MoySklad Analytics with an MCP endpoint
MoySklad Analytics
A self-hosted MoySklad analytics dashboard (sales, stock, customers) with an MCP endpoint that gives an agent the same verified numbers shown on screen
Medium risk
We rate an entry medium when the tool runs code, makes network calls or reads project files. Check what exactly it does before installing.
Why this level
- MCP tools are structurally read-only, but they expose a full view of money and customers if authorization is weak
- The dashboard shows cost price and profit per product and customer, and requires mandatory Basic auth in production
Install
In your terminal, with SkillFoxx CLI
npx skillfoxx add mcp/moysklad-analyticsDetects the agents on your machine, checks the risk and pins the version.
Other ways to install
Run in a terminal
claude mcp add --transport http moysklad https://your-deployment.example.com/api/mcp --header 'Authorization: Bearer <your AUTHORIZATION>'Or add to the file .mcp.json, in the project
{
"mcpServers": {
"moysklad": {
"type": "http",
"url": "https://your-deployment.example.com/api/mcp",
"headers": {
"Authorization": "Bearer <your AUTHORIZATION>"
}
}
}
}If the file already exists, add the server inside the mcpServers key.
Keys and settings
AUTHORIZATIONsecret, required
Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.
The button opens the agent and offers to add the server. If nothing happens, copy the config below.
Add to the file ~/.cursor/mcp.json, for all projects
{
"mcpServers": {
"moysklad": {
"url": "https://your-deployment.example.com/api/mcp",
"headers": {
"Authorization": "Bearer <your AUTHORIZATION>"
}
}
}
}If the file already exists, add the server inside the mcpServers key. For a single project, put the same block into .cursor/mcp.json.
Keys and settings
AUTHORIZATIONsecret, required
Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.
The button opens the agent and offers to add the server. If nothing happens, copy the config below.
Run in a terminal
code --add-mcp '{"name":"moysklad","type":"http","url":"https://your-deployment.example.com/api/mcp","headers":{"Authorization":"Bearer <your AUTHORIZATION>"}}'Or add to the file .vscode/mcp.json, in the project
{
"servers": {
"moysklad": {
"type": "http",
"url": "https://your-deployment.example.com/api/mcp",
"headers": {
"Authorization": "Bearer <your AUTHORIZATION>"
}
}
}
}If the file already exists, add the server inside the servers key.
Keys and settings
AUTHORIZATIONsecret, required
Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.
Add to the file ~/.codex/config.toml, for all projects
[mcp_servers.moysklad]
url = "https://your-deployment.example.com/api/mcp"
http_headers = { Authorization = "Bearer <your AUTHORIZATION>" }If the file already exists, append the block to the end.
Keys and settings
AUTHORIZATIONsecret, required
Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.
Add to the file ~/.gemini/settings.json, for all projects
{
"mcpServers": {
"moysklad": {
"httpUrl": "https://your-deployment.example.com/api/mcp",
"headers": {
"Authorization": "Bearer <your AUTHORIZATION>"
}
}
}
}If the file already exists, add the server inside the mcpServers key.
Keys and settings
AUTHORIZATIONsecret, required
Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.
Add to the file ~/.config/devin/mcp_config.json, for all projects
{
"mcpServers": {
"moysklad": {
"serverUrl": "https://your-deployment.example.com/api/mcp",
"headers": {
"Authorization": "Bearer <your AUTHORIZATION>"
}
}
}
}If the file already exists, add the server inside the mcpServers key. Legacy Cascade keeps the MCP config in ~/.codeium/windsurf/mcp_config.json.
Keys and settings
AUTHORIZATIONsecret, required
Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.
Formerly Windsurf.
Add to the file cline_mcp_settings.json, for all projects
{
"mcpServers": {
"moysklad": {
"type": "streamableHttp",
"url": "https://your-deployment.example.com/api/mcp",
"headers": {
"Authorization": "Bearer <your AUTHORIZATION>"
}
}
}
}If the file already exists, add the server inside the mcpServers key. Open the settings file in Cline: MCP Servers tab, Configure MCP Servers.
Keys and settings
AUTHORIZATIONsecret, required
Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.
Add to the file .roo/mcp.json, in the project
{
"mcpServers": {
"moysklad": {
"type": "streamable-http",
"url": "https://your-deployment.example.com/api/mcp",
"headers": {
"Authorization": "Bearer <your AUTHORIZATION>"
}
}
}
}If the file already exists, add the server inside the mcpServers key.
Keys and settings
AUTHORIZATIONsecret, required
Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.
A fork of Roo Code, same .roo folders.
Add to the file opencode.json, in the project
{
"mcp": {
"moysklad": {
"type": "remote",
"url": "https://your-deployment.example.com/api/mcp",
"headers": {
"Authorization": "Bearer <your AUTHORIZATION>"
}
}
}
}If the file already exists, add the server inside the mcp key.
Keys and settings
AUTHORIZATIONsecret, required
Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.
