Atlas / MCP servers / yosefhayim / eBay

eBayCAUTION

mcp/yosefhayim/ebay-2

Local MCP server that connects AI assistants to eBay seller APIs for listings, orders, and marketing, with OAuth setup.

Verdict
CAUTION
Grade
B
Trust score
85 /100
Exposed tools
200 212r · 118w · 32d
Transport
stdio · streamable-http
License
MIT
Stars
172
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

The eBay MCP server — give Claude, Cursor, and any AI assistant full access to eBay's Sell APIs. 384 tools for inventory, orders, marketing, and analytics, running locally with your own keys.

Unofficial, open-source project — not affiliated with, authorized, or endorsed by eBay Inc.

Read from source at commit 392ab1932424OBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add ebay-mcp --env EBAY_APP_ACCESS_TOKEN=${EBAY_APP_ACCESS_TOKEN} --env EBAY_CLIENT_SECRET=${EBAY_CLIENT_SECRET} --env EBAY_MCP_DISABLE_AUTH_HEADER=${EBAY_MCP_DISABLE_AUTH_HEADER} --env EBAY_OAUTH_CALLBACK_PORT=${EBAY_OAUTH_CALLBACK_PORT} -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "ebay-mcp": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ],
      "env": {
        "EBAY_APP_ACCESS_TOKEN": "${EBAY_APP_ACCESS_TOKEN}",
        "EBAY_CLIENT_SECRET": "${EBAY_CLIENT_SECRET}",
        "EBAY_MCP_DISABLE_AUTH_HEADER": "${EBAY_MCP_DISABLE_AUTH_HEADER}",
        "EBAY_OAUTH_CALLBACK_PORT": "${EBAY_OAUTH_CALLBACK_PORT}"
      }
    }
  }
}
03

Exposed tools (200)

