DiscogsSAFE
MCP Server for Discogs
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
[](LICENSE) [](https://github.com/cswkim/discogs-mcp-server/releases) [](https://github.com/cswkim/discogs-mcp-server/actions/workflows/check-pr.yml) [](https://www.npmjs.com/package/discogs-mcp-server) [](https://github.com/sponsors/cswkim)
MCP Server for the Discogs API, enabling music catalog operations, search functionality, and more.
Quickstart
If you just want to get started immediately using this MCP Server with the Claude desktop app and don't care about development or running the server yourself, then make sure you have Node.js installed and your Discogs personal access token ready and skip straight to the Claude configuration section. Use the NPX method from that section.
Table of Contents
- Acknowledgements
- Available Tools
- Caveats
- Prerequisites
- Setup
- Running the Server
- Option 1: Local Development
- Option 2: Docker
- Inspection
- MCP Clients
- Claude Desktop Configuration
- NPX
- Local Node
- Docker
- LibreChat
- LM Studio
- TODO
- License
Acknowledgements
This MCP server is built using FastMCP,
8bb8881f30d2OBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add discogs-mcp-server --env DISCOGS_PERSONAL_ACCESS_TOKEN=${DISCOGS_PERSONAL_ACCESS_TOKEN} -- npx -y [email protected]{
"mcpServers": {
"discogs-mcp-server": {
"command": "npx",
"args": [
"-y",
"[email protected]"
],
"env": {
"DISCOGS_PERSONAL_ACCESS_TOKEN": "${DISCOGS_PERSONAL_ACCESS_TOKEN}"
}
}
}
}Exposed tools (53)
33 read · 15 write · 5 destructive. Blast radius: 5 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
add_release_to_user_collection_folder | write | Add a release to a folder in a user |
add_to_wantlist | write | Add a release to a user |
create_marketplace_listing | write | Create a new marketplace listing |
create_marketplace_order_message | write | Adds a new message to the order |
create_user_collection_folder | write | Create a new folder in a user |
delete_item_in_wantlist | destructive | Delete a release from a user |
delete_marketplace_listing | destructive | Delete a marketplace listing |
delete_release_from_user_collection_folder | destructive | Remove an instance of a release from a user |
delete_release_rating | destructive | Deletes the release |
delete_user_collection_folder | destructive | Delete a folder from a user |
download_inventory_export | read | Download an inventory export as a CSV |
edit_item_in_wantlist | write | Edit a release in a user |
edit_marketplace_order | write | Edit a marketplace order |
edit_release_rating | write | Updates the release |
edit_user_collection_custom_field_value | write | Edit a custom field value for a release in a user |
edit_user_collection_folder | write | Edit a folder |
edit_user_profile | write | Edit a user |
fetch_image | read | Fetch an image by URL |
find_release_in_user_collection | read | Find a release in a user |
get_artist | read | Get an artist |
get_artist_releases | read | Get an artist |
get_inventory_export | read | Get details about an inventory export |
get_inventory_exports | read | Get a list of all recent exports of your inventory |
get_label | read | Get a label |
get_label_releases | read | Returns a list of Releases associated with the label |
get_list | read | Get a list by ID |
get_marketplace_listing | read | Get a listing from the marketplace |
get_marketplace_order | write | Get a marketplace order |
get_marketplace_order_messages | write | Get a list of an order |
get_marketplace_orders | read | Get a list of marketplace orders |
get_marketplace_release_stats | read | Retrieve marketplace statistics for the provided Release ID |
get_master_release | read | Get a master release |
get_master_release_versions | read | Retrieves a list of all Releases that are versions of this master |
get_release | read | Get a release |
get_release_community_rating | read | Retrieves the release community rating average and count |
get_release_rating_by_user | read | Retrieves the release |
get_user_collection_custom_fields | read | Retrieve a list of user-defined collection notes fields. These fields are available on every release in the collection. |
get_user_collection_folder | read | Retrieve metadata about a folder in a user |
get_user_collection_folders | read | Retrieve a list of folders in a user |
get_user_collection_items | read | Retrieve a list of items in a user |
get_user_collection_value | read | Returns the minimum, median, and maximum value of a user |
get_user_contributions | read | Retrieve a user |
get_user_identity | read | Retrieve basic information about the authenticated user |
get_user_inventory | read | Returns the list of listings in a user |
get_user_lists | read | Get a user |
get_user_profile | read | Retrieve a user by username |
get_user_submissions | read | Retrieve a user |
get_user_wantlist | read | Returns the list of releases in a user |
inventory_export | read | Request an export of your inventory as a CSV |
move_release_in_user_collection | write | Move a release in a user |
rate_release_in_user_collection | read | Rate a release in a user |
search | read | Issue a search query to the Discogs database |
update_marketplace_listing | write | Update a marketplace listing |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (4 observation(s))
- Network
- declared (1 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (13)
delete_item_in_wantlist, delete_marketplace_listing, delete_release_from_user_collection_folder, delete_release_rating, delete_user_collection_folder
.env.test
.prettierignore
.prettierrc.json
const pkgPath = join(__dirname, '../../package.json');
const versionTs = readFileSync(join(__dirname, '../../src/version.ts'), 'utf8');
import { isDiscogsError } from '../../errors.js';import { UsernameInput } from '../../types/common.js';} from '../../types/user/index.js';
This will start the MCP Inspector at `http://127.0.0.1:6274`. Visit this URL in your browser to interact with your local MCP server.
data: '/9j/4QAiRXhpZgAATU0AKgAAAAgAAQESAAMAAAABAAEAAAAAAAD/2wCEAAMCAgMCAgMDAwMEAwMEBQgFBQQEBQoHBwYIDAoMDAsKCwsNDhIQDQ4RDgsLEBYQERMUFRUVDA8XGBYUGBIUFRQBAwQEBQQFCQUFCRQNCw0UFBQUFBQUFBQUFBQUFBQUFBQUFBQUF
@modelcontextprotocol/sdk, dotenv, fastmcp, zod, @changesets/cli, @eslint/js, @svitejs/changesets-changelog-github-compact, @types/node
To get your Discogs personal access token, go to your [Discogs Settings > Developers](https://www.discogs.com/settings/developers) page and find your token or generate a new one. **_DO NOT SHARE YOUR
Gates applied: no_behavioural_pass.
8bb8881f30d2full audit observations/trust-audit/mcp-server/cswkim__discogs.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | 8bb8881f30d2 | SAFE | B | 89 | first audit |
Questions
What is the Discogs MCP server?
MCP Server for Discogs
What tools does Discogs expose?
53 in total: 33 read-only, 15 that write, and 5 that can delete or overwrite (delete_item_in_wantlist, delete_marketplace_listing, delete_release_from_user_collection_folder, delete_release_rating, delete_user_collection_folder). Every one is listed on this page with its risk.
Is Discogs safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 5 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Discogs need?
It reads DISCOGS_PERSONAL_ACCESS_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Discogs run?
It speaks streamable-http, so it runs as a service you connect to over the network. It is published on npm as discogs-mcp-server at 0.5.7.
How current is this page?
The grade is for one exact copy of the source (8bb8881f30d2), read on 2026-10-07. The repository is watched and re-audited when it changes.