Yandex Market Readonly MCP
A read-only MCP for a Yandex Market seller dashboard: products, orders, prices, stock and reviews, with no write tool at all even if the key has write rights
Medium risk
We rate an entry medium when the tool runs code, makes network calls or reads project files. Check what exactly it does before installing.
Why this level
- Reads order, price and stock data, including commercially sensitive information
- Remote deployment for ChatGPT requires your own VPS storing the Market API key
Install
Manual install
git clone https://github.com/zimuspro156-lab/mcp-ym-readonly.git
cd mcp-ym-readonly
npm ci
npm testDeveloper quick start, requires Node.js 22 or newer.
This is third-party code. Review the repository files before installing.
What it does
The server gives 20 tools to analyze a Yandex Market seller dashboard: status and a catalog of available data, product search and profile, order list and detail, stock, prices, returns without acting on decisions, quality index and reviews, plus local analytics: a restock plan, unit economics, aggregations and a daily sales review. Every tool is marked read-only, and by design the server physically cannot change the dashboard, even if the API key has write rights, because no such calls exist in the code. For ChatGPT the server is deployed on its own VPS behind a Cloudflare tunnel and protected by OAuth 2.0 Authorization Code with PKCE: the user enters the MCP's own login and password, not the Yandex Market key, which is stored only in .env on the server. For local use, such as in Cursor, a plain stdio launch is available.
Who it is for. For Yandex Market sellers who want dashboard analytics and an overview through an agent, with zero risk of accidentally changing anything.
Good fit when
- You want a daily review of sales, stock and orders with zero risk of changing the dashboard
- You want unit economics and a restock plan computed locally by the agent
- You need to connect ChatGPT to the Yandex Market dashboard remotely, not just a local agent
Not a fit when
- You need to change prices, stock, order statuses or reply in chats: the server cannot do this under any settings
- You cannot deploy a separate VPS for remote ChatGPT access: this scenario needs your own server behind a tunnel
Example request
Give me a daily sales review: what's running low on stock and what's the unit economics on the top five productsLimitations
The server is entirely read-only by design; generating reports or labels, changing order statuses, replying in chats, and any dashboard changes are excluded even if the key has the matching rights. Using it from ChatGPT needs your own Ubuntu VPS with a configured Cloudflare tunnel; a local launch is simpler and fits Cursor. Node.js 22 or newer is required.
How to disable. Stop the ym-readonly-mcp service on the server, or remove the server from your local MCP client config, and revoke the Yandex Market API key in the partner dashboard.
MCP
- Transport
- stdio, http
- Authentication
- OAuth
| Environment variables | |
|---|---|
| YM_API_KEY required, secret | Yandex Market API key, stored only in .env on the server |
Security check
- Reads order, price and stock data, including commercially sensitive information
- Remote deployment for ChatGPT requires your own VPS storing the Market API key
README in short
The Russian README states plainly that the server only reads data and cannot change the dashboard through MCP even if the key has write rights. It gives a table of analysis areas: stores, products, prices and stock, orders, returns without decisions, quality and reviews, local analytics. It shows the ChatGPT architecture: OAuth with PKCE through a Cloudflare tunnel to your own VPS, where the API key is stored. It lists 20 tools, all marked read-only, plus a ym://guide resource and a daily-review prompt. It gives a developer quick start and links to separate deploy and usage guides. MIT license; the project is not an official Yandex product.
FAQ
Can the server change anything in the dashboard if given a key with write rights?
No, there is no write call anywhere in the server's code, so it physically cannot write to the dashboard regardless of the key's permissions.
Does ChatGPT get access to the Yandex Market key?
No, the key is stored only in .env on the server, and ChatGPT's login is protected by a separate OAuth flow with the MCP's own username and password.
Related
Salesforce's official DX MCP server: work with orgs, metadata, data, users and Apex tests from your agent
Yandex Kit skills for store management
kit-skills
Yandex's official skill set: catalog, prices, stock, orders, storefront and a weekly checkup for a Yandex Kit store, through Claude Code or Codex
YouGile MCP by Indalo
YouGile MCP
Full 65-operation YouGile API coverage with configurable permissions, write confirmation and a shared company rate limit
Bitrix24 portal MCP server
MCP-сервер портала Битрикс24
Bitrix24's official per-portal MCP: an external agent uses OAuth or a token to read and change tasks, deals, meetings and mail