212 read · 118 write · 32 destructive. Blast radius: 32 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
disable_ebay_toolswrite
ebay_accept_payment_disputereadAccept a payment dispute and allow eBay to refund the buyer. Use this when you agree with the buyer claim.\n\nRequired OAuth Scope: sell.fulfillment\nMinimum Scope: https://api.ebay.com/oauth/api_scope/sell.fulfillment
ebay_add_payment_dispute_evidencewriteAdd evidence to support your case in a payment dispute. Provide evidence files and supporting information.\n\nRequired OAuth Scope: sell.fulfillment\nMinimum Scope: https://api.ebay.com/oauth/api_scope/sell.fulfillment
ebay_add_store_categorywriteAdd one custom category to the eBay Store (Stores API addStoreCategory). Pass categoryName and optionally destinationParentCategoryId (omit or -999 for top level) and listingDestinationCategoryId. ${CATEGORY_TASK_NOTE} ${STORE_NOTE}
ebay_bulk_cancel_packagesreadCancel multiple packages in one request
ebay_bulk_confirm_packagesreadConfirm multiple packages in one request
ebay_bulk_create_ads_by_inventory_referencewriteBulk create ads by inventory reference through the eBay Marketing API.
ebay_bulk_create_ads_by_listing_idwriteBulk create ads by listing id through the eBay Marketing API.
ebay_bulk_create_keywordwriteBulk create keyword through the eBay Marketing API.
ebay_bulk_create_negative_keywordwriteBulk create negative keyword through the eBay Marketing API.
ebay_bulk_create_or_replace_inventory_itemwriteBulk create or replace multiple inventory items
ebay_bulk_create_or_replace_sales_taxwriteBulk create or replace sales tax tables
ebay_bulk_delete_ads_by_inventory_referencedestructiveBulk delete ads by inventory reference through the eBay Marketing API.
ebay_bulk_delete_ads_by_listing_iddestructiveBulk delete ads by listing id through the eBay Marketing API.
ebay_bulk_delete_packagesdestructiveDelete multiple packages in one request
ebay_bulk_get_inventory_itemreadBulk get multiple inventory items
ebay_bulk_migrate_listingreadBulk migrate listings to the inventory model
ebay_bulk_publish_offerwriteBulk publish multiple offers
ebay_bulk_update_ads_bid_by_inventory_referencewriteBulk update ads bid by inventory reference through the eBay Marketing API.
ebay_bulk_update_ads_bid_by_listing_idwriteBulk update ads bid by listing id through the eBay Marketing API.
ebay_bulk_update_ads_statuswriteBulk update ads status through the eBay Marketing API.
ebay_bulk_update_ads_status_by_listing_idwriteBulk update ads status by listing id through the eBay Marketing API.
ebay_bulk_update_conversationwriteBulk update multiple conversations. Each entry sets conversationStatus (ACTIVE, ARCHIVE, DELETE, READ, UNREAD) for a conversationId.
ebay_bulk_update_keywordwriteBulk update keyword through the eBay Marketing API.
ebay_bulk_update_negative_keywordwriteBulk update negative keyword through the eBay Marketing API.
ebay_bulk_update_price_quantitywriteBulk update price and quantity for multiple offers
ebay_cancel_bundlereadCancel a bundle by ID
ebay_cancel_packagereadCancel a package by ID
ebay_cancel_shipmentdestructiveCancel a shipment and delete its shipping label; eBay refunds the totalShippingCost to the billing agreement (Logistics API cancelShipment). Fails once the label has been used. Returns the shipment with its cancellation status. ${LOGISTICS_ACCESS_NOTE}
ebay_clear_tokensdestructiveClear all stored OAuth tokens (both user tokens and client credentials). This will require re-authentication for subsequent API calls.
ebay_clone_campaignreadClone campaign through the eBay Marketing API.
ebay_clone_packagewriteClone a package to create a duplicate
ebay_confirm_packagereadConfirm a package for shipping
ebay_contest_payment_disputereadContest a payment dispute by providing evidence. Use this when you disagree with the buyer claim and want to provide proof.\n\nRequired OAuth Scope: sell.fulfillment\nMinimum Scope: https://api.ebay.com/oauth/api_scope/sell.fulfillment
