Go Wordstat MCP with its own OAuth
yandex-wordstat-mcp
A Go MCP server for Yandex Wordstat with three tools and a built-in OAuth server protecting remote access
Low risk
We rate an entry low when it mostly gives the agent instructions and reference material.
Why this level
- Only reads Wordstat query statistics, does not change anything in external systems
Install
Manual install
go build -o yandex-wordstat-mcp ./cmd/yandex-wordstat-mcpBuild from source, set YANDEX_API_KEY and YANDEX_FOLDER_ID before running.
This is third-party code. Review the repository files before installing.
What it does
The server provides three tools: top requests with options for exact word form and fixed phrase order, frequency dynamics by day, week or month over a period, and the full Wordstat region tree. It is written in Go on the official modelcontextprotocol/go-sdk, exposing a Streamable HTTP MCP on /mcp and a health check on /healthz. The server has its own built-in OAuth 2.0 layer with authorization code, PKCE and dynamic client registration, protecting the /mcp endpoint separately from the Yandex key. The Yandex key and folder id are set via environment variables and required at startup.
Who it is for. For people who want a self-hosted Go Wordstat server with access protected by a separate OAuth layer
Good fit when
- You want a compact Go binary without a Node or Python runtime
- You need a remote HTTP MCP server protected by its own OAuth authorization
- The basics are enough: top requests, dynamics, region tree
Not a fit when
- You need a regional distribution as a separate tool: it is not here
- You need ready install documentation: the repository has no README
Example request
Show the monthly dynamics for the query "apartment renovation" over the last yearLimitations
The repository has no README and no stars, with a single author. It can only be installed by building from Go source, no ready binary release is documented. The OAuth layer adds setup complexity for those who just want a simple local run.
How to disable. Stop the server process and remove it from your MCP client config.
MCP
- Transport
- http
- Authentication
- OAuth
| Environment variables | |
|---|---|
| YANDEX_API_KEY required, secret | Yandex Search API key for Wordstat |
| YANDEX_FOLDER_ID required | Yandex Cloud folder id |
Security check
- Only reads Wordstat query statistics, does not change anything in external systems
README in short
There is no README. This description is based on the code: go.mod references the official modelcontextprotocol/go-sdk, main.go registers three tools (top, dynamics, region tree) and starts an HTTP server with an OAuth-protected handler on /mcp and a health check on /healthz, while oauth.go implements authorization code with PKCE and in-memory client and token storage.
FAQ
Is there a regional impressions tool?
No, only the wordstat_regions_tree region tree; there is no separate regional distribution tool in the code.
Why does it have built-in OAuth?
It protects the /mcp HTTP endpoint with separate client authorization instead of relying only on the Yandex key in environment variables.
Related
Official DataLens (Yandex) skills for Claude Code, Codex and OpenCode: SDK, HTML reports and RLS resolution
A Yandex Metrika MCP server generated from the API spec: 108 methods, 10 tools declared by default, transparent filters and response metadata
An open MCP server and agent skill set for SEO: keyword research, competitors, backlinks and site audits powered by DataForSEO
A Claude Code plugin for SEO audits: technical SEO, E-E-A-T, schema, local and AI search via parallel subagents