yandex-marketing-mcp
A 155-tool MCP server for Yandex Direct, Metrika, Wordstat and Webmaster, with self-setup OAuth and read-only and confirm modes
High risk
We rate an entry high when the tool writes to external systems, handles money, production databases or secrets, or runs arbitrary commands. The CLI installs it only with your consent.
Why this level
- By default it can create, change and stop Direct campaigns and bids
- It can change Metrika goals and counters and delete Webmaster sitemaps
- Start with YD_READONLY=true and enable writes only deliberately
Install
Manual install
npm install && npm run buildInstall and build from source; requires Node.js 20 or newer.
This is third-party code. Review the repository files before installing.
What it does
The server brings four Yandex services together in one MCP: 72 tools for Direct, including extended vcards, feeds, smart targets and creatives, 43 for Metrika (counters, goals, segments, reports, offline data), 30 for Webmaster (indexing, search queries, links, recrawl), and 5 for Wordstat. Authorization happens right from the agent's tools: the server starts with no tokens, saves the Client ID via yd_set_client_id, returns a login link, and after confirmation the token is saved via yd_set_token and validated through the Metrika API. Wordstat separately needs a Yandex Cloud service account, because since June 2026 the cloud stopped exchanging user OAuth tokens issued after that date for an IAM token. There is a read-only mode that physically blocks every write tool, and a confirm mode where any write call first returns a preview and requires a repeat call with confirm=true.
Who it is for. For marketing agencies and specialists running ads, analytics and SEO across the Yandex ecosystem who want unified, safe agent access.
Good fit when
- You want to manage Direct, Metrika, Wordstat and Webmaster from one place without juggling separate servers
- You want to connect the server read-only first and consciously enable writes only later
- You run several Direct client accounts and need an allowlist of permitted logins
Not a fit when
- You only need one of the four services: a specialized server may be simpler to set up
- You cannot set up a Yandex Cloud service account: without one, Wordstat only works via a temporary 12-hour IAM token
Example request
Show me the weekly Direct campaign report and find pages that dropped out of search according to Webmaster dataLimitations
Full Wordstat access needs a Yandex Cloud service account with a linked billing account; the temporary IAM-token workaround lasts no more than 12 hours. By default the server runs with full write access; read-only and confirm modes must be turned on explicitly via environment variables. The OAuth application and scopes must be set up manually at oauth.yandex.ru. There is no npm package; install and build are from source.
How to disable. Remove the server from your MCP client config, revoke the OAuth token at oauth.yandex.ru, and delete ~/.yandex-marketing-mcp/config.json.
MCP
- Transport
- stdio
- Authentication
- OAuth
| Environment variables | |
|---|---|
| YANDEX_OAUTH_CLIENT_ID | OAuth application Client ID, a seed value; stored in the config file afterward |
| YD_OAUTH_TOKEN secret | OAuth access token, a seed value |
| YC_FOLDER_ID | Yandex Cloud folder ID for Wordstat |
| YD_READONLY | true blocks every write tool, leaving only reading and reports |
| YD_CONFIRM | true makes write calls first return a preview and require confirm=true |
| YD_ALLOWED_LOGINS | Comma-separated allowlist of Direct client logins |
Security check
- By default it can create, change and stop Direct campaigns and bids
- It can change Metrika goals and counters and delete Webmaster sitemaps
- Start with YD_READONLY=true and enable writes only deliberately
README in short
The Russian README describes the server as a self-setup OAuth tool for Direct, Metrika, Wordstat and Webmaster. It gives a capability table by service with tool counts, step-by-step OAuth application registration and required scopes, and a detailed section on setting up a Yandex Cloud service account for Wordstat, explaining the June 2026 changes. The full tool list is broken down by section: campaigns, ad groups, ads, keywords for Direct, Metrika reports, Webmaster indexing and links. A dedicated safety-modes section covers read-only, confirm, multi-account access via YD_ALLOWED_LOGINS, and partial-success error parsing. MIT license.
FAQ
Can the server be connected so it definitely changes nothing?
Yes, the YD_READONLY=true variable physically blocks every write tool, leaving only viewing and reports.
Why doesn't Wordstat work right after getting an OAuth token?
Since June 2026 Yandex Cloud no longer exchanges user OAuth tokens issued after that date for an IAM token; a separate service account with a linked billing account is needed.
Related
Official DataLens (Yandex) skills for Claude Code, Codex and OpenCode: SDK, HTML reports and RLS resolution
A Yandex Metrika MCP server generated from the API spec: 108 methods, 10 tools declared by default, transparent filters and response metadata
An open MCP server and agent skill set for SEO: keyword research, competitors, backlinks and site audits powered by DataForSEO
A Claude Code plugin for SEO audits: technical SEO, E-E-A-T, schema, local and AI search via parallel subagents