ebay_convert_date_to_timestampreadConvert a date string or number to Unix timestamp (milliseconds). Supports ISO 8601 dates, Unix timestamps (seconds or milliseconds), and relative time (e.g.,
ebay_create_ad_by_listing_idwriteCreate ad by listing id through the eBay Marketing API.
ebay_create_ad_groupwriteCreate ad group through the eBay Marketing API.
ebay_create_address_preferencewriteCreate an address preference for international shipping
ebay_create_ads_by_inventory_referencewriteCreate ads by inventory reference through the eBay Marketing API.
ebay_create_bundlewriteCreate a bundle of packages for international shipping
ebay_create_calculated_shipping_ruleswriteCreate calculated combined-shipping rules for listings that use calculated shipping (Account API v2 createCalculatedShippingRules): shippingRules.calculatedShippingRule (weight/item/cost-based discounts), calculatedHandlingRule, and/or combinedDuration. ${COMBINED_RULES_NOTE}
ebay_create_campaignwriteCreate campaign through the eBay Marketing API.
ebay_create_complaintwriteCreate a complaint for international shipping issues
ebay_create_consign_preferencewriteCreate a consign preference for international shipping
ebay_create_custom_policywriteCreate a new custom policy
ebay_create_documentwriteStage a listing document with documentType and languages. Returns documentId for ebay_upload_document. Requires sell.inventory.
ebay_create_document_from_urlwriteCreate a listing document from an HTTPS URL: PDF, JPEG/JPG or PNG up to 10 MiB. Check ebay_get_document for ACCEPTED before attaching it to a listing. Requires sell.inventory.
ebay_create_email_campaignwriteCreate email campaign through the eBay Marketing API.
ebay_create_flat_shipping_ruleswriteCreate flat-rate combined-shipping rules (Account API v2 createFlatShippingRules): shippingRules.flatShippingRule and/or combinedDuration. ${COMBINED_RULES_NOTE}
ebay_create_fulfillment_policywriteCreate a new fulfillment policy.\n\n
ebay_create_image_from_urlwriteCreate an EPS image from an HTTPS URL. Returns imageId, Location and the complete image payload, including EPS URLs. Requires sell.inventory.
ebay_create_inventory_locationwriteCreate an inventory location
ebay_create_item_price_markdown_promotionwriteCreate item price markdown promotion through the eBay Marketing API.
ebay_create_item_promotionwriteCreate item promotion through the eBay Marketing API.
ebay_create_keywordwriteCreate keyword through the eBay Marketing API.
ebay_create_listingwriteCreate a new fixed-price listing or auction.\n\nUses the Trading API: AddFixedPriceItem for format FIXED_PRICE (default) and AddItem with ListingType Chinese for format AUCTION. Requires complete item details.\n\n${AUCTION_ITEM_RULES} Reserve prices carry an eBay fee.\n\nRequired: User OAuth token.
ebay_create_negative_keywordwriteCreate negative keyword through the eBay Marketing API.
ebay_create_notification_destinationwriteCreate a notification destination
ebay_create_notification_subscriptionwriteCreate a notification subscription
ebay_create_notification_subscription_filterwriteCreate a filter for a notification subscription
ebay_create_or_replace_inventory_itemwriteCreate or replace an inventory item.\n\nRequired OAuth Scope: sell.inventory\nMinimum Scope: https://api.ebay.com/oauth/api_scope/sell.inventory
ebay_create_or_replace_inventory_item_groupwriteCreate or replace an inventory item group
ebay_create_or_replace_product_compatibilitywriteCreate or replace product compatibility for an inventory item
ebay_create_or_replace_sales_taxwriteCreate or replace sales tax table for a jurisdiction
ebay_create_or_replace_sku_location_mappingwriteCreate or replace SKU location mapping for a listing. Maps a SKU to fulfillment center locations.\n\nRequired OAuth Scope: sell.inventory\nMinimum Scope: https://api.ebay.com/oauth/api_scope/sell.inventory
ebay_create_packagewriteCreate a package for international shipping
ebay_create_payment_policywriteCreate a new payment policy
