Review the repository files before installing.

What it does

The server gives an agent a single tool, search_avito: it searches listings by query and price range and returns only the ones absent from the previous call of the same search. It targets recurring jobs such as ChatGPT Scheduled Tasks, where the agent checks for new listings on its own schedule. Avito has no public API for this kind of search, so the server reads the plain HTML results page through curl_cffi with a browser TLS fingerprint to lower the chance of a QRATOR block, though it is not immune to it. SQLite stores only search history: the query, price limit and ids of listings already seen, with no prices, descriptions or HTML. Access is protected with OAuth 2.1 Authorization Code plus PKCE: you enter a shared ACCESS_CODE once and the server issues a long-lived bearer token.

Who it is for. For people who want an agent to watch Avito on its own for new listings matching a saved search.

Good fit when

  • You want regular checks of Avito for new listings by query and price without opening the site by hand
  • Your agent runs on a schedule, for example ChatGPT Scheduled Tasks
  • A single search tool is enough, no messaging or profile access needed

Not a fit when

  • You need guaranteed bypass of Avito blocks: curl_cffi lowers the chance of a 429 but does not remove it
  • You need messaging, posting listings or access to a personal account
  • You need production stability: the server is experimental and self-hosted

Example request

Check Avito once a day for new road bike listings under 40,000 rubles

Limitations

Avito has no official buyer API, so the server reads the public results page and can still get an HTTP 429 from QRATOR even with a browser TLS fingerprint. It needs its own hosting (Docker Compose), a public HTTPS domain for PUBLIC_BASE_URL, and manually generated ACCESS_CODE and TOKEN_SECRET values. The bearer token defaults to a 365-day lifetime. The project has zero stars and a single author, and the README only documents connecting it from ChatGPT Scheduled Tasks.

How to disable. Stop the container (docker compose down) and remove the server from your MCP client settings.

MCP

Transport
http
Authentication
OAuth
Environment variables
Environment variables
ACCESS_CODE
required, secret
Shared code for the first sign-in, after which a bearer token is issued
TOKEN_SECRET
required, secret
Secret used to sign issued bearer tokens
PUBLIC_BASE_URL
required
The server's external HTTPS origin, without a trailing /mcp

Security check

  • Bypasses Avito's protection by mimicking browser TLS fingerprints, which may violate the site's terms
  • The bearer token defaults to a 365-day lifetime and grants server access without signing in again

README in short

The README explains the constraint in detail (Avito has no buyer API), the block-bypass approach using curl_cffi with rotating browser profiles, exactly what SQLite stores, the OAuth 2.1 plus PKCE scheme used instead of API keys, and two ways to run it: locally via venv or through Docker Compose with a healthcheck.

FAQ

Does the server store the listings it finds?

No. SQLite keeps only the query, the price limit and opaque ids of listings already shown, with no prices, text or HTML.

Do I need an Avito API key?

No, the server reads the public search page. Instead of an Avito key, you set your own ACCESS_CODE to sign in to the MCP server itself.

Official

A self-hosted knowledge base with block-level references and a built-in MCP server for connecting AI agents to your notes

MCP serverMedium risk46.5KRepository stars
Editors’ pick

A CLI for every Google Workspace API with JSON output and agent skills: Drive, Gmail, Calendar, Sheets and more

CLIHigh risk31.2KRepository stars
Editors’ pick

Local search over Markdown notes, docs and meeting transcripts: keywords, semantic search and reranking, with an MCP server

CLIMedium riskNo VPN needed30.1KRepository stars
Editors’ pick

A task manager for AI-driven development: breaks a PRD into dependent tasks and guides the agent through them via MCP or CLI

MCP serverMedium risk28.1KRepository stars
Foxx AIAvito Monitor MCP

I am Foxx AI and I have already vetted this tool. Ask about install, setup or anything else, and I will keep it simple.