Add to the file ~/.config/zed/settings.json, for all projects
{
"context_servers": {
"moysklad": {
"url": "https://your-deployment.example.com/api/mcp",
"headers": {
"Authorization": "Bearer <your AUTHORIZATION>"
}
}
}
}If the file already exists, add the server inside the context_servers key.
Keys and settings
AUTHORIZATIONsecret, required
Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.
Install dependencies with pnpm setup, set MOYSKLAD_TOKEN in .env, check the account with pnpm probe, deploy the server (pnpm dev for development or docker build for production), set MCP_TOKEN, and connect an agent with claude mcp add moysklad --transport http https://your-domain/api/mcp --header "Authorization: Bearer <MCP_TOKEN>".
Other ways from the author
pnpm setup && cp .env.example .envInstalls server and web dependencies, then set MOYSKLAD_TOKEN in .env.
This is third-party code. Review the repository files before installing.
What it does
The project is a full NestJS and React dashboard over the MoySklad JSON API 1.2: sales and profit by product, stock and restocking needs, customers and channels, trends over time. A separate pnpm probe command checks the token and its rights before trusting any figure, showing which reports the account can actually reach and whether cost price and profit are hidden by user permissions. A built-in DeepSeek AI assistant answers questions over the same data through seven read-only tools. For external agents there is a POST /api/mcp Streamable HTTP endpoint with the same seven analytics tools, plus seven business tools (documents, money, purchases, mutual settlements, counterparties, turnover) and a moysklad_api tool for reading any raw API path. All the money logic (minor units, the difference between markup and margin) is handled once in the stats service, so the dashboard, the built-in assistant and the external MCP cannot disagree on what "revenue" means.
Who it is for. For MoySklad store owners who want not just a chat with an agent but a full self-hosted dashboard with verified numbers and MCP as a bonus.
Good fit when
- You want a visual dashboard for sales, stock and customers, not just a chat with an agent
- You need to double-check the token's rights before trusting profit and margin figures
- You need MCP access to the same verified data for Claude, Cursor or ChatGPT connectors
Not a fit when
- You want just an MCP server with no full dashboard deployment: this is a self-hosted app with a NestJS backend and React frontend, there is no lightweight variant
- You are not ready to deploy via Docker and configure Basic auth: in production the server refuses to start without credentials set
- You need to write to MoySklad: moysklad_api and the other MCP tools are structurally read-only
Example request
Which products need restocking this week, and who are our biggest customers this quarterLimitations
This is not a lightweight MCP server but a full self-hosted app (NestJS + React), requiring Docker or your own server to deploy. The built-in AI assistant only works with a paid DeepSeek key. MoySklad limits the API to 45 requests per 3 seconds and 5 concurrent connections. If the token belongs to a restricted user, profit and margin columns come back empty rather than erroring.
How to disable. Stop the Docker container or server process and remove the MCP connection entry from your client (claude mcp remove moysklad or the equivalent command).
MCP
- Transport
- http
- Authentication
- OAuth
| Environment variables | |
|---|---|
| MOYSKLAD_TOKEN required, secret | MoySklad JSON API token |
| MCP_TOKEN secret | Enables the MCP endpoint, at least 24 characters, used both as a static bearer and the OAuth signing key |
| DASHBOARD_USER required | Dashboard Basic auth login, required in production |
| DASHBOARD_PASSWORD required, secret | Dashboard Basic auth password, required in production |
| DEEPSEEK_API_KEY secret | Enables the dashboard's built-in AI assistant |
Security check
- MCP tools are structurally read-only, but they expose a full view of money and customers if authorization is weak
- The dashboard shows cost price and profit per product and customer, and requires mandatory Basic auth in production
README in short
The README documents MoySklad API quirks confirmed on a live account in detail (money in minor units, the margin vs. salesMargin difference, differing href formats across reports), explains the DeepSeek model choice for the built-in assistant and why local models did not work out, and separately describes the MCP endpoint: a 15-tool surface, two auth methods (a static bearer and full MCP-spec OAuth), and mandatory Basic auth in production.
FAQ
Can the MCP tool change data in MoySklad?
No, both the seven business tools and the universal moysklad_api are structurally read-only, the API client only issues GET requests.
How do I connect from the Claude or ChatGPT mobile app?
Via OAuth: add a custom connector at /api/mcp, the app discovers the auth endpoints itself and asks you to sign in with the dashboard credentials.
Related
Salesforce's official DX MCP server: work with orgs, metadata, data, users and Apex tests from your agent
Yandex Kit skills for store management
kit-skills
Yandex's official skill set: catalog, prices, stock, orders, storefront and a weekly checkup for a Yandex Kit store, through Claude Code or Codex
YouGile MCP by Indalo
YouGile MCP
Full 65-operation YouGile API coverage with configurable permissions, write confirmation and a shared company rate limit
Bitrix24 portal MCP server
MCP-сервер портала Битрикс24
Bitrix24's official per-portal MCP: an external agent uses OAuth or a token to read and change tasks, deals, meetings and mail