ebay_create_promotional_shipping_rulewriteCreate the promotional combined-shipping rule, e.g. discounted or free shipping above an order amount or item count (Account API v2 createPromotionalShippingRule): shippingRules.promotionalShippingRule and/or combinedDuration. ${COMBINED_RULES_NOTE}
ebay_create_report_taskwriteCreate report task through the eBay Marketing API.
ebay_create_return_policywriteCreate a new return policy
ebay_create_shipment_from_shipping_quotewritePurchase postage: create a shipment and its shipping label from one rate of a shipping quote (Logistics API createFromShippingQuote). This charges the seller
ebay_create_shipping_fulfillmentwriteCreate a shipping fulfillment for an order.\n\nRequired OAuth Scope: sell.fulfillment\nMinimum Scope: https://api.ebay.com/oauth/api_scope/sell.fulfillment
ebay_create_signing_keywriteCreate a new signing keypair for API digital signatures. Supports ED25519 (recommended) or RSA ciphers. IMPORTANT: Save the private key immediately as eBay does not store it.
ebay_create_vero_reportwriteCreate a VERO report to report intellectual property infringement. This endpoint is part of the Verified Rights Owner (VeRO) Program and allows rights owners to report listings that infringe on their intellectual property.
ebay_delete_addestructiveDelete ad through the eBay Marketing API.
ebay_delete_ads_by_inventory_referencedestructiveDelete ads by inventory reference through the eBay Marketing API.
ebay_delete_campaigndestructiveDelete campaign through the eBay Marketing API.
ebay_delete_email_campaigndestructiveDelete email campaign through the eBay Marketing API.
ebay_delete_feed_scheduledestructiveDelete a Feed API schedule so it stops generating reports. This cannot be undone. ${SCHEDULE_SCOPE_NOTE}
ebay_delete_fulfillment_policydestructiveDelete a fulfillment policy
ebay_delete_inventory_itemdestructiveDelete an inventory item by SKU.\n\nRequired OAuth Scope: sell.inventory\nMinimum Scope: https://api.ebay.com/oauth/api_scope/sell.inventory
ebay_delete_inventory_item_groupdestructiveDelete an inventory item group
ebay_delete_inventory_locationdestructiveDelete an inventory location
ebay_delete_item_price_markdown_promotiondestructiveDelete item price markdown promotion through the eBay Marketing API.
ebay_delete_item_promotiondestructiveDelete item promotion through the eBay Marketing API.
ebay_delete_notification_destinationdestructiveDelete a notification destination
ebay_delete_notification_subscriptiondestructiveDelete a notification subscription
ebay_delete_notification_subscription_filterdestructiveDelete a subscription filter
ebay_delete_offerdestructiveDelete an offer
ebay_delete_packagedestructiveDelete a package by ID
ebay_delete_payment_policydestructiveDelete a payment policy
ebay_delete_product_compatibilitydestructiveDelete product compatibility for an inventory item
ebay_delete_report_taskdestructiveDelete report task through the eBay Marketing API.
ebay_delete_return_policydestructiveDelete a return policy
ebay_delete_sales_taxdestructiveDelete sales tax table for a jurisdiction
ebay_delete_sku_location_mappingdestructiveDelete SKU location mapping for a listing. Removes fulfillment center location mappings for a SKU.\n\nRequired OAuth Scope: sell.inventory\nMinimum Scope: https://api.ebay.com/oauth/api_scope/sell.inventory
ebay_delete_store_categorydestructiveDelete one custom eBay Store category (Stores API deleteStoreCategory). Pass the store categoryId and optionally listingDestinationCategoryId; active listings in or under the category move there, or to the store
ebay_disable_inventory_locationwriteDisable an inventory location
ebay_disable_notification_subscriptionwriteDisable a notification subscription
ebay_download_post_order_documentwriteDownload a post-order document as an embedded PDF resource. SUBMITTED documents are owner-only; PUBLISHED documents require authorization in the post-order flow. Expired documents are unavailable. Requires commerce.post_order.document.
