iikocloud-mcp: 236 iikoCloud methods with a write gate
iikocloud-mcp
An MCP server for the iikoCloud API: pick the needed subset from 236 methods by domain, defaults to read-only, confirms before every write
Medium risk
We rate an entry medium when the tool runs code, makes network calls or reads project files. Check what exactly it does before installing.
Why this level
- Write tools (orders, deliveries, banquets) actually write to a live iikoCloud account after confirmation
- Read-only by default plus a mandatory server-side gate substantially reduce the risk of an accidental write
Install
Manual install
uv pip install "iikocloud-mcp @ git+https://github.com/uservanya/iikocloud-mcp.git"Installing as a package, giving the iikocloud-mcp command on PATH.
This is third-party code. Review the repository files before installing.
What it does
The server is built by introspecting a separate IikoCloudApiClientManager package, turning 236 iikoCloud methods across 22 domains (organizations, menu, deliveries, employees, orders, banquets, discounts, webhooks and more) into MCP tools, but it starts with a chosen subset rather than the whole catalog at once: the full set costs about 439 KB of context, read-only alone about 124 KB. iikoCloud secrets (api_key, app_id, client_secret) travel only through the transport channel (HTTP headers under TLS or environment variables for stdio) and never appear as tool arguments, so the model never sees them and they're never logged. The server is read-only by default; writes are enabled with --allow-write, and every write tool additionally requires user confirmation through server-side MCP elicitation, a server gate, not just a client hint, and it can't be bypassed by a client that auto-approves tool calls. The server also points to where a required ID parameter comes from, flags asynchronous commands that need a separate status poll, caches slow reference lookups, and truncates oversized responses cleanly instead of cutting them off.
Who it is for. For restaurant chains and individual venues on iikoCloud who want safe-by-default access to menus, orders and deliveries from an agent, with explicit control over what can be written.
Good fit when
- You need access to part of the iikoCloud API (say, only menu and organizations) without bloating the model's context with all 236 methods
- It matters that writes only happen after explicit user confirmation, not the model's own decision
- You serve several iikoCloud accounts from one server and don't want a separate process per account
Not a fit when
- You need the older iikoServer with a login and password: that's a separate project by the same author, iikoserver-mcp; this one is specifically the cloud API with auth v2
- You want to run the server with all 236 tools at once with no domain split: the author explicitly advises against it for context size and write surface
- You don't have time to set up a TLS proxy for HTTP transport: the server does no encryption itself and needs a reverse proxy for external access
Example request
Show the menu and active organizations, but don't change anything without my confirmationLimitations
The repository has no stated license. It depends on two separate packages by the same author (iikocloud-manager and iikocloud-client) installed directly from Git rather than PyPI. The server introduces no organization- or app_id-level restrictions of its own: access is governed by the iikoCloud account's own settings. HTTP mode without a TLS proxy sends credentials in headers as plain text, which is why it listens on 127.0.0.1 only by default.
How to disable. Remove the iikocloud block from mcpServers in your client configuration and stop the server process if it runs separately.
MCP
- Transport
- stdio, http
- Authentication
- API key
| Environment variables | |
|---|---|
| IIKOCLOUD_API_KEY required, secret | The iikoCloud account API key. |
| IIKOCLOUD_APP_ID required, secret | The iikoCloud auth v2 application id. |
| IIKOCLOUD_CLIENT_SECRET required, secret | The client secret for the iikoCloud auth v2 application. |
| IIKOCLOUD_MCP_DOMAINS | A comma-separated list of allowed tool domains, empty by default (no tools). |
| IIKOCLOUD_MCP_ALLOW_WRITE | Enables write operations, off by default (read-only). |
Security check
- Write tools (orders, deliveries, banquets) actually write to a live iikoCloud account after confirmation
- Read-only by default plus a mandatory server-side gate substantially reduce the risk of an accidental write
README in short
The README explains the safety model in detail: secrets only through the transport channel, read-only by default, a server-side write confirmation gate via MCP elicitation, and tool selection by domain, operation type, allow-glob or deny-glob from CLI, env or YAML. It shows context-weight tables for different subsets, TTL reference-data caching, response-truncation and call-timeout handling, and built-in model hints about async commands and ID sources. It separately mentions a direct counterpart for iikoServer (iikoserver-mcp) by the same author.
FAQ
Can the model bypass write confirmation?
No, confirmation is implemented server-side via MCP elicitation, not as a client hint, and a client that auto-approves tools still won't execute a write without a user response.
Why limit domains instead of running all 236 tools?
The README's own table shows the context cost: all tools cost about 439 KB per connection, while selected domains alone cost far less, and also shrink the write surface.
Related
An MCP server with n8n node and template knowledge: the agent picks nodes, validates configs and, with API access, creates workflows in your n8n
Zapier's official MCP plugin: the agent gets actions across thousands of apps through your Zapier account
Awesome Claude Skills by Composio
Awesome Claude Skills
A curated list of Claude skills and plugins, plus Composio's own automation skills for 78 SaaS apps
A plugin and CLI catalog for agents: generates command-line interfaces for GUI apps like GIMP and Blender and installs ready ones via CLI-Hub