medusa-mcp

MCPattesté
v0.3.0Pavel TrhoňMITMis à jour il y a 1 jnpmGitHub

MCP server for the Medusa v2 Admin API – orders, payments, returns, products, catalog, inventory, promotions, price lists and sales reports. stdio or remote (Streamable HTTP + OAuth 2.1).

Fonctionne dans
ClaudeCursorCopilotGemini

Déduit des transports déclarés par cette annonce (stdio). Un client absent de cette liste n’est pas écarté pour autant — c’est simplement quelque chose que Forge ne peut pas confirmer.

Build attesté
Une attestation de provenance vérifiée lie cet artefact au dépôt indiqué. Personne n’a encore revendiqué l’annonce — cela prouve où le code a été construit, pas qui le soutient.
794Téléch./sem.
1Forks
il y a 1 jDernière mise à jour
Nécessite 1 identifiant avant de pouvoir fonctionner
  • MEDUSA_API_KEYClé d’APIobligatoire

    Secret API key from Medusa Admin → Settings → Developer → Secret API Keys (sk_…)

Déclaré par l’auteur dans le registre MCP officiel. Forge does not store, broker, or ever see these values — the config below is scaffolded with placeholders you fill in locally.

Paquet
AuteurPavel Trhoň
LicenceMIT
Version0.3.0
Sourcenpm+mcp-registry
Statut de confiance
A
85/100Fiable
✓Listé dans l’index Forge+10/10
✓Identité vérifiée · build attesté+20/20
—Signature de publication Ed25519+0/5
→ Incluse automatiquement quand l’éditeur exécute `forge publish`
—Vérification de domaine+0/5
→ Éditeur : hébergez /.well-known/forge.json sur la page d’accueil du paquet avec { "publisher": "<github-login>" }
✓npm Trusted Publishing (Sigstore)+5/5
—Correspondance de mainteneur npm+0/5
→ Éditeur : ajoutez le login GitHub vérifié aux mainteneurs du paquet npm (npm owner add <login>)
✓Analyse CVE · propre+30/30
✓Analyse statique · propre+20/20
Collez-le dans Claude Code, Cursor ou tout assistant d’IA pour combler toutes les lacunes
StatutIdentité vérifiée
ÉditeurNon vérifié
SignatureNon signé
Domaine—
Provenance✓ Vérifié par Sigstore · 0a89af4
Dépendances✓ 60 résolues+ · aucune vulnérable
Surface d’outils40 outils · 6 privilégiés
Analyse de sécurité✓ Proprev0.3.0 · aujourd’huiQuelle est l’efficacité de cette analyse ?
ÉvaluationsAucune
Indexé4 oct. 2026

La vérification confirme l’identité de l’éditeur (la propriété du dépôt), pas la sûreté du code. L’analyse de sécurité couvre les CVE connues et les scripts d’installation suspects.

Outils

40 outils · 6 privilégiés
Extrait statiquement du paquet publiév0.3.0 · 12h ago

Lu dans le code que npm livre réellement, au moment de l’analyse. Le paquet n’a jamais été exécuté. Les outils enregistrés dynamiquement à l’exécution, ou cachés dans du code empaqueté ou minifié, peuvent passer inaperçus — c’est donc un plancher de la surface d’outils, pas un recensement complet.

list_catalogProduct categories (with parent, so the tree can be rebuilt), collections, tags and product types – with IDs for other tools.

Product categories (with parent, so the tree can be rebuilt), collections, tags and product types – with IDs for other tools.

Aucun schéma d’entrée n’a été publié pour cet outil.

save_categoryWithout category_id creates a product category (name required); with category_id updates only the given fields.

Without category_id creates a product category (name required); with category_id updates only the given fields.

Aucun schéma d’entrée n’a été publié pour cet outil.

delete_categoryprivilégiéDELETES a product category (products stay, they just lose the category). Confirm with the user first.

DELETES a product category (products stay, they just lose the category). Confirm with the user first.

