medusa-mcp

MCPattested
v0.3.0Pavel TrhoňMITUpdated 1d agonpmGitHub

MCP server for the Medusa v2 Admin API – orders, payments, returns, products, catalog, inventory, promotions, price lists and sales reports. stdio or remote (Streamable HTTP + OAuth 2.1).

Works in
ClaudeCursorCopilotGemini

Inferred from the transports this listing declares (stdio). A client not listed here hasn’t been ruled out — it just isn’t something Forge can confirm.

Attested build
A verified provenance attestation binds this artifact to the listed repository. Nobody has claimed the listing yet — this proves where the code was built, not who stands behind it.
794Downloads/wk
1Forks
1d agoLast update
Needs 1 credential before it runs
  • MEDUSA_API_KEYAPI keyrequired

    Secret API key from Medusa Admin → Settings → Developer → Secret API Keys (sk_…)

Declared by the author in the official MCP registry. Forge does not store, broker, or ever see these values — the config below is scaffolded with placeholders you fill in locally.

Package
AuthorPavel Trhoň
LicenseMIT
Version0.3.0
Sourcenpm+mcp-registry
Trust Status
A
85/100Trusted
✓Listed in Forge index+10/10
✓Identity verified · attested build+20/20
—Ed25519 publish signature+0/5
→ Included automatically when the publisher runs `forge publish`
—Domain verification+0/5
→ Publisher: host /.well-known/forge.json on the package homepage with { "publisher": "<github-login>" }
✓npm Trusted Publishing (Sigstore)+5/5
—npm maintainer match+0/5
→ Publisher: add the verified GitHub login to the npm package's maintainers (npm owner add <login>)
✓CVE scan · clean+30/30
✓Static analysis · clean+20/20
Paste into Claude Code, Cursor, or any AI assistant to fix all gaps
StatusIdentity verified
PublisherUnverified
SignatureUnsigned
Domain—
Provenance✓ Sigstore-verified · 0a89af4
Dependencies✓ 60 resolved+ · none vulnerable
Tool surface40 tools · 6 privileged
Security scan✓ Cleanv0.3.0 · todayHow well does this scan work?
EvalsNone
IndexedOct 4, 2026

Verification confirms publisher identity (repo ownership), not code safety. The security scan covers known CVEs and suspicious install scripts.

Tools

40 tools · 6 privileged
Statically extracted from the published packagev0.3.0 · 11h ago

Read out of the source npm actually ships, at scan time. The package was never executed. Tools registered dynamically at runtime, or hidden inside bundled or minified code, can be missed — so this is a floor on the tool surface, not a complete census of it.

list_catalogProduct categories (with parent, so the tree can be rebuilt), collections, tags and product types – with IDs for other tools.

Product categories (with parent, so the tree can be rebuilt), collections, tags and product types – with IDs for other tools.

No input schema was published for this tool.

save_categoryWithout category_id creates a product category (name required); with category_id updates only the given fields.

Without category_id creates a product category (name required); with category_id updates only the given fields.

No input schema was published for this tool.

delete_categoryprivilegedDELETES a product category (products stay, they just lose the category). Confirm with the user first.

DELETES a product category (products stay, they just lose the category). Confirm with the user first.

No input schema was published for this tool.

save_collectionWithout collection_id creates a collection (title required); with collection_id updates it. Can add or remove products

Without collection_id creates a collection (title required); with collection_id updates it. Can add or remove products

No input schema was published for this tool.

delete_collectionprivilegedDELETES a collection (products stay, they just leave the collection). Confirm with the user first.

DELETES a collection (products stay, they just leave the collection). Confirm with the user first.

No input schema was published for this tool.

list_customersSearches customers by name, email or company, optionally within a customer group.

Searches customers by name, email or company, optionally within a customer group.

No input schema was published for this tool.

get_customerCustomer detail with addresses, groups and order history (count, total spent, recent orders).

Customer detail with addresses, groups and order history (count, total spent, recent orders).

No input schema was published for this tool.

list_customer_groupsCustomer groups (e.g. B2B, VIP) – used by price lists and promotions.

Customer groups (e.g. B2B, VIP) – used by price lists and promotions.

No input schema was published for this tool.

save_customerWithout customer_id creates a customer (email required); with customer_id updates only the given fields.

Without customer_id creates a customer (email required); with customer_id updates only the given fields.

No input schema was published for this tool.

save_customer_groupWithout group_id creates a group (name required); with group_id renames it. Can add/remove customers.

