iiko-mcp: iikoTransport API request debugging
iiko-mcp
A lightweight MCP server for manually debugging the iikoTransport API (api-ru.iiko.services) with v2 authorization and a universal arbitrary-request tool
Medium risk
We rate an entry medium when the tool runs code, makes network calls or reads project files. Check what exactly it does before installing.
Why this level
- iiko_request can call any API method, including potentially data-changing ones, with no built-in confirmation
- iiko credentials (apiKey, appId, clientSecret) are stored in the client config or .env and must stay secret
Install
Manual install
git clone https://github.com/steamn/iiko-mcp.git && cd iiko-mcp && npm install && npm run buildSetup and build from the README.
This is third-party code. Review the repository files before installing.
What it does
The server authenticates to iikoTransport using the new v2 scheme (POST /api/v2/access_token with apiKey, appId and clientSecret), gets a one-hour JWT and caches it in memory, since the old /api/1/access_token scheme is being phased out by iiko. Six tools: iiko_request is a universal call to any method, path and body with automatic authorization, returning the status, correlationId and response body; iiko_access_token fetches or refreshes a token for debugging authorization itself; iiko_organizations, iiko_nomenclature, iiko_stop_lists and iiko_deliveries_by_id are ready shortcuts for the corresponding /api/1 endpoints. The iiko_request tool lets you call any method from iiko's documentation, even one with no dedicated tool yet.
Who it is for. For developers integrating the iikoTransport API who want a quick way to manually hit an endpoint and see the raw response from an agent, without Postman.
Good fit when
- You need to manually debug a specific iikoTransport API request and see the raw response with correlationId
- You need a ready shortcut for organizations, nomenclature, stop lists or deliveries by id
- You need access to an endpoint with no dedicated tool yet, via iiko_request
Not a fit when
- You need a ready toolset covering dozens of operations rather than a debugging minimum of six
- You don't want the agent able to call an arbitrary write method via iiko_request with no built-in confirmation
- You need classic iikoServer login/password authorization: this is specifically iikoTransport with an api key, app id and client secret
Example request
Call POST /api/1/nomenclature for organization X and show the raw responseLimitations
The project explicitly positions itself as a manual debugging tool, not a production integration. iiko_request doesn't restrict which methods can be called, so it can reach write endpoints too, with no separate server-level confirmation. The author explicitly warns not to commit real apiKey and clientSecret values, keeping them only in .env or the client config outside the repository.
How to disable. Remove the iiko block from your MCP client configuration (.cursor/mcp.json or claude_desktop_config.json).
MCP
- Transport
- stdio
- Authentication
- API key
| Environment variables | |
|---|---|
| IIKO_API_LOGIN required, secret | The API key (apiKey) from iikoWeb, under Integrations → API keys. |
| IIKO_APP_ID required, secret | The appId, issued on iiko's developer portal. |
| IIKO_CLIENT_SECRET required, secret | The clientSecret from the developer portal, shown once when the app is created. |
Security check
- iiko_request can call any API method, including potentially data-changing ones, with no built-in confirmation
- iiko credentials (apiKey, appId, clientSecret) are stored in the client config or .env and must stay secret
README in short
The bilingual README describes an MCP server for manually debugging the iikoTransport API with v2 authorization, steps to get the apiKey and appId/clientSecret, an environment variable table, and two ways to pass credentials: the client's env block or a .env file. It lists six tools with an emphasis on the universal iiko_request, gives configs for Cursor and Claude Desktop, and a security section about keeping secrets out of the repository. MIT license.
FAQ
How does v2 authorization differ from the old one?
v2 uses POST /api/v2/access_token with apiKey, appId and clientSecret and issues an hour-long JWT; the old /api/1/access_token scheme is being disabled by iiko.
Can I call an endpoint with no ready shortcut?
Yes, iiko_request accepts any method, path and body and handles authorization itself.
Related
An MCP server with n8n node and template knowledge: the agent picks nodes, validates configs and, with API access, creates workflows in your n8n
Zapier's official MCP plugin: the agent gets actions across thousands of apps through your Zapier account
Awesome Claude Skills by Composio
Awesome Claude Skills
A curated list of Claude skills and plugins, plus Composio's own automation skills for 78 SaaS apps
A plugin and CLI catalog for agents: generates command-line interfaces for GUI apps like GIMP and Blender and installs ready ones via CLI-Hub