moysklad-mcp-ru

A MoySklad MCP server with two write gates: stock, profit, reports and draft documents over JSON API 1.2

MCP server

High risk

We rate an entry high when the tool writes to external systems, handles money, production databases or secrets, or runs arbitrary commands. The CLI installs it only with your consent.

Why this level

  • Write tools create, post and delete documents in live accounting
  • The account token moves stock and money once writing is enabled
All reasons and checks
Russian stack

marfarin/moysklad-mcp-ru

Install

Manual install

Text for your agent

установи МойСклад MCP

The simplest method from the README: tell this to Claude or Cowork, and it runs the bundled install-skill.

This is third-party code. Review the repository files before installing.

What it does

The server gives an agent direct access to a MoySklad account's JSON API 1.2 without a browser, claiming 32 tools and 70 offline tests. Eight meta-tools (search a method, describe it, call it, raw call, fetch all pages and more) work over a catalog of 892 methods built from the official MoySklad documentation. There are also typed read tools for stock, products, orders, profit, turnover, cash, counterparties, warehouses and documents, with amounts auto-converted from kopecks to rubles. Writing documents goes through two independent safety layers: a process-level MOYSKLAD_ALLOW_WRITE flag, off by default, and mandatory confirmation on every call. Creating always produces a draft, and posting or deleting a document needs separate explicit consent. The server's core is a vendored engine from the open-source ilyautov/marketplaces-mcp-ru project, MIT-licensed and unmodified by this author, with MoySklad-specific logic built on top.

Who it is for. For MoySklad business owners and accountants who want full API access with protection against accidentally writing to live accounting.

Good fit when

  • You need access to all 892 MoySklad API methods, not just standard reports
  • You need maximum protection against accidentally posting a document in a live account
  • You want installation without hand-editing JSON, via the built-in install-skill or a script

Not a fit when

  • You are not ready for alpha status: some imported methods are not battle-tested
  • You need a long-stable 1.0 release rather than 0.1.0

Example request

Create a draft receipt of 10 units from Supplier LLC at 250 rubles on the test account

Limitations

The author marks the project alpha: the curated core and write path are battle-tested on a test account, while methods imported from documentation are an exploration map, and write bodies should be checked against docs or called via ms_call_raw. 0 stars, version 0.1.0. The core/ folder is a vendored, unmodified engine from another open-source project (ilyautov/marketplaces-mcp-ru), not this repository author's own original code.

How to disable. Remove the ms server from your agent config and delete ~/.moysklad-mcp/cabinets.json with the stored tokens.

MCP

Transport
stdio
Authentication
API key
Environment variables
Environment variables
MOYSKLAD_ALLOW_WRITE
Enables write capability, off by default
MOYSKLAD_WRITE_CABINETS
Optional list of cabinets allowed to write

Security check

  • Write tools create, post and delete documents in live accounting
  • The account token moves stock and money once writing is enabled

README in short

The Russian README with an English version alongside describes a scheme of 8 meta-tools over a method catalog, typed read tools, a safety model with two independent write-protection layers, three install paths (via an AI, a release archive with install.command, or install.py per client), kopeck-to-ruble conversion, MoySklad API limits (a 45-requests-per-3-seconds bucket), and an honest caveats section about the reliability of imported methods. MIT licensed.

FAQ

Can the server accidentally post a document?

No, posting and deleting is a separate destructive step requiring MOYSKLAD_ALLOW_WRITE=1 plus explicit confirmation on that specific call.

What is the core folder?

It is an unmodified vendored engine from the open-source ilyautov/marketplaces-mcp-ru project under MIT, with the rest of the MoySklad logic built on top.

Editors’ pick

The official FastAPI skill, bundled with the package, teaching agents to write code for the installed version

SkillLow riskNo VPN needed102.7KRepository stars
Editors’ pick

Official skills and agents from the .NET team: performance, MSBuild, NuGet, upgrades, testing, ASP.NET Core, Blazor and MAUI

PluginMedium risk5.5KRepository stars

Firebase MCP Server

Firebase CLI and MCP Server

Official

Official Firebase MCP server from the Firebase CLI: projects, Firestore, Auth, Crashlytics, Remote Config and function logs

MCP serverHigh riskNeeds a VPN4.5KRepository stars
Official

Laravel's official MCP server, guidelines and skills: the agent sees the DB schema, logs and package versions and searches ecosystem docs

MCP serverMedium risk3.6KRepository stars
Foxx AImoysklad-mcp-ru

I am Foxx AI and I have already vetted this tool. Ask about install, setup or anything else, and I will keep it simple.