DigiKeySAFE
An MCP for DigiKey
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
A Model Context Protocol (MCP) server for DigiKey's Product Search API using FastMCP.
Requirements
- Python 3.10+
- uv package manager
- DigiKey API credentials (CLIENTID and CLIENTSECRET)
Setup
1. Install dependencies
uv sync
2. Set up environment variables
Create a .env file in the project root:
CLIENT_ID=your_digikey_client_id CLIENT_SECRET=your_digikey_client_secret USE_SANDBOX=false
Set USE_SANDBOX=true to use DigiKey's sandbox environment for testing.
3. Run the server
uv run python digikey_mcp_server.py
Available Tools
Search Methods
keyword_search(keywords, limit=5, manufacturer_id=None, category_id=None, search_options=None, sort_field=None, sort_order="Ascending")- Search DigiKey products by keyword with sorting and filteringsearch_manufacturers()- Get all product manufacturerssearch_categories()- Get all product categoriessearch_product_substitutions(product_number, limit=10, search_options=None, exclude_marketplace=False)- Find substitute products
Product Details
product_details(product_number, manufacturer_id=None, customer_id="0")- Get detailed product informationget_category_by_id(category_id)- Get specific category detailsget_product_media(product_number)- Get product images, documents, and videosget_product_pricing(product_number, customer_id="0", requested_quantity=1)- Get detailed pricing informationget_digi_reel_pricing(product_number, requested_quantity, customer_id="0")- Get DigiReel pricing
Sort Options for keyword_search
Available sort fields:
Packaging- Sort by packaging typeProductStatus- Sort by product statusDigiKeyProductNumber- Sort by DigiKey part numberManufacturerProductNumber- Sort by manufacturer part numberManufacturer- Sort by manufacturer nameMinimumQuantity- Sort by minimum order quantityQuantityAvailable- Sort by available quantity
-
e44ae1119a6cOBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add digikey-mcp --env CLIENT_SECRET=${CLIENT_SECRET} -- uvx digikey-mcp{
"mcpServers": {
"digikey-mcp": {
"command": "uvx",
"args": [
"digikey-mcp"
],
"env": {
"CLIENT_SECRET": "${CLIENT_SECRET}"
}
}
}
}Exposed tools (9)
9 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
get_category_by_id | read | Get specific category details by ID. |
get_digi_reel_pricing | read | Get DigiReel pricing for a product. |
get_product_media | read | Get media (images, documents, videos) for a product. |
get_product_pricing | read | Get detailed pricing information for a product. |
keyword_search | read | Search DigiKey products by keyword. |
product_details | read | Get detailed information for a specific product. |
search_categories | read | Search and retrieve all product categories. |
search_manufacturers | read | Search and retrieve all product manufacturers. |
search_product_substitutions | read | Search for product substitutions for a given product. |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- declared (3 observation(s))
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (1)
Gates applied: no_behavioural_pass, no_license.
e44ae1119a6cfull audit observations/trust-audit/mcp-server/bengineer19__digikey.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | e44ae1119a6c | SAFE | B | 89 | first audit |
Questions
What is the DigiKey MCP server?
An MCP for DigiKey
What tools does DigiKey expose?
9 in total: 9 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is DigiKey safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B.
What credentials does DigiKey need?
It reads CLIENT_SECRET from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How current is this page?
The grade is for one exact copy of the source (e44ae1119a6c), read on 2026-10-08. The repository is watched and re-audited when it changes.