Yandex Direct MCP as a Claude HTTP connector
ya-direct-mcp
A Streamable HTTP Yandex Direct MCP server, deployed on Railway and connected to Claude as a custom connector via a secret URL
High risk
We rate an entry high when the tool writes to external systems, handles money, production databases or secrets, or runs arbitrary commands. The CLI installs it only with your consent.
Why this level
- Leaking MCP_SECRET grants full account access, including irreversible campaign deletion
- Creates, suspends and archives campaigns, groups, ads and keywords
Install
In your terminal, with SkillFoxx CLI
npx skillfoxx add mcp/ya-direct-mcpDetects the agents on your machine, checks the risk and pins the version.
Other ways to install
Assembled automatically, review before installing.
This entry is high risk, so there is no one-click install. Review the code and add the config by hand.
Run in a terminal
claude mcp add --transport http ya-direct-mcp 'https://ВАШ-ДОМЕН.up.railway.app/mcp/<your MCP_SECRET>' --header 'Authorization: Bearer <your MCP_SECRET>'Or add to the file .mcp.json, in the project
{
"mcpServers": {
"ya-direct-mcp": {
"type": "http",
"url": "https://ВАШ-ДОМЕН.up.railway.app/mcp/<your MCP_SECRET>",
"headers": {
"Authorization": "Bearer <your MCP_SECRET>"
}
}
}
}If the file already exists, add the server inside the mcpServers key.
Keys and settings
YD_TOKENsecret, required- OAuth-токен Яндекс.Директа
YD_LOGINrequired- Логин рекламодателя по умолчанию
MCP_SECRETsecret, required- Собственный секрет сервера для защиты эндпоинта. Не токен Яндекса
PORToptional- Порт сервера, Railway подставляет автоматически
LOG_LEVELoptional- `INFO` по умолчанию
YD_REPORT_TIMEOUToptional- Максимум ожидания отчёта, сек. По умолчанию 120
Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.
Add to the file ~/.cursor/mcp.json, for all projects
{
"mcpServers": {
"ya-direct-mcp": {
"url": "https://ВАШ-ДОМЕН.up.railway.app/mcp/<your MCP_SECRET>",
"headers": {
"Authorization": "Bearer <your MCP_SECRET>"
}
}
}
}If the file already exists, add the server inside the mcpServers key. For a single project, put the same block into .cursor/mcp.json.
Keys and settings
YD_TOKENsecret, required- OAuth-токен Яндекс.Директа
YD_LOGINrequired- Логин рекламодателя по умолчанию
MCP_SECRETsecret, required- Собственный секрет сервера для защиты эндпоинта. Не токен Яндекса
PORToptional- Порт сервера, Railway подставляет автоматически
LOG_LEVELoptional- `INFO` по умолчанию
YD_REPORT_TIMEOUToptional- Максимум ожидания отчёта, сек. По умолчанию 120
Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.
Run in a terminal
code --add-mcp '{"name":"ya-direct-mcp","type":"http","url":"https://ВАШ-ДОМЕН.up.railway.app/mcp/<your MCP_SECRET>","headers":{"Authorization":"Bearer <your MCP_SECRET>"}}'Or add to the file .vscode/mcp.json, in the project
{
"servers": {
"ya-direct-mcp": {
"type": "http",
"url": "https://ВАШ-ДОМЕН.up.railway.app/mcp/<your MCP_SECRET>",
"headers": {
"Authorization": "Bearer <your MCP_SECRET>"
}
}
}
}If the file already exists, add the server inside the servers key.
Keys and settings
YD_TOKENsecret, required- OAuth-токен Яндекс.Директа
YD_LOGINrequired- Логин рекламодателя по умолчанию
MCP_SECRETsecret, required- Собственный секрет сервера для защиты эндпоинта. Не токен Яндекса
PORToptional- Порт сервера, Railway подставляет автоматически
LOG_LEVELoptional- `INFO` по умолчанию
YD_REPORT_TIMEOUToptional- Максимум ожидания отчёта, сек. По умолчанию 120
Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.
Add to the file ~/.codex/config.toml, for all projects
[mcp_servers.ya-direct-mcp]
url = "https://ВАШ-ДОМЕН.up.railway.app/mcp/<your MCP_SECRET>"
http_headers = { Authorization = "Bearer <your MCP_SECRET>" }If the file already exists, append the block to the end.
Keys and settings
YD_TOKENsecret, required- OAuth-токен Яндекс.Директа
YD_LOGINrequired- Логин рекламодателя по умолчанию
MCP_SECRETsecret, required- Собственный секрет сервера для защиты эндпоинта. Не токен Яндекса
PORToptional- Порт сервера, Railway подставляет автоматически
LOG_LEVELoptional- `INFO` по умолчанию
YD_REPORT_TIMEOUToptional- Максимум ожидания отчёта, сек. По умолчанию 120
Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.
