iikoServer MCP: 39 iiko REST API tools
iikoServer MCP Server
An MCP server for the iikoServer REST API: products, employees, invoices, cash shifts, encashment and OLAP reports, including raw calls to any endpoint
High risk
We rate an entry high when the tool writes to external systems, handles money, production databases or secrets, or runs arbitrary commands. The CLI installs it only with your consent.
Why this level
- create_encashment writes a cash movement entry with no separate confirmation
- raw_request grants access to any iikoServer endpoint, including potentially data-changing ones
Install
Manual install
pip install -r requirements.txtInstalling dependencies after cloning the repository.
This is third-party code. Review the repository files before installing.
What it does
The server logs into iikoServer with a username and password (SHA1 is computed internally), automatically re-authenticates when the token expires, and logs out cleanly on shutdown to free the license slot. 39 tools are grouped by area: nomenclature and products, employees and roles, entities and warehouses, incoming and outgoing invoices, write-offs, menu changes, payment types, cash shifts and payments (including create_encashment for a cash-in/cash-out entry), price categories, and OLAP reports with custom columns and filters or saved presets. A separate raw_request tool lets you make any authorized call to iikoServer directly when no ready shortcut exists. All dates use the DD.MM.YYYY format iiko expects, and errors come back as a tool result rather than a server crash.
Who it is for. For restaurant owners and managers running iikoServer who want quick access to reports, nomenclature and cash data from an agent chat.
Good fit when
- You want to check revenue, stock, invoices or cash shifts for a period through an agent
- You need a custom OLAP report with specific columns and filters without opening the iiko interface
- You need access to an iikoServer endpoint with no ready-made tool yet, via raw_request
Not a fit when
- You don't want the agent able to create encashment entries: create_encashment writes a cash movement with no separate server-level confirmation
- You need a tool for iikoCloud or iikoTransport: this server is only for classic iikoServer
- You're not comfortable storing your iiko password in an environment variable: SHA1 is computed locally, but the plain password is still passed to the server
Example request
Show today's revenue as of 18:00 and the list of cash shifts for the weekLimitations
The repository has no stated license. The raw_request and create_encashment tools run with no built-in server-level confirmation step; the risk of an erroneous call falls on the client and the user. The project comes from a single author, and the README doesn't describe a read-only versus write mode split. It accepts self-signed certificates without verification (verify=False), which weakens the connection if the iiko server itself is set up insecurely.
How to disable. Remove the iiko block from your MCP client configuration; the server logs out cleanly on normal process shutdown.
MCP
- Transport
- stdio
- Authentication
- API key
| Environment variables | |
|---|---|
| IIKO_URL | The iikoServer base URL, defaults to the author's demo address. |
| IIKO_LOGIN required, secret | The iikoServer username. |
| IIKO_PASS required, secret | The user's password; SHA1 is computed by the server internally. |
Security check
- create_encashment writes a cash movement entry with no separate confirmation
- raw_request grants access to any iikoServer endpoint, including potentially data-changing ones
README in short
The README lists 39 tools across eight sections: system, nomenclature, employees, entities, documents, cash and payments, prices, reports and OLAP, plus raw_request. It gives environment variables, configuration for Hermes Agent, Claude Desktop and Cursor, the DD.MM.YYYY date format, and a feature list: auto re-authentication, clean logout, self-signed certificate support, errors returned as tool results.
FAQ
Do I need to hash the password myself?
No, the server computes the SHA1 hash of the given password itself; IIKO_PASS takes the plain password.
What does raw_request do?
It makes any authorized call to iikoServer directly, useful for endpoints with no ready-made tool, but it needs to be used carefully.
Related
An MCP server with n8n node and template knowledge: the agent picks nodes, validates configs and, with API access, creates workflows in your n8n
Zapier's official MCP plugin: the agent gets actions across thousands of apps through your Zapier account
Awesome Claude Skills by Composio
Awesome Claude Skills
A curated list of Claude skills and plugins, plus Composio's own automation skills for 78 SaaS apps
A plugin and CLI catalog for agents: generates command-line interfaces for GUI apps like GIMP and Blender and installs ready ones via CLI-Hub