Aucun schéma d’entrée n’a été publié pour cet outil.

save_collectionWithout collection_id creates a collection (title required); with collection_id updates it. Can add or remove products

Without collection_id creates a collection (title required); with collection_id updates it. Can add or remove products

Aucun schéma d’entrée n’a été publié pour cet outil.

delete_collectionprivilégiéDELETES a collection (products stay, they just leave the collection). Confirm with the user first.

DELETES a collection (products stay, they just leave the collection). Confirm with the user first.

Aucun schéma d’entrée n’a été publié pour cet outil.

list_customersSearches customers by name, email or company, optionally within a customer group.

Searches customers by name, email or company, optionally within a customer group.

Aucun schéma d’entrée n’a été publié pour cet outil.

get_customerCustomer detail with addresses, groups and order history (count, total spent, recent orders).

Customer detail with addresses, groups and order history (count, total spent, recent orders).

Aucun schéma d’entrée n’a été publié pour cet outil.

list_customer_groupsCustomer groups (e.g. B2B, VIP) – used by price lists and promotions.

Customer groups (e.g. B2B, VIP) – used by price lists and promotions.

Aucun schéma d’entrée n’a été publié pour cet outil.

save_customerWithout customer_id creates a customer (email required); with customer_id updates only the given fields.

Without customer_id creates a customer (email required); with customer_id updates only the given fields.

Aucun schéma d’entrée n’a été publié pour cet outil.

save_customer_groupWithout group_id creates a group (name required); with group_id renames it. Can add/remove customers.

Without group_id creates a group (name required); with group_id renames it. Can add/remove customers.

Aucun schéma d’entrée n’a été publié pour cet outil.

delete_customer_groupprivilégiéDELETES a customer group (the customers stay). Price lists and promotions targeting it stop applying. Confirm with the user first.

DELETES a customer group (the customers stay). Price lists and promotions targeting it stop applying. Confirm with the user first.

Aucun schéma d’entrée n’a été publié pour cet outil.

list_inventoryInventory items with stock per location (stocked, reserved, available). With low_stock_threshold returns only items at or below the threshold.

Inventory items with stock per location (stocked, reserved, available). With low_stock_threshold returns only items at or below the threshold.

Aucun schéma d’entrée n’a été publié pour cet outil.

set_stock_levelSets the stocked quantity of an item at a location. Provide either an absolute 'stocked_quantity' or a relative 'adjust_by' (+/-).

Sets the stocked quantity of an item at a location. Provide either an absolute 'stocked_quantity' or a relative 'adjust_by' (+/-).

Aucun schéma d’entrée n’a été publié pour cet outil.

list_ordersLists orders, newest first. Filters: full-text, date range (YYYY-MM-DD in the reporting timezone), customer, order/payment/fulfillment status.

Lists orders, newest first. Filters: full-text, date range (YYYY-MM-DD in the reporting timezone), customer, order/payment/fulfillment status.

Aucun schéma d’entrée n’a été publié pour cet outil.

get_orderFull order detail – line items, addresses, payments (with captures and refunds), fulfillments, tracking numbers and returns.

Full order detail – line items, addresses, payments (with captures and refunds), fulfillments, tracking numbers and returns.

Aucun schéma d’entrée n’a été publié pour cet outil.

create_fulfillmentCreates a fulfillment for an order. Without 'items' it fulfills all remaining unfulfilled quantities.

Creates a fulfillment for an order. Without 'items' it fulfills all remaining unfulfilled quantities.

Aucun schéma d’entrée n’a été publié pour cet outil.

create_shipmentMarks a fulfillment as shipped and attaches a tracking number. Without 'fulfillment_id' it uses the only unshipped fulfillment.

Marks a fulfillment as shipped and attaches a tracking number. Without 'fulfillment_id' it uses the only unshipped fulfillment.

Aucun schéma d’entrée n’a été publié pour cet outil.

mark_deliveredMarks a fulfillment as delivered. Without 'fulfillment_id' it uses the only fulfillment that is not delivered yet.

Marks a fulfillment as delivered. Without 'fulfillment_id' it uses the only fulfillment that is not delivered yet.