Add to the file ~/.gemini/settings.json, for all projects
{
"mcpServers": {
"ya-direct-mcp": {
"httpUrl": "https://ВАШ-ДОМЕН.up.railway.app/mcp/<your MCP_SECRET>",
"headers": {
"Authorization": "Bearer <your MCP_SECRET>"
}
}
}
}If the file already exists, add the server inside the mcpServers key.
Keys and settings
YD_TOKENsecret, required- OAuth-токен Яндекс.Директа
YD_LOGINrequired- Логин рекламодателя по умолчанию
MCP_SECRETsecret, required- Собственный секрет сервера для защиты эндпоинта. Не токен Яндекса
PORToptional- Порт сервера, Railway подставляет автоматически
LOG_LEVELoptional- `INFO` по умолчанию
YD_REPORT_TIMEOUToptional- Максимум ожидания отчёта, сек. По умолчанию 120
Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.
Add to the file ~/.config/devin/mcp_config.json, for all projects
{
"mcpServers": {
"ya-direct-mcp": {
"serverUrl": "https://ВАШ-ДОМЕН.up.railway.app/mcp/<your MCP_SECRET>",
"headers": {
"Authorization": "Bearer <your MCP_SECRET>"
}
}
}
}If the file already exists, add the server inside the mcpServers key. Legacy Cascade keeps the MCP config in ~/.codeium/windsurf/mcp_config.json.
Keys and settings
YD_TOKENsecret, required- OAuth-токен Яндекс.Директа
YD_LOGINrequired- Логин рекламодателя по умолчанию
MCP_SECRETsecret, required- Собственный секрет сервера для защиты эндпоинта. Не токен Яндекса
PORToptional- Порт сервера, Railway подставляет автоматически
LOG_LEVELoptional- `INFO` по умолчанию
YD_REPORT_TIMEOUToptional- Максимум ожидания отчёта, сек. По умолчанию 120
Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.
Formerly Windsurf.
Add to the file cline_mcp_settings.json, for all projects
{
"mcpServers": {
"ya-direct-mcp": {
"type": "streamableHttp",
"url": "https://ВАШ-ДОМЕН.up.railway.app/mcp/<your MCP_SECRET>",
"headers": {
"Authorization": "Bearer <your MCP_SECRET>"
}
}
}
}If the file already exists, add the server inside the mcpServers key. Open the settings file in Cline: MCP Servers tab, Configure MCP Servers.
Keys and settings
YD_TOKENsecret, required- OAuth-токен Яндекс.Директа
YD_LOGINrequired- Логин рекламодателя по умолчанию
MCP_SECRETsecret, required- Собственный секрет сервера для защиты эндпоинта. Не токен Яндекса
PORToptional- Порт сервера, Railway подставляет автоматически
LOG_LEVELoptional- `INFO` по умолчанию
YD_REPORT_TIMEOUToptional- Максимум ожидания отчёта, сек. По умолчанию 120
Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.
Add to the file .roo/mcp.json, in the project
{
"mcpServers": {
"ya-direct-mcp": {
"type": "streamable-http",
"url": "https://ВАШ-ДОМЕН.up.railway.app/mcp/<your MCP_SECRET>",
"headers": {
"Authorization": "Bearer <your MCP_SECRET>"
}
}
}
}If the file already exists, add the server inside the mcpServers key.
Keys and settings
YD_TOKENsecret, required- OAuth-токен Яндекс.Директа
YD_LOGINrequired- Логин рекламодателя по умолчанию
MCP_SECRETsecret, required- Собственный секрет сервера для защиты эндпоинта. Не токен Яндекса
PORToptional- Порт сервера, Railway подставляет автоматически
LOG_LEVELoptional- `INFO` по умолчанию
YD_REPORT_TIMEOUToptional- Максимум ожидания отчёта, сек. По умолчанию 120
Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.
A fork of Roo Code, same .roo folders.
Add to the file opencode.json, in the project
{
"mcp": {
"ya-direct-mcp": {
"type": "remote",
"url": "https://ВАШ-ДОМЕН.up.railway.app/mcp/<your MCP_SECRET>",
"headers": {
"Authorization": "Bearer <your MCP_SECRET>"
}
}
}
}If the file already exists, add the server inside the mcp key.
Keys and settings
YD_TOKENsecret, required- OAuth-токен Яндекс.Директа
YD_LOGINrequired- Логин рекламодателя по умолчанию
MCP_SECRETsecret, required- Собственный секрет сервера для защиты эндпоинта. Не токен Яндекса
PORToptional- Порт сервера, Railway подставляет автоматически
LOG_LEVELoptional- `INFO` по умолчанию
YD_REPORT_TIMEOUToptional- Максимум ожидания отчёта, сек. По умолчанию 120
Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.