Without group_id creates a group (name required); with group_id renames it. Can add/remove customers.

No input schema was published for this tool.

delete_customer_groupprivilegedDELETES a customer group (the customers stay). Price lists and promotions targeting it stop applying. Confirm with the user first.

DELETES a customer group (the customers stay). Price lists and promotions targeting it stop applying. Confirm with the user first.

No input schema was published for this tool.

list_inventoryInventory items with stock per location (stocked, reserved, available). With low_stock_threshold returns only items at or below the threshold.

Inventory items with stock per location (stocked, reserved, available). With low_stock_threshold returns only items at or below the threshold.

No input schema was published for this tool.

set_stock_levelSets the stocked quantity of an item at a location. Provide either an absolute 'stocked_quantity' or a relative 'adjust_by' (+/-).

Sets the stocked quantity of an item at a location. Provide either an absolute 'stocked_quantity' or a relative 'adjust_by' (+/-).

No input schema was published for this tool.

list_ordersLists orders, newest first. Filters: full-text, date range (YYYY-MM-DD in the reporting timezone), customer, order/payment/fulfillment status.

Lists orders, newest first. Filters: full-text, date range (YYYY-MM-DD in the reporting timezone), customer, order/payment/fulfillment status.

No input schema was published for this tool.

get_orderFull order detail – line items, addresses, payments (with captures and refunds), fulfillments, tracking numbers and returns.

Full order detail – line items, addresses, payments (with captures and refunds), fulfillments, tracking numbers and returns.

No input schema was published for this tool.

create_fulfillmentCreates a fulfillment for an order. Without 'items' it fulfills all remaining unfulfilled quantities.

Creates a fulfillment for an order. Without 'items' it fulfills all remaining unfulfilled quantities.

No input schema was published for this tool.

create_shipmentMarks a fulfillment as shipped and attaches a tracking number. Without 'fulfillment_id' it uses the only unshipped fulfillment.

Marks a fulfillment as shipped and attaches a tracking number. Without 'fulfillment_id' it uses the only unshipped fulfillment.

No input schema was published for this tool.

mark_deliveredMarks a fulfillment as delivered. Without 'fulfillment_id' it uses the only fulfillment that is not delivered yet.

Marks a fulfillment as delivered. Without 'fulfillment_id' it uses the only fulfillment that is not delivered yet.

No input schema was published for this tool.

cancel_fulfillmentCancels a fulfillment that has not been shipped yet, so its items can be fulfilled again.

Cancels a fulfillment that has not been shipped yet, so its items can be fulfilled again.

No input schema was published for this tool.

complete_orderMarks the order as completed.

Marks the order as completed.

No input schema was published for this tool.

cancel_orderCANCELS the order. Irreversible – get explicit confirmation from the user before calling. The order must not have active fulfillments.

CANCELS the order. Irreversible – get explicit confirmation from the user before calling. The order must not have active fulfillments.

No input schema was published for this tool.

update_orderChanges the order's email, shipping or billing address, or metadata (e.g. an internal note). Send only what should change;

Changes the order's email, shipping or billing address, or metadata (e.g. an internal note). Send only what should change;

No input schema was published for this tool.

mark_order_paidRecords a manual payment (e.g. a received bank transfer or cash on delivery) for the order's unpaid payment collection.

Records a manual payment (e.g. a received bank transfer or cash on delivery) for the order's unpaid payment collection.

No input schema was published for this tool.

capture_paymentCaptures an authorized payment (charges the customer). Without 'amount' captures the full remaining amount.

Captures an authorized payment (charges the customer). Without 'amount' captures the full remaining amount.

No input schema was published for this tool.

refund_paymentREFUNDS money to the customer through the payment provider. Irreversible – confirm the amount with the user before calling.

REFUNDS money to the customer through the payment provider. Irreversible – confirm the amount with the user before calling.

No input schema was published for this tool.

create_returnRequests a return of order items (the customer is sending them back). Without 'items' returns every shipped item.

Requests a return of order items (the customer is sending them back). Without 'items' returns every shipped item.

No input schema was published for this tool.

receive_returnRecords that returned items arrived; they go back to stock. Without 'items' receives everything requested.

Records that returned items arrived; they go back to stock. Without 'items' receives everything requested.

No input schema was published for this tool.

create_draft_orderCreates a draft order on behalf of a customer (phone or e-mail orders, B2B). Items by variant_id or SKU (of published products), optionally with a custom unit price.

