Amazon AdsCAUTION
Amazon Ads MCP - Model Context Protocol server for Amazon Advertising API
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Build AI-powered advertising applications with the Model Context Protocol (MCP) SDK for Amazon Advertising API
Made with ❤️ + ☕ by [Openbridge](https://www.openbridge.com/)
[](https://www.python.org/downloads/) [](https://opensource.org/licenses/MIT) [](https://github.com/KuudoAI/amazonadsmcp/actions/workflows/ci.yml)
MCP registry id (for clients and catalogs that display a stable package name): io.github.KuudoAI/amazon_ads_mcp
Table of contents
- Where this fits in Kuudo
- What are MCP tools?
- What is Amazon Ads API MCP SDK?
- Quick start
- Installation
- Configuration (auth, packages, profiles, regions)
- Downloading reports and exports
- Example MCP client (Claude Desktop)
- Context limits
- Code mode
- Tool audit
- Background tasks
- Frequently asked
- Troubleshooting
- Documentation map
Where this fits in Kuudo
This repository is the tool layer of a broader Amazon agent platform. Kuudo gives Amazon agents tools, knowledge, workflows, and a place to work. This repository is the tools.
b8317dc3160cOBSERVED · 2026-10-07Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add amazon-ads-mcp --env AMAZON_ADS_AUTH_METHOD=${AMAZON_ADS_AUTH_METHOD} --env AMAZON_ADS_DOWNLOAD_AUTH_TOKEN=${AMAZON_ADS_DOWNLOAD_AUTH_TOKEN} --env AMAZON_ADS_ENCRYPTION_KEY=${AMAZON_ADS_ENCRYPTION_KEY} --env AMAZON_ADS_TOKEN_PERSIST=${AMAZON_ADS_TOKEN_PERSIST} -- uvx amazon-ads-mcp{
"mcpServers": {
"amazon-ads-mcp": {
"command": "uvx",
"args": [
"amazon-ads-mcp"
],
"env": {
"AMAZON_ADS_AUTH_METHOD": "${AMAZON_ADS_AUTH_METHOD}",
"AMAZON_ADS_DOWNLOAD_AUTH_TOKEN": "${AMAZON_ADS_DOWNLOAD_AUTH_TOKEN}",
"AMAZON_ADS_ENCRYPTION_KEY": "${AMAZON_ADS_ENCRYPTION_KEY}",
"AMAZON_ADS_TOKEN_PERSIST": "${AMAZON_ADS_TOKEN_PERSIST}"
}
}
}
}Exposed tools (16)
14 read · 1 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
check_oauth_status | read | Check OAuth authentication status. |
clear_oauth_tokens | destructive | Clear OAuth tokens. |
constrained_tool | read | return { |
dummy_tool | read | return { |
echo | read | set_last_http_meta( |
enum_tool | read | return { |
get_region | read | Get the current region. |
list_downloads | read | List downloaded files for the active profile. |
list_identities | read | List all available identities. |
list_regions | read | List available regions. |
page_profiles | read | # Echo the values the function actually received so the test can |
refresh_oauth_token | read | Refresh OAuth access token. |
select_profile | read | Interactively select an Amazon Ads profile. |
start_oauth_flow | write | Start the OAuth authorization flow. |
test_QueryCampaign | read | return { |
test_sampling | read | Test the native MCP sampling functionality. |
Trust audit
CAUTIONgrade D · trust 60/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (2 observation(s))
- Network
- declared (8 observation(s))
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- found
Findings (25)
>>> print(f"Retrieved token: {token is not None}")self.logger.debug(f"Extracted token (length: {len(token)}, type: JWT)")self.logger.debug(f"Validating JWT token (length: {len(token)})")self.logger.error(f"Original token: {sanitize_string(token)}")sys.exit(0 if urllib.request.urlopen(f'http://127.0.0.1:{port}/health', timeout=4).status == 200 else 1)" \default="http://127.0.0.1:9080/mcp",
token = "sk_test_client_supplied"
token = "sk_test_client_supplied"
api_key="client-supplied-token",
api_key="client-supplied-token",
api_key = "client-supplied-token"
clear_oauth_tokens
CLAUDE.md
module = importlib.import_module(module_path)
for bad in ("../escape.csv", "a/../../escape.csv", "..\\escape"):"../../outside.csv", profile_id=profile_id
for bad in ("../escape.csv", "/etc/passwd", "a/../../escape.csv"):out = sanitize_filename("../../etc/passwd")(socket.AF_INET, socket.SOCK_STREAM, 6, "", ("169.254.169.254", 443))return [(socket.AF_INET, socket.SOCK_STREAM, 0, "", ("169.254.169.254", 0))]"https://169.254.169.254/latest/meta-data/",
--url http://127.0.0.1:9080/mcp \
--url http://127.0.0.1:9080/mcp \
--url http://127.0.0.1:9080/mcp \
encrypted_bytes = base64.b64decode(encrypted_b64)
Gates applied: no_behavioural_pass.
b8317dc3160cfull audit observations/trust-audit/mcp-server/kuudoai__amazon-ads-1.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | b8317dc3160c | CAUTION | D | 60 | first audit |
Questions
What is the Amazon Ads MCP server?
Amazon Ads MCP - Model Context Protocol server for Amazon Advertising API
What tools does Amazon Ads expose?
16 in total: 14 read-only, 1 that write, and 1 that can delete or overwrite (clear_oauth_tokens). Every one is listed on this page with its risk.
Is Amazon Ads safe to connect to an agent?
With care. The audit graded it D (60/100) and found 25 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Amazon Ads need?
It reads AMAZON_ADS_AUTH_METHOD, AMAZON_ADS_DOWNLOAD_AUTH_TOKEN, AMAZON_ADS_ENCRYPTION_KEY, AMAZON_ADS_TOKEN_PERSIST, AMAZON_AD_API_CLIENT_SECRET, AMAZON_AD_API_REFRESH_TOKEN, AUTH0_CLIENT_ID, AUTH0_DOMAIN, AUTH_ENABLED, AUTH_METHOD, DOWNLOAD_AUTH_TOKEN and JSON_API_TOKEN_TYPE_NAME from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Amazon Ads run?
It speaks streamable-http, so it runs as a service you connect to over the network. It is published on PyPI as amazon-ads-mcp.
How current is this page?
The grade is for one exact copy of the source (b8317dc3160c), read on 2026-10-07. The repository is watched and re-audited when it changes.