hh-mcp-pro: hh.ru via the Android app's OAuth

hh-mcp-pro

A FastMCP server with 43 hh.ru tools: signs in via the official hh.ru Android app's OAuth, no need to register your own app at dev.hh.ru

MCP server

High risk

We rate an entry high when the tool writes to external systems, handles money, production databases or secrets, or runs arbitrary commands. The CLI installs it only with your consent.

Why this level

  • apply_to_vacancy, apply_two_step and send_message write directly to the live account and employer correspondence
  • Logging in via the official hh.ru mobile app's OAuth instead of your own app may violate the service's terms
  • The token grants broad access to the job seeker's resumes, applications and correspondence
All reasons and checks
Russian stack

evgenygurin/hh-mcp-pro

Install

Manual install

uv sync && hh-mcp-pro --login

Installing dependencies and a one-time browser login, the commands from the README.

This is third-party code. Review the repository files before installing.

What it does

Instead of a normal OAuth app registration at dev.hh.ru, the server uses what it calls hhandroid-OAuth: authenticating as the official hh.ru mobile app, which removes the need to register your own app and wait for approval. The hh-mcp-pro --login command opens a browser to sign in and save a token; after that, 43 tools become available: vacancy and employer search, salary statistics, your own resumes, applying to a vacancy in one or two steps (apply_to_vacancy, apply_two_step), listing and reading negotiations, sending a message in a chat (send_message), reference data for regions, roles and industries, and analytics: TF-IDF scoring of a vacancy against a resume, a skills gap, salary-range statistics, and a cover-letter skeleton. The architecture is split into composition/application/domain/infra layers with OpenTelemetry tracing, readiness and liveness health endpoints, and mandatory bearer authorization for protected tools.

Who it is for. For developers who want a full set of job-seeker actions on hh.ru without registering their own OAuth app, and who accept the legal uncertainty of this login method.

Good fit when

  • You need a full set of job-seeker actions: search, one- or two-step apply, messaging, resumes, without waiting for dev.hh.ru app approval
  • You want built-in analytics: vacancy scoring, skills gap, a cover-letter skeleton
  • You're fine with a FastMCP v3 architecture with tracing and health checks for production deployment

Not a fit when

  • You don't want to sign in through the official hh.ru Android app's OAuth mechanism instead of your own registered app: this may violate hh.ru's terms
  • You're not ready for apply_to_vacancy and send_message to execute directly with no built-in confirmation step
  • You need a stable version: the README states both 35 and 43 tools in different places, and parts of the documentation are marked "deferred"

Example request

Find Python developer vacancies, score the top 3 against my resume, and draft a cover-letter skeleton

Limitations

The repository has no license registered on GitHub, though pyproject.toml and the README both state MIT. hhandroid-OAuth means signing in as the official hh.ru mobile app rather than through your own registered OAuth client, which sits in a gray area of hh.ru's API terms. The repository description and the README title disagree on the tool count: 35 in the repo description and plugin.json versus 43 in the main README text. A large share of the docs/notes documentation is marked "deferred," meaning not fully implemented.

How to disable. Remove the hh-mcp-pro block from your MCP client configuration and delete the token.json and state.json files holding the saved session.

MCP

Transport
stdio, http
Authentication
OAuth
Environment variables
Environment variables
HH_ACCESS_TOKEN
secret
A ready access token if you don't want to log in via the browser flow; takes the highest priority.
HH_JWT_PUBLIC_KEY
The public key for verifying the bearer token in the server's HTTP mode.

Security check

  • apply_to_vacancy, apply_two_step and send_message write directly to the live account and employer correspondence
  • Logging in via the official hh.ru mobile app's OAuth instead of your own app may violate the service's terms
  • The token grants broad access to the job seeker's resumes, applications and correspondence

README in short

The README describes a FastMCP 3.4.7 server with 43 tools across five namespaces: auth, vacancies, resumes, applications, dictionaries, plus analytics and diagnostics. It gives a table of every tool with call examples, the hhandroid-OAuth login sequence with token source priority, and composition/application/domain/infra architecture layers with OpenTelemetry and health endpoints. It separately describes FastMCP v3+ enhancements: lifespan management, middleware, a pooled httpx client. MIT license.

FAQ

Do I need to register an app at dev.hh.ru?

No, the server signs in via hhandroid-OAuth, the official hh.ru mobile app's mechanism, which replaces the usual app registration.

Can the server submit an application or message on its own?

Yes, the apply_to_vacancy, apply_two_step and send_message tools execute directly with no built-in confirmation step.

Official

A self-hosted knowledge base with block-level references and a built-in MCP server for connecting AI agents to your notes

MCP serverMedium risk46.5KRepository stars
Editors’ pick

A CLI for every Google Workspace API with JSON output and agent skills: Drive, Gmail, Calendar, Sheets and more

CLIHigh risk31.2KRepository stars
Editors’ pick

Local search over Markdown notes, docs and meeting transcripts: keywords, semantic search and reranking, with an MCP server

CLIMedium riskNo VPN needed30.1KRepository stars
Editors’ pick

A task manager for AI-driven development: breaks a PRD into dependent tasks and guides the agent through them via MCP or CLI

MCP serverMedium risk28.1KRepository stars
Foxx AIhh-mcp-pro: hh.ru via the Android app's OAuth

I am Foxx AI and I have already vetted this tool. Ask about install, setup or anything else, and I will keep it simple.