Add to the file ~/.config/zed/settings.json, for all projects
{
"context_servers": {
"ya-direct-mcp": {
"url": "https://ВАШ-ДОМЕН.up.railway.app/mcp/<your MCP_SECRET>",
"headers": {
"Authorization": "Bearer <your MCP_SECRET>"
}
}
}
}If the file already exists, add the server inside the context_servers key.
Keys and settings
YD_TOKENsecret, required- OAuth-токен Яндекс.Директа
YD_LOGINrequired- Логин рекламодателя по умолчанию
MCP_SECRETsecret, required- Собственный секрет сервера для защиты эндпоинта. Не токен Яндекса
PORToptional- Порт сервера, Railway подставляет автоматически
LOG_LEVELoptional- `INFO` по умолчанию
YD_REPORT_TIMEOUToptional- Максимум ожидания отчёта, сек. По умолчанию 120
Replace the values in angle brackets with your own. Keys never go into install links and are not stored by us.
Deploy the service on Railway from this repository, add the YD_TOKEN, YD_LOGIN and a generated MCP_SECRET variables, enable the public domain, then in Claude add a custom connector at https://YOUR-DOMAIN.up.railway.app/mcp/YOUR_MCP_SECRET.
This is third-party code. Review the repository files before installing.
What it does
Unlike most Direct servers that run locally over stdio, this one deploys as a cloud HTTP endpoint and connects to Claude via Settings, Connectors, Add custom connector, with no local install and no .mcp.json. It manages text campaigns: list, fetch, create, update, suspend, resume, archive and delete for campaigns, ad groups, ads and keywords, plus a report and account balance. Every tool accepts an optional client_login, so one deployed server can serve several advertisers at once. Client authorization runs through its own MCP_SECRET, baked into the URL path or passed as a header, while the Direct OAuth token lives only in the server's Railway environment and Claude never sees it.
Who it is for. For people who want to connect Yandex Direct to Claude as a cloud connector with no local install, and are willing to deploy their own server on Railway.
Good fit when
- You need a Direct MCP server reachable from Claude with no local process on your machine
- You need to serve several advertisers from one deployed server via client_login
- You already have, or do not mind creating, a Railway account for a quick deploy
Not a fit when
- You do not want an endpoint exposed to the internet: the only protection is the MCP_SECRET in the path or header
- You need a local stdio install with no cloud hosting
- You need accidental-delete protection on every method: only delete_campaign has a safety catch
Example request
Show account balance and suspend campaigns that spent over 5,000 rubles this week with no conversionsLimitations
The endpoint is exposed to the internet; the only protection is the MCP_SECRET, and leaking it means full access to the ad account, including deleting campaigns. Only delete_campaign has an exact-name confirmation safety catch; the other delete_* tools have none, and deletion is irreversible. Only TEXT_CAMPAIGN campaigns are supported, and deployment targets Railway.
How to disable. Remove the yandex-direct connector in Claude's settings and stop or delete the service on Railway.
MCP
- Transport
- http
- Authentication
- API key
| Environment variables | |
|---|---|
| YD_TOKEN required, secret | Yandex Direct OAuth token |
| YD_LOGIN required | Default advertiser login |
| MCP_SECRET required, secret | The server's own secret protecting the HTTP endpoint, not the Yandex token |
Security check
- Leaking MCP_SECRET grants full account access, including irreversible campaign deletion
- Creates, suspends and archives campaigns, groups, ads and keywords
README in short
The README gives a step-by-step Railway deploy: New Project, environment variables, public domain generation and a /health readiness check. It separately covers connecting as a custom Claude connector via a URL with the secret in the path or header, and a security section that plainly names MCP_SECRET as the only protection and notes which delete method has a safety catch and which do not.
FAQ
What do I do if the secret leaks?
Rotate MCP_SECRET in Railway's variables, the service restarts itself, then recreate the connector in Claude with the new URL.
Are all delete methods protected against a typo?
No, only delete_campaign requires an exact campaign-name match via confirm_name; the other delete_* tools run with no such check.
Related
A skill that strips AI writing tells from text using Wikipedia's list, without adding invented facts
Marketing Skills for AI agents
Marketing Skills for AI Agents
About fifty skills for CRO, copywriting, SEO, analytics, ads and launches, built for coding agents
SendPulse MCP server
SendPulse MCP
SendPulse's official remote MCP server: statistics, campaigns and user data through an agent chat
Yandex Direct MCP generated from a machine-readable schema
yandex-direct-mcp
An MCP server and CLI covering all 113 Yandex Direct API v5 methods generated from WSDL, exposing 9 read tools by default and writes only on demand