ebay_download_shipping_label_filereadDownload the shipping label of a shipment as an embedded PDF resource (Logistics API downloadLabelFile). Pass the shipmentId from ebay_create_shipment_from_shipping_quote. ${LOGISTICS_ACCESS_NOTE}
ebay_enable_inventory_locationwriteEnable an inventory location
ebay_enable_notification_subscriptionwriteEnable a notification subscription
ebay_end_campaignreadEnd campaign through the eBay Marketing API.
ebay_end_listingdestructiveEnd/remove an active listing.\n\nUses the Trading API: EndFixedPriceItem for format FIXED_PRICE (default) and EndItem for format AUCTION. SellToHighBidder is only valid for auctions with bids.\n\nRequired: User OAuth token.
ebay_fetch_item_aspectsreadTaxonomy API: download the aspects (item specifics) of every leaf category in a category tree as eBay
ebay_fetch_payment_dispute_evidence_contentreadDownload evidence file content from a payment dispute.\n\nRequired OAuth Scope: sell.fulfillment\nMinimum Scope: https://api.ebay.com/oauth/api_scope/sell.fulfillment
ebay_find_active_itemsreadSearch active eBay listings marketplace-wide (not the seller\
ebay_find_campaign_by_ad_referencereadFind campaign by ad reference through the eBay Marketing API.
ebay_find_eligible_itemswriteFind items eligible for Send Offer to Buyers
ebay_find_listing_recommendationsreadFind listing recommendations through the eBay Recommendation API.
ebay_find_seller_standards_profilesreadFind all seller standards profiles
ebay_get_actual_costsreadGet actual costs for shipped packages
ebay_get_adreadGet ad through the eBay Marketing API.
ebay_get_ad_groupreadGet ad group through the eBay Marketing API.
ebay_get_ad_groupsreadGet ad groups through the eBay Marketing API.
ebay_get_address_preferencesreadGet address preferences for international shipping
ebay_get_adsreadGet ads through the eBay Marketing API.
ebay_get_ads_by_inventory_referencereadGet ads by inventory reference through the eBay Marketing API.
ebay_get_advertising_eligibilityreadCheck the seller eligibility status for eBay advertising programs. This allows developers to determine if a seller is eligible for various advertising programs on eBay.\n\nRequired OAuth Scope: sell.account.readonly or sell.account
ebay_get_agentsreadGet available shipping agents for international shipping
ebay_get_api_statusreadGet the latest eBay API status and incidents from the official RSS feed. Returns recent issues, fixes, and outages for eBay APIs (e.g. Trading API, Inventory API, Sandbox). Use when the user asks about API status, outages, or fixes.
ebay_get_audiencesreadGet audiences through the eBay Marketing API.
ebay_get_automotive_parts_compatibility_policiesreadGet automotive parts compatibility policies for a marketplace
ebay_get_awaiting_feedbackreadGet transactions awaiting feedback from the seller
ebay_get_battery_qualificationsreadGet battery qualifications for international shipping
ebay_get_billing_activitiesreadGet seller billing activities (fees and credits) from the eBay Finances API. eBay requires exactly one filter criterion: activityId, listingId, orderId, or a transactionDate range starting within the last 120 days. Page with limit/offset, sort by transactionDate. ${FINANCES_SCOPE_NOTE}
ebay_get_bundlereadGet bundle details by ID
ebay_get_bundle_labelreadGet shipping label for a bundle
ebay_get_campaignreadGet campaign through the eBay Marketing API.
ebay_get_campaign_by_namereadGet campaign by name through the eBay Marketing API.
ebay_get_campaignsreadGet campaigns through the eBay Marketing API.
ebay_get_category_policiesreadGet category policies for a marketplace
ebay_get_category_suggestionsreadGet category suggestions based on query
ebay_get_category_treereadGet category tree by ID
ebay_get_charity_orgreadCharity API: get one charitable organization supported by eBay for Charity by charityOrgId (from ebay_get_charity_orgs): name, mission statement, description, logo, location, registration ID (EIN on EBAY_US) and website. ${CHARITY_AUTH_NOTE}