Aucun schéma d’entrée n’a été publié pour cet outil.

cancel_fulfillmentCancels a fulfillment that has not been shipped yet, so its items can be fulfilled again.

Cancels a fulfillment that has not been shipped yet, so its items can be fulfilled again.

Aucun schéma d’entrée n’a été publié pour cet outil.

complete_orderMarks the order as completed.

Marks the order as completed.

Aucun schéma d’entrée n’a été publié pour cet outil.

cancel_orderCANCELS the order. Irreversible – get explicit confirmation from the user before calling. The order must not have active fulfillments.

CANCELS the order. Irreversible – get explicit confirmation from the user before calling. The order must not have active fulfillments.

Aucun schéma d’entrée n’a été publié pour cet outil.

update_orderChanges the order's email, shipping or billing address, or metadata (e.g. an internal note). Send only what should change;

Changes the order's email, shipping or billing address, or metadata (e.g. an internal note). Send only what should change;

Aucun schéma d’entrée n’a été publié pour cet outil.

mark_order_paidRecords a manual payment (e.g. a received bank transfer or cash on delivery) for the order's unpaid payment collection.

Records a manual payment (e.g. a received bank transfer or cash on delivery) for the order's unpaid payment collection.

Aucun schéma d’entrée n’a été publié pour cet outil.

capture_paymentCaptures an authorized payment (charges the customer). Without 'amount' captures the full remaining amount.

Captures an authorized payment (charges the customer). Without 'amount' captures the full remaining amount.

Aucun schéma d’entrée n’a été publié pour cet outil.

refund_paymentREFUNDS money to the customer through the payment provider. Irreversible – confirm the amount with the user before calling.

REFUNDS money to the customer through the payment provider. Irreversible – confirm the amount with the user before calling.

Aucun schéma d’entrée n’a été publié pour cet outil.

create_returnRequests a return of order items (the customer is sending them back). Without 'items' returns every shipped item.

Requests a return of order items (the customer is sending them back). Without 'items' returns every shipped item.

Aucun schéma d’entrée n’a été publié pour cet outil.

receive_returnRecords that returned items arrived; they go back to stock. Without 'items' receives everything requested.

Records that returned items arrived; they go back to stock. Without 'items' receives everything requested.

Aucun schéma d’entrée n’a été publié pour cet outil.

create_draft_orderCreates a draft order on behalf of a customer (phone or e-mail orders, B2B). Items by variant_id or SKU (of published products), optionally with a custom unit price.

Creates a draft order on behalf of a customer (phone or e-mail orders, B2B). Items by variant_id or SKU (of published products), optionally with a custom unit price.

Aucun schéma d’entrée n’a été publié pour cet outil.

convert_draft_orderTurns a draft order into a regular order (reserves stock). Record the payment afterwards with mark_order_paid.

Turns a draft order into a regular order (reserves stock). Record the payment afterwards with mark_order_paid.

Aucun schéma d’entrée n’a été publié pour cet outil.

list_price_listsPrice lists – sales (temporary discounted prices) and overrides (e.g. B2B prices for a customer group).

Price lists – sales (temporary discounted prices) and overrides (e.g. B2B prices for a customer group).

Aucun schéma d’entrée n’a été publié pour cet outil.

save_price_listWithout price_list_id creates a price list (title required); with price_list_id updates it.

Without price_list_id creates a price list (title required); with price_list_id updates it.

Aucun schéma d’entrée n’a été publié pour cet outil.

delete_price_listprivilégiéDELETES a price list – its prices stop applying immediately. Confirm with the user first.

DELETES a price list – its prices stop applying immediately. Confirm with the user first.

Aucun schéma d’entrée n’a été publié pour cet outil.

list_productsLists products with their variants (SKUs). Filter by full-text, status, collection, category or tag.

Lists products with their variants (SKUs). Filter by full-text, status, collection, category or tag.

Aucun schéma d’entrée n’a été publié pour cet outil.

get_productProduct detail – variants, prices in all currencies, linked inventory items, options, categories, collection, tags, images and sales channels.

