Habr Career MCP server
habr-mcp
An MCP server that edits your own career.habr.com profile using a session cookie, because the official API is read-only
High risk
We rate an entry high when the tool writes to external systems, handles money, production databases or secrets, or runs arbitrary commands. The CLI installs it only with your consent.
Why this level
- Uses a session cookie that grants full access to the Habr Career account
- Writes to the profile through site forms rather than the official API
Install
In your terminal, with SkillFoxx CLI
npx skillfoxx add mcp/habr-mcpDetects the agents on your machine, checks the risk and pins the version.
Other ways to install
Assembled automatically, review before installing.
This entry is high risk, so there is no one-click install. Review the code and add the config by hand.
Run in a terminal
claude mcp add --transport stdio --env 'HABR_COOKIE=<your HABR_COOKIE>' habr-mcp -- uvx run --script server.pyOr add to the file .mcp.json, in the project
{
"mcpServers": {
"habr-mcp": {
"command": "uvx",
"args": [
"run",
"--script",
"server.py"
],
"env": {
"HABR_COOKIE": "<your HABR_COOKIE>"
}
}
}
}If the file already exists, add the server inside the mcpServers key.
Keys and settings
HABR_COOKIEsecret, required- Cookie from career.habr.com (_career_session and remember_user_token)
Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.
Add to the file ~/.cursor/mcp.json, for all projects
{
"mcpServers": {
"habr-mcp": {
"command": "uvx",
"args": [
"run",
"--script",
"server.py"
],
"env": {
"HABR_COOKIE": "<your HABR_COOKIE>"
}
}
}
}If the file already exists, add the server inside the mcpServers key. For a single project, put the same block into .cursor/mcp.json.
Keys and settings
HABR_COOKIEsecret, required- Cookie from career.habr.com (_career_session and remember_user_token)
Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.
Run in a terminal
code --add-mcp '{"name":"habr-mcp","type":"stdio","command":"uvx","args":["run","--script","server.py"],"env":{"HABR_COOKIE":"<your HABR_COOKIE>"}}'Or add to the file .vscode/mcp.json, in the project
{
"servers": {
"habr-mcp": {
"type": "stdio",
"command": "uvx",
"args": [
"run",
"--script",
"server.py"
],
"env": {
"HABR_COOKIE": "<your HABR_COOKIE>"
}
}
}
}If the file already exists, add the server inside the servers key.
Keys and settings
HABR_COOKIEsecret, required- Cookie from career.habr.com (_career_session and remember_user_token)
Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.
Run in a terminal
codex mcp add habr-mcp --env 'HABR_COOKIE=<your HABR_COOKIE>' -- uvx run --script server.pyOr add to the file ~/.codex/config.toml, for all projects
[mcp_servers.habr-mcp]
command = "uvx"
args = ["run", "--script", "server.py"]
env = { HABR_COOKIE = "<your HABR_COOKIE>" }If the file already exists, append the block to the end.
Keys and settings
HABR_COOKIEsecret, required- Cookie from career.habr.com (_career_session and remember_user_token)
Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.
Add to the file ~/.gemini/settings.json, for all projects
{
"mcpServers": {
"habr-mcp": {
"command": "uvx",
"args": [
"run",
"--script",
"server.py"
],
"env": {
"HABR_COOKIE": "<your HABR_COOKIE>"
}
}
}
}If the file already exists, add the server inside the mcpServers key.
Keys and settings
HABR_COOKIEsecret, required- Cookie from career.habr.com (_career_session and remember_user_token)
Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.
Add to the file ~/.config/devin/mcp_config.json, for all projects
{
"mcpServers": {
"habr-mcp": {
"command": "uvx",
"args": [
"run",
"--script",
"server.py"
],
"env": {
"HABR_COOKIE": "<your HABR_COOKIE>"
}
}
}
}If the file already exists, add the server inside the mcpServers key. Legacy Cascade keeps the MCP config in ~/.codeium/windsurf/mcp_config.json.
Keys and settings
HABR_COOKIEsecret, required- Cookie from career.habr.com (_career_session and remember_user_token)
Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.
Formerly Windsurf.
Add to the file cline_mcp_settings.json, for all projects
{
"mcpServers": {
"habr-mcp": {
"command": "uvx",
"args": [
"run",
"--script",
"server.py"
],
"env": {
"HABR_COOKIE": "<your HABR_COOKIE>"
}
}
}
}If the file already exists, add the server inside the mcpServers key. Open the settings file in Cline: MCP Servers tab, Configure MCP Servers.
Keys and settings
HABR_COOKIEsecret, required- Cookie from career.habr.com (_career_session and remember_user_token)
Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.
Add to the file .roo/mcp.json, in the project
{
"mcpServers": {
"habr-mcp": {
"command": "uvx",
"args": [
"run",
"--script",
"server.py"
],
"env": {
"HABR_COOKIE": "<your HABR_COOKIE>"
}
}
}
}If the file already exists, add the server inside the mcpServers key.