Creates a draft order on behalf of a customer (phone or e-mail orders, B2B). Items by variant_id or SKU (of published products), optionally with a custom unit price.

No input schema was published for this tool.

convert_draft_orderTurns a draft order into a regular order (reserves stock). Record the payment afterwards with mark_order_paid.

Turns a draft order into a regular order (reserves stock). Record the payment afterwards with mark_order_paid.

No input schema was published for this tool.

list_price_listsPrice lists – sales (temporary discounted prices) and overrides (e.g. B2B prices for a customer group).

Price lists – sales (temporary discounted prices) and overrides (e.g. B2B prices for a customer group).

No input schema was published for this tool.

save_price_listWithout price_list_id creates a price list (title required); with price_list_id updates it.

Without price_list_id creates a price list (title required); with price_list_id updates it.

No input schema was published for this tool.

delete_price_listprivilegedDELETES a price list – its prices stop applying immediately. Confirm with the user first.

DELETES a price list – its prices stop applying immediately. Confirm with the user first.

No input schema was published for this tool.

list_productsLists products with their variants (SKUs). Filter by full-text, status, collection, category or tag.

Lists products with their variants (SKUs). Filter by full-text, status, collection, category or tag.

No input schema was published for this tool.

get_productProduct detail – variants, prices in all currencies, linked inventory items, options, categories, collection, tags, images and sales channels.

Product detail – variants, prices in all currencies, linked inventory items, options, categories, collection, tags, images and sales channels.

No input schema was published for this tool.

create_productCreates a product with its variants and prices. For a simple product without options pass just 'prices' (and optionally 'sku', 'stock').

Creates a product with its variants and prices. For a simple product without options pass just 'prices' (and optionally 'sku', 'stock').

No input schema was published for this tool.

update_productUpdates product fields – texts, status, handle, images, collection, categories, tags, sales channels, metadata.

Updates product fields – texts, status, handle, images, collection, categories, tags, sales channels, metadata.

No input schema was published for this tool.

delete_productprivilegedDELETES the product with all its variants. Irreversible – get explicit confirmation from the user before calling.

DELETES the product with all its variants. Irreversible – get explicit confirmation from the user before calling.

No input schema was published for this tool.

create_variantAdds a variant to an existing product, e.g. a new size. 'options' must name every product option; new option values are added automatically.

Adds a variant to an existing product, e.g. a new size. 'options' must name every product option; new option values are added automatically.

No input schema was published for this tool.

update_variantUpdates variant fields – title, SKU, barcodes, inventory tracking, backorders, weight, metadata. For prices use set_variant_price.

Updates variant fields – title, SKU, barcodes, inventory tracking, backorders, weight, metadata. For prices use set_variant_price.

No input schema was published for this tool.

delete_variantprivilegedDELETES one variant of a product. Irreversible – confirm with the user first. 'confirm' must equal the variant's SKU (or its title when it has no SKU).

DELETES one variant of a product. Irreversible – confirm with the user first. 'confirm' must equal the variant's SKU (or its title when it has no SKU).

No input schema was published for this tool.

40 of 40 tools published a description.

Tool names and descriptions are written by the publisher and shown verbatim as inert text. They are the strings an MCP client passes to a model, so Forge scans them for prompt-injection patterns — any finding appears with the security scan above. “Privileged” is a keyword match on the tool name, not an audit of what the tool does: a benign-sounding name can still do anything.

About

MCP server for the Medusa v2 Admin API – orders, payments, returns, products, catalog, inventory, promotions, price lists and sales reports. stdio or remote (Streamable HTTP + OAuth 2.1).

Keywords
mcpmodel-context-protocolmedusamedusajsecommerceclaudeoauth
Alternatives
Comparing tool surfaces…

Dependency tree

What one Forge scan resolved from npm metadata on 2026-10-04 — observed resolution, not a publisher declaration.

60 packages resolved · 4 direct · none carrying advisories Resolution stops at depth 4 and 60 packages.

The crawl stopped at the 60-package limit. The rest of the tree was never resolved.

36 more resolved packages are not drawn here (display cap: 24). Every dependency carrying an advisory is drawn regardless of the cap. Full inventory (CycloneDX SBOM)

Declared but not resolved

37 declared dependencies never landed in the tree. They are missing from Forge's resolution, not from the package.

+25 more not listed. The counts by reason above cover all of them.

Not followed: peerDependencies. This tree covers runtime dependencies only, so anything those pull in was never resolved.

Topics

Related in payments & commerce