Product detail – variants, prices in all currencies, linked inventory items, options, categories, collection, tags, images and sales channels.

Aucun schéma d’entrée n’a été publié pour cet outil.

create_productCreates a product with its variants and prices. For a simple product without options pass just 'prices' (and optionally 'sku', 'stock').

Creates a product with its variants and prices. For a simple product without options pass just 'prices' (and optionally 'sku', 'stock').

Aucun schéma d’entrée n’a été publié pour cet outil.

update_productUpdates product fields – texts, status, handle, images, collection, categories, tags, sales channels, metadata.

Updates product fields – texts, status, handle, images, collection, categories, tags, sales channels, metadata.

Aucun schéma d’entrée n’a été publié pour cet outil.

delete_productprivilégiéDELETES the product with all its variants. Irreversible – get explicit confirmation from the user before calling.

DELETES the product with all its variants. Irreversible – get explicit confirmation from the user before calling.

Aucun schéma d’entrée n’a été publié pour cet outil.

create_variantAdds a variant to an existing product, e.g. a new size. 'options' must name every product option; new option values are added automatically.

Adds a variant to an existing product, e.g. a new size. 'options' must name every product option; new option values are added automatically.

Aucun schéma d’entrée n’a été publié pour cet outil.

update_variantUpdates variant fields – title, SKU, barcodes, inventory tracking, backorders, weight, metadata. For prices use set_variant_price.

Updates variant fields – title, SKU, barcodes, inventory tracking, backorders, weight, metadata. For prices use set_variant_price.

Aucun schéma d’entrée n’a été publié pour cet outil.

delete_variantprivilégiéDELETES one variant of a product. Irreversible – confirm with the user first. 'confirm' must equal the variant's SKU (or its title when it has no SKU).

DELETES one variant of a product. Irreversible – confirm with the user first. 'confirm' must equal the variant's SKU (or its title when it has no SKU).

Aucun schéma d’entrée n’a été publié pour cet outil.

40 outils sur 40 ont publié une description.

Les noms et descriptions d’outils sont écrits par l’éditeur et affichés tels quels, comme du texte inerte. Ce sont les chaînes qu’un client MCP transmet à un modèle, alors Forge y recherche des motifs d’injection de prompt — tout constat apparaît avec l’analyse de sécurité ci-dessus. « Privilégié » est une correspondance de mot-clé sur le nom de l’outil, pas un audit de ce qu’il fait : un nom anodin peut tout de même tout faire.

À propos

MCP server for the Medusa v2 Admin API – orders, payments, returns, products, catalog, inventory, promotions, price lists and sales reports. stdio or remote (Streamable HTTP + OAuth 2.1).

Mots-clés
mcpmodel-context-protocolmedusamedusajsecommerceclaudeoauth
Alternatives
Comparaison des surfaces d’outils…

Arbre de dépendances

Ce qu'une analyse Forge a résolu à partir des métadonnées npm le 2026-10-04 — résolution observée, et non une déclaration de l'éditeur.

60 paquets résolus · 4 directs · aucun porteur d'avis de sécurité La résolution s'arrête à la profondeur 4 et à 60 paquets.

L'exploration s'est arrêtée à la limite de 60 paquets. Le reste de l'arbre n'a jamais été résolu.

36 autres paquets résolus ne sont pas dessinés ici (limite d'affichage : 24). Toute dépendance porteuse d'un avis de sécurité est dessinée quelle que soit la limite. Inventaire complet (SBOM CycloneDX)

Déclarées mais non résolues

37 dépendances déclarées ne sont jamais arrivées dans l'arbre. Elles manquent à la résolution de Forge, pas au paquet.

+25 de plus non listées. Les comptes par motif ci-dessus les couvrent toutes.

Non suivies : peerDependencies. Cet arbre ne couvre que les dépendances d'exécution ; ce qu'elles entraînent n'a jamais été résolu.

Thèmes

Apparentés dans payments & commerce