Magento 2CAUTION
A MCP server for Magento 2
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
This is a Model Context Protocol (MCP) server that connects to a Magento 2 REST API, allowing Claude and other MCP clients to query product information from a Magento store.
Features
Product Features
- Query product information by SKU or ID
- Search for products using various criteria
- Get product categories
- Get related products
- Get product stock information
- Get product attributes
- Update product attributes by specifying attribute code and value
- Advanced product search with filtering and sorting
Customer Features
- Get all ordered products for a customer by email address
Order and Revenue Features
- Get order count for specific date ranges
- Get revenue for specific date ranges
- Get revenue filtered by country for specific date ranges
- Get product sales statistics including quantity sold and top-selling products
- Support for relative date expressions like "today", "yesterday", "last week", "this month", "YTD"
- Support for country filtering using both country codes and country names
Prerequisites
- Node.js (v14 or higher)
- A Magento 2 instance with REST API access
- API token for the Magento 2 instance
Installation
- Clone this repository
- Install dependencies:
npm install
Usage
Running the server directly
node mcp-server.js
Testing with the test client
node test-mcp-server.js
Using with Claude Desktop
- Check your path node with
which node - Go to the Developer settings and click "Edit config". This will open a JSON file.
- Add the following snippet within the
mcpServers:
"magento2": {
"command": "/path/to/your/node",
"args": ["/path/to/mcp-server.js"],
"env": {
"MAGENTO_BASE_URL": "https://YOUR_DOMAIN/rest/V1",
"MAGENTO_API_TOKEN": "your-api-token"
}
}- Replace
/path/to/your/nodewith the path you checked in step 1 - Replace
/path/to/mcp-server.jswith the path where
ebb06be00f31OBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add mcp-magento2 --env MAGENTO_API_TOKEN=${MAGENTO_API_TOKEN} -- npx -y [email protected]{
"mcpServers": {
"mcp-magento2": {
"command": "npx",
"args": [
"-y",
"[email protected]"
],
"env": {
"MAGENTO_API_TOKEN": "${MAGENTO_API_TOKEN}"
}
}
}
}Exposed tools (14)
12 read · 2 write · 0 destructive.
| Tool | Risk | Description |
|---|---|---|
advanced_product_search | read | Search for products with advanced filtering options |
get_customer_ordered_products_by_email | read | Get all ordered products for a customer by email address |
get_order_count | write | Get the number of orders for a given date range |
get_product_attributes | read | Get all attributes for a product by SKU |
get_product_by_id | read | Get detailed information about a product by its ID |
get_product_by_sku | read | Get detailed information about a product by its SKU |
get_product_categories | read | Get categories for a specific product by SKU |
get_product_sales | read | Get statistics about the quantity of products sold in a given date range |
get_product_stock | read | Get stock information for a product by SKU |
get_related_products | read | Get products related to a specific product by SKU |
get_revenue | read | Get the total revenue for a given date range |
get_revenue_by_country | read | Get revenue filtered by country for a given date range |
search_products | read | Search for products using Magento search criteria |
update_product_attribute | write | Update a specific attribute of a product by SKU |
Trust audit
CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- declared (1 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (5)
rejectUnauthorized: false
.clinerules
@anthropic-ai/sdk, @modelcontextprotocol/sdk, axios, body-parser, date-fns, dotenv, express, zod
load_dotenv() # load environment variables from .env
curl -LsSf https://astral.sh/uv/install.sh | sh
Gates applied: no_behavioural_pass.
ebb06be00f31full audit observations/trust-audit/mcp-server/boldcommerce__magento-2.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | ebb06be00f31 | CAUTION | B | 89 | first audit |
Questions
What is the Magento 2 MCP server?
A MCP server for Magento 2
What tools does Magento 2 expose?
14 in total: 12 read-only, 2 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.
Is Magento 2 safe to connect to an agent?
With care. The audit graded it B (89/100) and found 5 things worth knowing before you trust this server, listed below with the exact line each was found on.
What credentials does Magento 2 need?
It reads MAGENTO_API_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Magento 2 run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as mcp-magento2 at 1.0.0.
How current is this page?
The grade is for one exact copy of the source (ebb06be00f31), read on 2026-10-07. The repository is watched and re-audited when it changes.