ebay_get_charity_orgsreadCharity API: search charitable organizations supported by eBay for Charity, either by keywords (q) or by comma-separated registrationIds; supply exactly one. Paginated with limit (1-100) and offset (0-10000). ${CHARITY_AUTH_NOTE}
ebay_get_classified_ad_policiesreadGet classified ad policies for a marketplace
ebay_get_combined_shipping_rulesreadGet the seller
ebay_get_compatibilities_by_specificationreadGet compatibilities by specification
ebay_get_compatibility_property_namesreadGet compatibility property names
ebay_get_compatibility_property_valuesreadGet compatibility property values
ebay_get_consign_preferencesreadGet consign preferences for international shipping
ebay_get_conversationreadGet a specific conversation by ID
ebay_get_conversationsreadGet all buyer-seller conversations (paginated)
ebay_get_currenciesreadGet currencies for a marketplace
ebay_get_custom_policiesreadRetrieve custom policies defined for the seller account
ebay_get_custom_policyreadGet a specific custom policy by ID
ebay_get_customer_service_metricreadGet customer service metrics
ebay_get_customer_service_metric_taskreadGet one Feed API customer service metric report task by taskId: status, filter criteria and timestamps. Requires sell.analytics.readonly.
ebay_get_customer_service_metric_tasksreadList Feed API customer service metric report tasks (CUSTOMER_SERVICE_METRICS_REPORT), filtered by dateRange or lookBackDays (not both), with limit/offset paging. Requires sell.analytics.readonly.
ebay_get_default_category_tree_idreadGet the default category tree ID for a marketplace
ebay_get_documentreadGet listing document metadata and processing status. Only ACCEPTED documents may be attached to listings. Does not download document bytes. Requires sell.inventory.
ebay_get_dropoff_sitesreadGet available dropoff sites for international shipping
ebay_get_email_campaignreadGet email campaign through the eBay Marketing API.
ebay_get_email_campaignsreadGet email campaigns through the eBay Marketing API.
ebay_get_email_previewreadGet email preview through the eBay Marketing API.
ebay_get_email_reportreadGet email report through the eBay Marketing API.
ebay_get_exclude_shipping_locationsreadMetadata API: list the regions, countries and special locations (e.g. PO Box, APO/FPO) a seller can exclude from shipping on a marketplace. ${SHIPPING_LANGUAGE_NOTE}
ebay_get_expired_categoriesreadTaxonomy API: list expired leaf categories in a category tree with the active categories that replaced them (fromCategoryId to toCategoryId; several may merge into one). Only mapped (merged or split) categories are returned; an empty success (HTTP 204) means the tree has none.
ebay_get_extended_producer_responsibility_policiesreadGet extended producer responsibility policies for a marketplace
ebay_get_feed_schedulewriteGet one Feed API schedule by scheduleId: template, trigger settings, status and last run. ${SCHEDULE_SCOPE_NOTE}
ebay_get_feed_schedule_result_filewriteDownload the latest report a Feed API schedule generated (compressed or plain CSV, XML or JSON). ${DOWNLOAD_NOTE} ${SCHEDULE_SCOPE_NOTE}
ebay_get_feed_schedule_templatewriteGet one Feed API schedule template by scheduleTemplateId: feed type, frequency and which schedule fields are required or optional (with defaults). ${SCHEDULE_SCOPE_NOTE}
ebay_get_feed_schedule_templateswriteList the Feed API schedule templates for a feedType (required), with limit/offset paging; use a template ID with ebay_create_feed_schedule. ${SCHEDULE_SCOPE_NOTE}
ebay_get_feed_schedulesreadList the seller
ebay_get_feed_taskreadGet one Feed API task by taskId: feed type, status (QUEUED, IN_PROCESS, then COMPLETED or COMPLETED_WITH_ERROR when the file is ready), timestamps and the upload summary (success and failure counts). ${TASK_SCOPE_NOTE}
ebay_get_feed_task_input_filereadDownload the file previously uploaded to a Feed API task (not available for LMS_ORDER_REPORT or LMS_ACTIVE_INVENTORY_REPORT tasks). ${DOWNLOAD_NOTE} ${TASK_SCOPE_NOTE}
