Read-only Wildberries dashboard MCP
WB Readonly MCP
A read-only Wildberries MCP server: products, ads, orders, stock, finance and reviews, with writes blocked in code, not just prompts
Low risk
We rate an entry low when it mostly gives the agent instructions and reference material.
Why this level
- Writes are excluded at the code level by a fixed operation allowlist, not just a prompt-level restriction
- It reads the seller's financial reports and ad budget but cannot change them
Install
Manual install
git clone https://github.com/zimuspro156-lab/mcp-wb-readonly.git
cd mcp-wb-readonly
npm ci
npm test
npm run check
npm run setupThe README's developer quick start; you still need .env with WB_READ_ONLY_TOKEN and npm run start:http.
This is third-party code. Review the repository files before installing.
What it does
The server gives an agent 12 tools and access to 181 allowed Wildberries API operations across 13 sections: product cards and prices, ad campaigns with bids and negative phrases, FBS, DBS, DBW and FBW orders and supplies, warehouse stock, financial reports and documents, buyer reviews and questions, tariffs and seller rating. Write operations are excluded at the code level: a call is only allowed for an exact operation, method, path and domain combination from a fixed catalog/allowlist.json, the agent cannot set an arbitrary URL or method, and creating or re-running WB's background reports is excluded too. Separate tools compute ad CTR, CPC and ROAS-style spend ratio, a stock replenishment scenario, and unit economics for one sold item from entered costs. It deploys on your own VPS with external access via Cloudflare and OAuth 2.0 with PKCE login for ChatGPT; Cursor can run it locally over stdio.
Who it is for. For Wildberries sellers and managers who want a full dashboard view with no risk of the agent accidentally changing anything.
Good fit when
- You want a broad dashboard view: products, ads, orders, stock, finance, reviews
- You need writes excluded in server code, not just in a prompt instruction
- You want remote access from ChatGPT and local access from Cursor from one server
Not a fit when
- You need write operations: this server does not change prices, bids, order status or review replies
- You have no VPS to deploy on: the project does not offer managed cloud hosting
Example request
Break down product 123456789: its card, price, stock and latest ad statsLimitations
The operation catalog is based on a Wildberries API snapshot from August 19, 2026 with added schemas; part of WB's documentation was unavailable during development, and the provenance is documented separately. One operation, FBS auto-return settings, is disabled due to an incomplete schema. Tests use stubbed WB responses, so verifying with a real dashboard token is still up to the user. A Docker setup is prepared but not verified by an actual build; the main install path is systemd services on a Linux VPS. Ready ZIP and PDF files come back as stored content with no automatic unpacking or OCR.
How to disable. Stop the server's systemd service on the VPS and disconnect the app from ChatGPT, or remove it from your Cursor configuration.
MCP
- Transport
- http, stdio
- Authentication
- OAuth
| Environment variables | |
|---|---|
| WB_READ_ONLY_TOKEN required, secret | A personal WB token with the needed API categories; either permission mode works |
Security check
- Writes are excluded at the code level by a fixed operation allowlist, not just a prompt-level restriction
- It reads the seller's financial reports and ad budget but cannot change them
README in short
The README explains the Cloudflare-and-tunnel architecture in detail, gives a table of what a manager can read across eight areas, separately and thoroughly justifies why writes are unavailable with a list of code-level restrictions, lists twelve MCP tools, a developer quick start, and an honest section on the current version's limits including the API snapshot date and unverified parts.
FAQ
Can the AI change a price or stock through this server?
No, write operations are excluded in code via a fixed allowlist, not just forbidden in a model prompt.
Do I need a write-capable token?
No, a read-only token works; the token's own permissions do not widen the MCP's method set, since the server only allows reads regardless.
Related
Salesforce's official DX MCP server: work with orgs, metadata, data, users and Apex tests from your agent
Yandex Kit skills for store management
kit-skills
Yandex's official skill set: catalog, prices, stock, orders, storefront and a weekly checkup for a Yandex Kit store, through Claude Code or Codex
YouGile MCP by Indalo
YouGile MCP
Full 65-operation YouGile API coverage with configurable permissions, write confirmation and a shared company rate limit
Bitrix24 portal MCP server
MCP-сервер портала Битрикс24
Bitrix24's official per-portal MCP: an external agent uses OAuth or a token to read and change tasks, deals, meetings and mail