Keys and settings
HABR_COOKIEsecret, required- Cookie from career.habr.com (_career_session and remember_user_token)
Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.
A fork of Roo Code, same .roo folders.
Add to the file opencode.json, in the project
{
"mcp": {
"habr-mcp": {
"type": "local",
"command": [
"uvx",
"run",
"--script",
"server.py"
],
"environment": {
"HABR_COOKIE": "<your HABR_COOKIE>"
}
}
}
}If the file already exists, add the server inside the mcp key.
Keys and settings
HABR_COOKIEsecret, required- Cookie from career.habr.com (_career_session and remember_user_token)
Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.
Add to the file ~/.config/zed/settings.json, for all projects
{
"context_servers": {
"habr-mcp": {
"command": "uvx",
"args": [
"run",
"--script",
"server.py"
],
"env": {
"HABR_COOKIE": "<your HABR_COOKIE>"
}
}
}
}If the file already exists, add the server inside the context_servers key.
Keys and settings
HABR_COOKIEsecret, required- Cookie from career.habr.com (_career_session and remember_user_token)
Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.
Add to the file .codeassistant/mcp.json, in the project
{
"mcpServers": {
"habr-mcp": {
"command": "uvx",
"args": [
"run",
"--script",
"server.py"
],
"env": {
"HABR_COOKIE": "<your HABR_COOKIE>"
}
}
}
}If the file already exists, add the server inside the mcpServers key.
Keys and settings
HABR_COOKIEsecret, required- Cookie from career.habr.com (_career_session and remember_user_token)
Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.
Grab the _career_session and remember_user_token cookies from browser DevTools on career.habr.com, put them in the HABR_COOKIE variable, then connect the server with uv run --script server.py in your MCP client config.
Other ways from the author
uv run --script server.py --checkChecks whether the HABR_COOKIE is still valid and prints the login.
This is third-party code. Review the repository files before installing.
What it does
Habr Career's official OAuth API is read-only, so the server writes the way a browser does: through Rails forms with a CSRF token and the user's session cookie. Its tools let you check whether the cookie is still valid, fetch the HTML or JSON of any profile page with scripts and styles stripped out, parse a form's schema with current values and options, submit only the fields you want while leaving the rest untouched, and ask the user a clarifying question via elicitation. A submit response is explicitly marked SAVED or NOT SAVED with a reason, because Rails returns validation errors with an HTTP 200 status.
Who it is for. For people who want to update their own Habr Career profile through an agent instead of filling out forms on the site by hand.
Good fit when
- You want to quickly update salary expectations, skills or job search status in your profile
- You need to see what fields a specific profile form has before changing it
- You want to change one field without touching the rest of the profile
Not a fit when
- You need access to someone else's profile: the server only works with the account owner's own session cookie
- You want profile access without a browser cookie: the official API is read-only for that
Example request
Update my Habr Career profile's salary expectation to 500000 rublesLimitations
The project has a single author, no license or releases, and requires manually pulling the _career_session and remember_user_token cookies from browser DevTools. The cookie is valid for a limited time, roughly until September per the author, after which the server reports an anonymous status and the cookie must be refreshed by hand. There is deliberately no typed resume-creation tool; the page itself is used as the schema.
How to disable. Remove the habr entry from your MCP client config and, if needed, revoke the Habr Career session on the site.
MCP
- Transport
- stdio
- Authentication
- API key
| Environment variables | |
|---|---|
| HABR_COOKIE required, secret | The _career_session and remember_user_token cookies from the browser, granting access to the user's account. |
Security check
- Uses a session cookie that grants full access to the Habr Career account
- Writes to the profile through site forms rather than the official API
README in short
The README explains why a session cookie is needed instead of the official API, gives commands for obtaining and checking the cookie and wiring the server into an MCP client. It describes four tools: session check, page read, form parsing and field submission with an explicit save status. It ends with a list of tests, some of which need a real account and change a live profile.
FAQ
Why doesn't the server use the official Habr Career API?
The official OAuth API is read-only, and profile changes are only possible through web forms, so the server mimics browser behavior with a CSRF token.
Can changing one field accidentally wipe other profile data?
No, habr_submit only sends the fields you pass and resends the rest as they are, including Vue-driven fields like skills and languages.
Related
A self-hosted knowledge base with block-level references and a built-in MCP server for connecting AI agents to your notes
A CLI for every Google Workspace API with JSON output and agent skills: Drive, Gmail, Calendar, Sheets and more
Local search over Markdown notes, docs and meeting transcripts: keywords, semantic search and reranking, with an MCP server
A task manager for AI-driven development: breaks a PRD into dependent tasks and guides the agent through them via MCP or CLI