Production-grade Ozon Seller MCP server
Ozon Seller MCP Server
An MCP server for the Ozon Seller API with a PostgreSQL audit log, Redis caching and rate limits, a circuit breaker and a no-key demo mode
High risk
We rate an entry high when the tool writes to external systems, handles money, production databases or secrets, or runs arbitrary commands. The CLI installs it only with your consent.
Why this level
- Bulk-updates product prices and stock in the live account
- Stores credentials and a log of every operation in its own PostgreSQL database
Install
Manual install
docker compose up -dBrings up the server together with Redis and PostgreSQL; keys go in .env.
This is third-party code. Review the repository files before installing.
What it does
The server provides 13 tools for the Ozon Seller API: product cards, warehouse stock, bulk price and stock updates, archiving, FBS and FBO orders, sales analytics, financial reports and a warehouse list. Around the API sits a six-layer defense: input validation, credential masking in logs, rate limiting, a PostgreSQL audit log of every call with response time and trace ID, a circuit breaker that cuts off Ozon calls after a run of failures, and SSRF protection. Write tools are marked destructiveHint, so clients like Claude Desktop prompt for confirmation before running them. A DEMO_MODE=true mode ships mock data and needs no Ozon keys, Redis or PostgreSQL at all.
Who it is for. For teams that need not just a working server but a production setup with audit logging and defenses around the Ozon Seller API.
Good fit when
- You need an audit log of every Ozon Seller API call for later review
- You need rate limiting and automatic cutoff during Ozon outages
- You want to try the tools on mock data first, without a real Ozon account
Not a fit when
- You want a simple server with no infrastructure: full operation here needs PostgreSQL and Redis (outside demo mode)
- You do not want to run Docker Compose: a local uv run is possible, but the README is built around docker compose up
Example request
Show this week's sales analytics and update stock for products the warehouse shows as zeroLimitations
Full operation needs PostgreSQL and Redis running, which is noticeably heavier than single-file alternatives. POSTGRES_PASSWORD is required with no default value. The README calls the project the first MCP server for the Ozon Seller API, though several independent implementations already exist.
How to disable. Stop docker compose (docker compose down) and remove the server from your MCP client config.
MCP
- Transport
- stdio
- Authentication
- API key
| Environment variables | |
|---|---|
| OZON_CLIENT_ID required | Seller Client Id from the Ozon Seller dashboard. |
| OZON_API_KEY required, secret | Seller Api Key from the same pair. |
| POSTGRES_PASSWORD required, secret | Password for the audit log database, required with no default. |
| DEMO_MODE | true runs the server on mock data with no real keys or infrastructure. |
Security check
- Bulk-updates product prices and stock in the live account
- Stores credentials and a log of every operation in its own PostgreSQL database
README in short
The English README, with an architecture diagram, shows six defense layers, OWASP MCP Top 10 compliance, a Redis cache with write-time invalidation, and a PostgreSQL audit log. It gives a table of the 13 tools with read/write type and the matching Ozon endpoint, docker compose and local uv run instructions, and a demo mode with no real keys.
FAQ
Can I try it without Ozon keys?
Yes, DEMO_MODE=true gives five products, four orders, three warehouses and analytics on mock data, with no Ozon, Redis or PostgreSQL needed.
Will it confirm before changing data?
Yes, write tools are marked destructiveHint, and MCP clients like Claude Desktop show a confirmation prompt.
Related
Salesforce's official DX MCP server: work with orgs, metadata, data, users and Apex tests from your agent
Yandex Kit skills for store management
kit-skills
Yandex's official skill set: catalog, prices, stock, orders, storefront and a weekly checkup for a Yandex Kit store, through Claude Code or Codex
YouGile MCP by Indalo
YouGile MCP
Full 65-operation YouGile API coverage with configurable permissions, write confirmation and a shared company rate limit
Bitrix24 portal MCP server
MCP-сервер портала Битрикс24
Bitrix24's official per-portal MCP: an external agent uses OAuth or a token to read and change tasks, deals, meetings and mail