codflowBLOCK
The open-source, COD-first e-commerce + delivery platform for Algeria built agentic-ready.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
The open-source, COD-first e-commerce platform for Algeria — built agentic-ready.
[](https://t.me/codflow_dz)
Cash on Delivery meets serverless infrastructure. Self-host your entire commerce stack on Cloudflare with zero transaction fees, connect to Algeria's delivery carriers, and optimize Meta ads for real deliveries instead of door refusals.
Get Started
Choose your path:
🚀 I want to run CodFlow
See it in action and deploy your own store.
→ See It in Action → What works today → Quick setup guide → Production deployment
💻 I want to contribute
Build features or customize CodFlow.
→ Contributing guide → Architecture overview → AI agent instructions
🎥 See It in Action
Watch the step-by-step setup guide:
[](https://youtu.be/rJPCGQnDZ18)
[▶️ Watch: CodFlow Setup & Deployment Guide](https://youtu.be/rJPCGQnDZ18)
🎯 The Problem CodFlow Solves
E-commerce in Algeria is 95%+ Cash on Delivery (الدفع عند الاستلام). Western platforms like Shopify and local tools charge per-transaction fees, require expensive VPS hosting, and lock your data in their databases.
CodFlow is the first and only open-source COD e-commerce platform built for Algeria.
945fa0df288dOBSERVED · 2026-10-06Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add codflow --env R2_ACCESS_KEY_ID=${R2_ACCESS_KEY_ID} --env R2_SECRET_ACCESS_KEY=${R2_SECRET_ACCESS_KEY} --env SMOKE_PASSWORD=${SMOKE_PASSWORD} --env STORE_API_KEY=${STORE_API_KEY} -- npx -y codflow{
"mcpServers": {
"codflow": {
"command": "npx",
"args": [
"-y",
"codflow"
],
"env": {
"R2_ACCESS_KEY_ID": "${R2_ACCESS_KEY_ID}",
"R2_SECRET_ACCESS_KEY": "${R2_SECRET_ACCESS_KEY}",
"SMOKE_PASSWORD": "${SMOKE_PASSWORD}",
"STORE_API_KEY": "${STORE_API_KEY}"
}
}
}
}Exposed tools (5)
5 read · 0 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
VIP | read | Top buyers |
X-API-Key | read | API key for authentication. Get your API key from the Developers section. |
X-Store-API-Key | read | Store API key for public storefront endpoints. Different from the dashboard API key. |
commande_recue | read | Commande recue |
livre | read | Livre au client |
Trust audit
BLOCKgrade F · trust 43/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | WARN |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | FAIL |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (3 observation(s))
- Network
- declared (10 observation(s))
- Shell
- declared (5 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- found
Findings (25)
| dashboard sign-in API | `curl -s -X POST https://<dashboard-url>/api/auth/sign-in/email -H "Content-Type: application/json" -H "Origin: https://<dashboard-url>" -d '{"email":"<admin>","password":"<p| dashboard sign-in API | `curl -s -X POST https://<dashboard-url>/api/auth/sign-in/email -H "Content-Type: application/json" -H "Origin: https://<dashboard-url>" -d '{"email":"<admin>","password":"<pImplement [Learning Phase best practices](https://www.facebook.com/business/help/112167992830700?id=561906377587030)
Refrain from making [significant campaign edits](https://www.facebook.com/business/help/316478108955072?id=561906377587030)
[Minimize Auction Overlap](https://www.facebook.com/business/help/537699989762051?id=561906377587030)
Select [Automatic Placements](https://www.facebook.com/business/help/965529646866485?id=802745156580214) and [Campaign Budget Optimization](https://www.facebook.com/business/help/153514848493595?id=62
[Choose the right bid strategy](https://www.facebook.com/business/help/1619591734742116?id=2196356200683573) based on your business goals
cart.ts
cart.ts
console.log(`║ Password : ${password.padEnd(44)} ║`);console.log(`║ API Key : ${apiKey.padEnd(44)} ║`);.forEach(r=>console.log(r.id+"="+r.api_key));
console.log(` next step : add a courier's API token, run Test-connection, then activate`);
body: JSON.stringify({ email: EMAIL, password: "definitely-wrong-password" }),apiKey: "sk_live_super-secret-a9f2",
{ apiKey: "sk_live_super-secret-a9f2", fromEmail: "[email protected]", fromName: undefined, enabled: true }apiKey: "dz-super-secret-a9f2",
const SECRET = "test_webhook_secret_key_2026";
<img height="1" width="1" style="display:none"
<img height="1" width="1" style="display:none"
.dev.vars.example
.assetsignore
.dev.vars.example
.dev.vars.example
capi-payload-helper.md
Gates applied: critical_finding, no_behavioural_pass, undeclared_transfer.
945fa0df288dfull audit observations/trust-audit/mcp-server/bighadj22__codflow.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-06 | 945fa0df288d | BLOCK | F | 43 | first audit |
Questions
What is the codflow MCP server?
The open-source, COD-first e-commerce + delivery platform for Algeria built agentic-ready.
What tools does codflow expose?
5 in total: 5 read-only, 0 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is codflow safe to connect to an agent?
No — not without reading the findings first. The audit graded it F (43/100) and found 7 critical or high issues in the source. Each one is listed on this page with the file and line it is on.
What credentials does codflow need?
It reads R2_ACCESS_KEY_ID, R2_SECRET_ACCESS_KEY, SMOKE_PASSWORD, STORE_API_KEY and YALIDINE_API_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How current is this page?
The grade is for one exact copy of the source (945fa0df288d), read on 2026-10-06. The repository is watched and re-audited when it changes.