Chestny Znak MCP: marking codes and emission

chestny-znak-mcp-ru

An MCP server for the Chestny Znak GIS MT and SUZ systems with 33 methods: marking code checks, emission, application reports and product routes by GTIN

MCP server

High risk

We rate an entry high when the tool writes to external systems, handles money, production databases or secrets, or runs arbitrary commands. The CLI installs it only with your consent.

Why this level

  • It can create code emission orders and submit application reports under the market participant's credentials
  • Errors in the unverified method map (verified: false) could lead to an incorrect call against a regulatory API
All reasons and checks
Russian stack

ilyautov/chestny-znak-mcp-ru

Install

In your terminal, with SkillFoxx CLI

npx skillfoxx add mcp/chestny-znak-mcp-ru

Detects the agents on your machine, checks the risk and pins the version.

Other ways to install

This entry is high risk, so there is no one-click install. Review the code and add the config by hand.

Run in a terminal

claude mcp add --transport stdio chestny-znak-mcp-ru -- uvx chestny-znak-mcp-ru==0.3.0

Or add to the file .mcp.json, in the project

{
  "mcpServers": {
    "chestny-znak-mcp-ru": {
      "command": "uvx",
      "args": [
        "chestny-znak-mcp-ru==0.3.0"
      ]
    }
  }
}

If the file already exists, add the server inside the mcpServers key.

Keys and settings

CRPT_TOKENsecret, optional
Токен ГИС МТ, выдаётся в обмен на данные, подписанные КЭП. Живёт около 10 часов.

Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.

Add to the file ~/.cursor/mcp.json, for all projects

{
  "mcpServers": {
    "chestny-znak-mcp-ru": {
      "command": "uvx",
      "args": [
        "chestny-znak-mcp-ru==0.3.0"
      ]
    }
  }
}

If the file already exists, add the server inside the mcpServers key. For a single project, put the same block into .cursor/mcp.json.

Keys and settings

CRPT_TOKENsecret, optional
Токен ГИС МТ, выдаётся в обмен на данные, подписанные КЭП. Живёт около 10 часов.

Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.

Run in a terminal

code --add-mcp '{"name":"chestny-znak-mcp-ru","type":"stdio","command":"uvx","args":["chestny-znak-mcp-ru==0.3.0"]}'

Or add to the file .vscode/mcp.json, in the project

{
  "servers": {
    "chestny-znak-mcp-ru": {
      "type": "stdio",
      "command": "uvx",
      "args": [
        "chestny-znak-mcp-ru==0.3.0"
      ]
    }
  }
}

If the file already exists, add the server inside the servers key.

Keys and settings

CRPT_TOKENsecret, optional
Токен ГИС МТ, выдаётся в обмен на данные, подписанные КЭП. Живёт около 10 часов.

Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.

Run in a terminal

codex mcp add chestny-znak-mcp-ru -- uvx chestny-znak-mcp-ru==0.3.0

Or add to the file ~/.codex/config.toml, for all projects

[mcp_servers.chestny-znak-mcp-ru]
command = "uvx"
args = ["chestny-znak-mcp-ru==0.3.0"]

If the file already exists, append the block to the end.

Keys and settings

CRPT_TOKENsecret, optional
Токен ГИС МТ, выдаётся в обмен на данные, подписанные КЭП. Живёт около 10 часов.

Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.

Run in a terminal

gemini mcp add -s user chestny-znak-mcp-ru uvx chestny-znak-mcp-ru==0.3.0

Or add to the file ~/.gemini/settings.json, for all projects

{
  "mcpServers": {
    "chestny-znak-mcp-ru": {
      "command": "uvx",
      "args": [
        "chestny-znak-mcp-ru==0.3.0"
      ]
    }
  }
}

If the file already exists, add the server inside the mcpServers key.

Keys and settings

CRPT_TOKENsecret, optional
Токен ГИС МТ, выдаётся в обмен на данные, подписанные КЭП. Живёт около 10 часов.

Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.

Add to the file ~/.config/devin/mcp_config.json, for all projects

{
  "mcpServers": {
    "chestny-znak-mcp-ru": {
      "command": "uvx",
      "args": [
        "chestny-znak-mcp-ru==0.3.0"
      ]
    }
  }
}

If the file already exists, add the server inside the mcpServers key. Legacy Cascade keeps the MCP config in ~/.codeium/windsurf/mcp_config.json.

Keys and settings

CRPT_TOKENsecret, optional
Токен ГИС МТ, выдаётся в обмен на данные, подписанные КЭП. Живёт около 10 часов.

Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.

Formerly Windsurf.

Add to the file cline_mcp_settings.json, for all projects

{
  "mcpServers": {
    "chestny-znak-mcp-ru": {
      "command": "uvx",
      "args": [
        "chestny-znak-mcp-ru==0.3.0"
      ]
    }
  }
}

If the file already exists, add the server inside the mcpServers key. Open the settings file in Cline: MCP Servers tab, Configure MCP Servers.

Keys and settings

CRPT_TOKENsecret, optional
Токен ГИС МТ, выдаётся в обмен на данные, подписанные КЭП. Живёт около 10 часов.

Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.

Add to the file .roo/mcp.json, in the project

{
  "mcpServers": {
    "chestny-znak-mcp-ru": {
      "command": "uvx",
      "args": [
        "chestny-znak-mcp-ru==0.3.0"
      ]
    }
  }
}

If the file already exists, add the server inside the mcpServers key.