ebay_get_feed_task_result_filereadDownload the result file of a Feed API task once it is COMPLETED or COMPLETED_WITH_ERROR: the generated report (order, inventory or customer service metric task IDs work too) or an upload
ebay_get_feed_tasksreadList Feed API tasks (uploads and downloads, on-demand and scheduled) by feedType or scheduleId (not both), filtered by dateRange or lookBackDays (not both), with limit/offset paging. ${TASK_SCOPE_NOTE}
ebay_get_feedbackreadGet feedback for a user by type
ebay_get_feedback_rating_summaryreadGet feedback rating summary for a user
ebay_get_fulfillment_policiesreadGet fulfillment policies for the seller.\n\nRequired OAuth Scope: sell.account.readonly or sell.account\nMinimum Scope: https://api.ebay.com/oauth/api_scope/sell.account.readonly
ebay_get_fulfillment_policyreadGet a specific fulfillment policy by ID
ebay_get_fulfillment_policy_by_namereadGet a fulfillment policy by name
ebay_get_handling_timesdestructiveMetadata API: list the handling times (maximum business days to ship after cleared payment, flagged when extended) a marketplace allows. ${SHIPPING_LANGUAGE_NOTE}
ebay_get_handover_sheetreadGet handover sheet for packages
ebay_get_hazardous_materials_labelsreadGet hazardous materials labels for a marketplace
ebay_get_inventory_itemreadGet a specific inventory item by SKU.\n\nRequired OAuth Scope: sell.inventory.readonly or sell.inventory\nMinimum Scope: https://api.ebay.com/oauth/api_scope/sell.inventory.readonly
ebay_get_inventory_item_groupreadGet an inventory item group (variation group)
ebay_get_inventory_itemsreadRetrieve all inventory items for the seller.\n\nRequired OAuth Scope: sell.inventory.readonly or sell.inventory\nMinimum Scope: https://api.ebay.com/oauth/api_scope/sell.inventory.readonly
ebay_get_inventory_locationreadGet a specific inventory location
ebay_get_inventory_locationsreadGet all inventory locations
ebay_get_inventory_taskreadGet one Feed API active inventory report task by taskId: status, filter criteria and timestamps. Requires sell.inventory.
ebay_get_inventory_tasksreadList Feed API active inventory report tasks (LMS_ACTIVE_INVENTORY_REPORT), filtered by dateRange or lookBackDays (not both), with limit/offset paging. Requires sell.inventory.
ebay_get_item_aspects_for_categoryreadIdentify required and recommended item specifics for a category before creating an inventory item or checking listing fees
ebay_get_item_condition_policiesreadGet item condition policies for a marketplace
ebay_get_item_detailsreadGet full detail for one active eBay listing by its Browse RESTful item id (from ebay_find_active_items, e.g.
ebay_get_item_price_markdown_promotionreadGet item price markdown promotion through the eBay Marketing API.
ebay_get_item_promotionreadGet item promotion through the eBay Marketing API.
ebay_get_keywordreadGet keyword through the eBay Marketing API.
ebay_get_keywordsreadGet keywords through the eBay Marketing API.
ebay_get_kycreadGet seller KYC (Know Your Customer) status
ebay_get_labelsreadGet shipping labels for packages
ebay_get_listingreadGet full details for a single listing by item ID.\n\nUses the Trading API (GetItem). Returns all listing fields including description, specifics, shipping, images, and ListingType (Chinese = auction, FixedPriceItem = fixed price).\n\nRequired: User OAuth token.
ebay_get_listing_feesreadGet listing fees for offers before publishing
ebay_get_listing_setwriteGet listing set through the eBay Marketing API.
ebay_get_listing_structure_policiesreadGet listing structure policies for a marketplace
ebay_get_listing_type_policiesreadGet listing type policies for a marketplace
ebay_get_listing_violationsreadDECOMMISSIONED: eBay shut down the Sell Compliance API on 2026-03-30. This tool always fails with a clear message. Use Seller Hub → Performance → Issue Resolution Center instead (no API equivalent).
04

