Max Bot MCP server
Max Bot MCP Server
An MCP server that reads a bot's messages in the Max messenger: chats, members, text search and attachment downloads
Medium risk
We rate an entry medium when the tool runs code, makes network calls or reads project files. Check what exactly it does before installing.
Why this level
- Reads private messages and attachments from every chat the bot has access to
- The bot token grants full chat access until revoked
Install
Manual install
claude mcp add max-bot -- env MAX_BOT_TOKEN=ваш_токен_бота python server.pyCommand from the README, requires pip install -r requirements.txt beforehand.
This is third-party code. Review the repository files before installing.
What it does
The server wraps the Max Bot API in six read-only tools: list the bot's chats, list a chat's members, fetch messages with date filters and pagination, case-insensitive text search, and download audio or any file attachment. It cannot send messages as the bot. Search is capped at 5000 scanned messages by default, all HTTP requests to Max have a timeout, and file downloads are guarded against path traversal.
Who it is for. For developers who already run a bot in Max and want to give Claude Code access to its chats for analysis and search.
Good fit when
- You want to find messages by keyword in a Max bot's chats
- You want to pull messages for a date range with pagination
- You need to download an attachment from a message in a specific chat
Not a fit when
- You need to send messages or reply as the bot: the server is read-only
- You need access to a personal Max account rather than a bot
Example request
Find messages containing the word report in chat 12345 from the last weekLimitations
The project is very small: a single server.py file, 1 star, one author. There is no npm or pip package install and no tests. You need your own Max bot with a token from @MasterBot.
How to disable. Remove the server with claude mcp remove max-bot and revoke the bot token via @MasterBot if needed.
MCP
- Transport
- stdio
- Authentication
- API key
| Environment variables | |
|---|---|
| MAX_BOT_TOKEN required, secret | Max bot token, issued via @MasterBot |
Security check
- Reads private messages and attachments from every chat the bot has access to
- The bot token grants full chat access until revoked
README in short
A short Russian README describes six tools, installation via pip install -r requirements.txt, and connecting with claude mcp add and the MAX_BOT_TOKEN variable. A separate security section mentions the token passed only through an environment variable, path traversal protection on file downloads, a scan limit for search and request timeouts.
FAQ
Can the server send a message as the bot?
No, all tools only read chats, members and messages.
How many messages does search scan?
Up to 5000 messages per chat by default, a limit set in the server code.
Related
A skill that strips AI writing tells from text using Wikipedia's list, without adding invented facts
Marketing Skills for AI agents
Marketing Skills for AI Agents
About fifty skills for CRO, copywriting, SEO, analytics, ads and launches, built for coding agents
SendPulse MCP server
SendPulse MCP
SendPulse's official remote MCP server: statistics, campaigns and user data through an agent chat
Yandex Direct MCP generated from a machine-readable schema
yandex-direct-mcp
An MCP server and CLI covering all 113 Yandex Direct API v5 methods generated from WSDL, exposing 9 read tools by default and writes only on demand