Keys and settings

CRPT_TOKENsecret, optional
Токен ГИС МТ, выдаётся в обмен на данные, подписанные КЭП. Живёт около 10 часов.

Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.

A fork of Roo Code, same .roo folders.

Add to the file opencode.json, in the project

{
  "mcp": {
    "chestny-znak-mcp-ru": {
      "type": "local",
      "command": [
        "uvx",
        "chestny-znak-mcp-ru==0.3.0"
      ]
    }
  }
}

If the file already exists, add the server inside the mcp key.

Keys and settings

CRPT_TOKENsecret, optional
Токен ГИС МТ, выдаётся в обмен на данные, подписанные КЭП. Живёт около 10 часов.

Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.

Add to the file ~/.config/zed/settings.json, for all projects

{
  "context_servers": {
    "chestny-znak-mcp-ru": {
      "command": "uvx",
      "args": [
        "chestny-znak-mcp-ru==0.3.0"
      ]
    }
  }
}

If the file already exists, add the server inside the context_servers key.

Keys and settings

CRPT_TOKENsecret, optional
Токен ГИС МТ, выдаётся в обмен на данные, подписанные КЭП. Живёт около 10 часов.

Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.

Add to the file .codeassistant/mcp.json, in the project

{
  "mcpServers": {
    "chestny-znak-mcp-ru": {
      "command": "uvx",
      "args": [
        "chestny-znak-mcp-ru==0.3.0"
      ]
    }
  }
}

If the file already exists, add the server inside the mcpServers key.

Keys and settings

CRPT_TOKENsecret, optional
Токен ГИС МТ, выдаётся в обмен на данные, подписанные КЭП. Живёт около 10 часов.

Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.

You will need: uv

Checked against the repository on Sep 25, 2026, commit 4088302.

Text for your agent

Run the server with uvx chestny-znak-mcp-ru, obtain a CRPT_TOKEN by signing data with a КЭП in КриптоПро and exchanging it via POST /api/v3/true-api/auth/simpleSignIn, set it in your MCP client config, and verify with uvx chestny-znak-mcp-ru doctor.

Other ways from the author
uvx chestny-znak-mcp-ru

Runs without a separate package install.

This is third-party code. Review the repository files before installing.

What it does

A catalog of 33 True API and SUZ methods from the CRPT, assembled from open SDKs (there is no machine-readable spec in the documentation) and shipped right in the repository as endpoints.yaml, so the method table cannot drift from the code. Instead of 33 separate tools, the agent gets three: search for a method by words, describe a specific method with its parameters and access class, and call a method. Methods split into 24 reads and 9 writes, with no irreversible ones. Auth keys are never stored in plain text or sent outside the service's domain: a token is obtained by signing with a КЭП through КриптоПро on the user's own machine, and the server never sees the private key.

Who it is for. For participants in marked-goods circulation who need to check codes, track emission and review application reports directly from a chat with an agent.

Good fit when

  • You need to verify a batch of marking codes before accepting goods
  • You need to check the status of a code emission order in SUZ
  • You need to export codes belonging to a market participant or look up a product route by GTIN

Not a fit when

  • You have no GIS MT token obtained by signing with a КЭП: the server does not work without one
  • You need a different government traceability system, not Chestny Znak

Example request

Check this batch of marking codes before accepting the goods and show the emission order status

Limitations

The method catalog is assembled from open SDKs, not an official machine-readable spec, so every entry is marked verified: false, a map for exploration rather than a guaranteed-accurate description; paths are reliable, but verbs and parameters are worth checking against CRPT documentation. The CRPT_TOKEN lasts about 10 hours and needs a КЭП signature on the user's machine before each refresh.

How to disable. Remove the crpt-mcp entry from your MCP client config and delete the ~/.ru-mcp/cabinets.json file with saved cabinets.

MCP

Transport
stdio
Authentication
API key
Environment variables
Environment variables
CRPT_TOKEN
required, secret
GIS MT token, obtained in exchange for КЭП-signed data, lasts about 10 hours

Security check

  • It can create code emission orders and submit application reports under the market participant's credentials
  • Errors in the unverified method map (verified: false) could lead to an incorrect call against a regulatory API

README in short

The README explains where the method catalog comes from (open SDKs) and its status as an exploratory map, gives two install paths (an mcpb file or uvx), describes obtaining a token by signing with a КЭП, a method table by section with read/write counts, an example search-and-call dialog, a security section, and a separate privacy policy.

FAQ

Can I install it without a terminal?

Yes, there is a .mcpb file on the releases page that Claude Desktop installs with a double-click, prompting for keys in its own window.

Can anything be deleted irreversibly?

No, none of the 33 methods are irreversible, only reads and writes that require confirmation.

Editors’ pick

An MCP server with n8n node and template knowledge: the agent picks nodes, validates configs and, with API access, creates workflows in your n8n

MCP serverHigh riskNo VPN needed23KRepository stars
Official

Zapier's official MCP plugin: the agent gets actions across thousands of apps through your Zapier account

PluginHigh risk421Repository stars

A curated list of Claude skills and plugins, plus Composio's own automation skills for 78 SaaS apps

SkillHigh risk75.8KRepository stars

A plugin and CLI catalog for agents: generates command-line interfaces for GUI apps like GIMP and Blender and installs ready ones via CLI-Hub

PluginHigh riskNo VPN needed50.9KRepository stars
Foxx AIChestny Znak MCP: marking codes and emission

I am Foxx AI and I have already vetted this tool. Ask about install, setup or anything else, and I will keep it simple.