Trust audit

CAUTIONgrade B · trust 85/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (4 observation(s))
Network
declared (3 observation(s))
Shell
declared (3 observation(s))
Dependencies
not all pinned
Secrets in source
found

Findings (19)

MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
src/types/ebay.ts:261
TOKEN = '/identity/v1/oauth2/token',
MEDIUMHard-coded secrets · secret.private_key · CWE-798, CWE-321
tests/unit/api/developer.test.ts:242
privateKey: '-----BEGIN PRIVATE KEY-----\nMIIEvgIBADANBgkqhkiG9w0BAQEFAAOCAQ8A...',
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
ebay_bulk_delete_ads_by_inventory_reference, ebay_bulk_delete_ads_by_listing_id, ebay_bulk_delete_packages, ebay_cancel_shipment, ebay_clear_tokens, ebay_delete_ad, ebay_delete_ads_by_inventory_refere
Why it matters. 32 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/config/credentialFile.ts:16
join(dirname(fileURLToPath(moduleUrl)), '../../.env');
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/config/environment.ts:606
const url = new URL(`../../public/icons/${size}.png`, import.meta.url);
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
src/utils/version.ts:9
const PACKAGE_JSON_PATH = join(__dirname, '../../package.json');
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/integration/api/ebayApiClient.test.ts:19
vi.mock('../../../src/auth/oauth.js', () => ({
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/integration/mcp/noContentResponses.test.ts:17
vi.mock('../../../src/auth/oauth.js', () => ({
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
tests/unit/config/environment.test.ts:361
process.env.EBAY_MCP_API_BASE_URL = 'http://127.0.0.1:8080';
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
tests/unit/mcp/httpTransport.test.ts:37
expect(getHttpServerUrl(config)).toBe('http://127.0.0.1:3000');
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
tests/unit/mcp/httpTransport.test.ts:108
const loopback = await request(app).get('/health').set('Origin', 'http://127.0.0.1:3000');
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
tests/unit/mcp/httpTransport.test.ts:112
expect(loopback.headers['access-control-allow-origin']).toBe('http://127.0.0.1:3000');
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
tests/unit/utils/http.test.ts:51
baseUrl = `http://127.0.0.1:${(server.address() as AddressInfo).port}`;
LOWObfuscation / stealth · obf.zero_width · CWE-506, CWE-94
tests/unit/utils/localFeedFiles.test.ts:58
['utf16.xml', Buffer.from('<a/>', 'utf16le'), 'UTF-8 text without NUL bytes'],
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
chalk, cors, dotenv, effect, express, fast-xml-parser, helmet, jose
Why it matters. 33 dependency range(s) float
Fix. pin exact versions or ship a lockfile
INFOInventory / provenance · inv.oversize · CWE-1104
public/icons/1024x1024.png
public/icons/1024x1024.png
Why it matters. 1155849 bytes not read
INFOInventory / provenance · inv.oversize · CWE-1104
public/video-tutorial.mp4
public/video-tutorial.mp4
Why it matters. 3640972 bytes not read
INFOPrompt injection · prompt.authority_framing · CWE-94, CWE-1427
README.md:8
<strong>The eBay MCP server — give Claude, Cursor, and any AI assistant full access to eBay's Sell APIs. 384 tools for inventory, orders, marketing, and analytics, running locally with your own keys.<
INFOPrompt injection · prompt.credential_read · CWE-94, CWE-1427
llms.txt:127
No. "Runs locally" means the server runs on your machine; it still needs internet access and valid credentials to reach eBay's live APIs.
Why it matters. asks the agent to read credentials

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha 392ab1932424full audit observations/trust-audit/mcp-server/yosefhayim__ebay-2.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-07392ab1932424CAUTIONB85first audit
06

Questions

What is the eBay MCP server?

Local MCP server that connects AI assistants to eBay seller APIs for listings, orders, and marketing, with OAuth setup.

What tools does eBay expose?

200 in total: 212 read-only, 118 that write, and 32 that can delete or overwrite (ebay_bulk_delete_ads_by_inventory_reference, ebay_bulk_delete_ads_by_listing_id, ebay_bulk_delete_packages, ebay_cancel_shipment, ebay_clear_tokens). Every one is listed on this page with its risk.

Is eBay safe to connect to an agent?

With care. The audit graded it B (85/100) and found 19 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 32 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does eBay need?

It reads EBAY_APP_ACCESS_TOKEN, EBAY_CLIENT_SECRET, EBAY_MCP_DISABLE_AUTH_HEADER, EBAY_OAUTH_CALLBACK_PORT, EBAY_OAUTH_SCOPES, EBAY_USER_ACCESS_TOKEN and EBAY_USER_REFRESH_TOKEN from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does eBay run?

It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on npm as ebay-mcp at 1.18.0.

How current is this page?

The grade is for one exact copy of the source (392ab1932424), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement