PluginBench
MCP Server
Active
MIT

io.github.Dudude-bit/yandex-lavka-mcp MCP Server

io.github.Dudude-bit/yandex-lavka-mcp

AI-powered Yandex Lavka grocery ordering: search, cart, and checkout with explicit confirmation.

What is the io.github.Dudude-bit/yandex-lavka-mcp MCP server?

The yandex-lavka-mcp server is an unofficial MCP server that enables AI assistants to order groceries from Yandex Lavka by searching products, managing a shopping cart, and placing real orders. It uses your own Yandex session cookies to automate your account, with a two-step confirmation flow to prevent accidental charges.

This server bridges Claude and other AI assistants to Yandex Lavka's private API, letting you search the grocery catalog, add items to your cart, preview orders with full pricing and delivery details, and place real orders—all through natural conversation. It's designed for hands-off grocery shopping: the AI can search and build your cart, but you must explicitly confirm the final total before any money is charged.

How to install io.github.Dudude-bit/yandex-lavka-mcp

Copy-paste configuration for popular MCP clients.

transport: stdio
Config generated by PluginBench — verify against the source before use.
~/Library/Application Support/Claude/claude_desktop_config.json
{
  "mcpServers": {
    "yandex-lavka-mcp": {
      "command": "uvx",
      "args": [
        "yandex-lavka-mcp"
      ]
    }
  }
}

Tools & capabilities

Tools this server exposes to the agent.

  • lavka_status — Check if the session and delivery location are configured.
  • list_addresses — Retrieve your saved Lavka delivery addresses by name.
  • use_address — Switch delivery to a saved address by name.
  • set_delivery_address — Set delivery to any address by text, supporting any city with geocoding.
  • set_location — Set delivery point by latitude and longitude coordinates.
  • search_products — Search the grocery catalog at the current delivery location.
  • get_product — Retrieve detailed information about a specific product.
  • view_cart — Display current cart contents and total price.
  • add_to_cart — Add an item to the shopping cart.
  • update_cart_item — Set exact quantity for a cart item (0 removes it).
  • clear_cart — Empty the entire shopping cart.
  • checkout_preview — Generate a full order summary with items, subtotal, discount, delivery, ETA, and total—without charging.
  • confirm_order — Place the order and charge the on-file card; requires exact total from a recent preview.
  • cancel_order — Cancel an order by its ID.
  • active_orders — List currently tracked orders with status and estimated delivery time.

Use cases

  • Search for groceries by name and browse product details at your delivery location.
  • Build a shopping cart by adding items, adjusting quantities, and viewing the total.
  • Preview a complete order summary (items, subtotal, delivery fee, ETA, final total) before committing to payment.
  • Place a real order and pay with your on-file card, with explicit confirmation of the final amount.
  • Manage multiple delivery addresses and switch between them (e.g., home, dacha, office).

io.github.Dudude-bit/yandex-lavka-mcp MCP server FAQ

What is the yandex-lavka-mcp server?

It's an unofficial MCP server that lets AI assistants order groceries from Yandex Lavka by searching products, managing a cart, and placing real orders using your own Yandex account.

Does it cost money to use?

The server itself is free and open-source (MIT license). Placing an order with `confirm_order` charges your on-file Yandex Lavka payment card for the groceries.

How do I install it in Claude or Cursor?

Install via PyPI (`pip install yandex-lavka-mcp`), then register with Claude Desktop by adding it to `mcpServers` in your config, or with Claude Code using `claude mcp add yandex-lavka`.

What authentication does it need?

You must provide your Yandex session cookies (from logging into Lavka in your browser) via a config file or environment variable. The server uses these to authenticate API calls on your behalf.

Is it safe to use?

The server is unofficial and not affiliated with Yandex; using it may violate Yandex's Terms of Service. It requires explicit confirmation before charging, and session cookies are stored locally. Use at your own risk.

Can I use it on my phone?

Yes, by deploying it remotely over HTTP with OAuth authentication and connecting it as a custom connector in claude.ai.

README (reference)

Source of truth, from the repository.

<!-- mcp-name: io.github.Dudude-bit/yandex-lavka-mcp -->

yandex-lavka-mcp

PyPI Python License: MIT MCP

An MCP server that lets an AI assistant order groceries from Yandex Lavka — search products, build a cart, and place a real order — with an explicit human confirmation before any money is charged.

[!WARNING] Unofficial. Yandex Lavka has no public API. This project talks to the same private web API that lavka.yandex.ru uses, authenticated with your own Yandex session cookies. It automates your own account, for your own shopping.

  • Not affiliated with or endorsed by Yandex. Using it may violate Yandex's Terms of Service, and the private API can change or be blocked at any time.
  • confirm_order spends real money on your card. Use at your own risk.
  • Provided as is, without warranty (see LICENSE).

What it does

ToolCharges?What it does
lavka_status—Is the session + location set up?
list_addresses—Your saved Lavka addresses, by name.
use_address—Switch delivery to a saved address by name.
set_delivery_address—Set delivery to any address by text (any city).
set_location—Set delivery point by raw lat/lon.
search_products—Search the catalog at the current location.
get_product—Product detail.
view_cart—Show cart + total.
add_to_cart—Add an item.
update_cart_item—Set exact quantity (0 removes).
clear_cart—Empty the cart.
checkout_previewnoFull summary: items, subtotal, discount, delivery, ETA, payment, total.
confirm_orderYESPlaces the order and charges the on-file card.
cancel_order—Cancel an order by id.
active_orders—Currently tracked orders with status/ETA.

Money safety. Placing an order is a deliberate two-step flow: checkout_preview returns the full summary and charges nothing; confirm_order(confirmed_total) refuses unless a preview was just run and you pass back the exact total it showed. Change the cart and the preview is invalidated — you must preview again.

3-D Secure. confirm_order submits the order and charges the on-file card, then polls payment status. If your bank requires 3-D Secure, payment_status comes back wait_user_action and a redirect_url is returned — open it to finish paying (a headless charge cannot complete 3DS). cancel_order(order_id) cancels.

Multiple locations / cities. Catalog, prices and cart are location-scoped. use_address("Дача") switches to a saved address; set_delivery_address("Казань, улица Баумана, 1", flat="12") works for any address in any city (it geocodes via Lavka's own address search).

How it's built

  • Python 3.12+ · FastMCP · httpx.
  • client.py — the async API client (session auth, CSRF, request building, trims huge payloads).
  • endpoints.py — every API path in one place (overridable from config, no code change).
  • server.py — the MCP tools the assistant sees.

The API sits under https://lavka.yandex.ru/api/v1/providers/* (plus /api/v1/orders/submit for placing orders). Requests need the CSRF token from the homepage HTML plus X-Lavka-Web-* headers — the client handles this.

Setup

1. Install

uv venv && uv pip install -e .

2. Provide your Yandex session (one time)

Log into Lavka in your browser first, then get the session cookies into ~/.config/yandex-lavka-mcp/config.json.

macOS — pull cookies straight from Chrome (one Keychain prompt → Allow):

uv pip install -e '.[browser]'
python scripts/extract_chrome_cookies.py          # auto-detects your profile

Any OS — paste the Cookie header from DevTools (Network → any lavka.yandex.ru request → Request Headers → Cookie):

python scripts/import_cookies.py --header "Session_id=...; yandexuid=...; L=..."

Session cookies expire — re-run when calls start returning "session expired".

3. Set a delivery location

Copy config.example.json to ~/.config/yandex-lavka-mcp/config.json and edit, or set it from the assistant with use_address / set_delivery_address. The catalog only works once a location is set. Smoke-test:

python scripts/smoke.py "молоко"

4. Register with your assistant

Claude Code:

claude mcp add yandex-lavka -- uv run --directory /path/to/yandex-lavka-mcp yandex-lavka-mcp

Claude Desktop (mcpServers):

{
  "yandex-lavka": {
    "command": "uv",
    "args": ["run", "--directory", "/path/to/yandex-lavka-mcp", "yandex-lavka-mcp"]
  }
}

Remote deploy (order from your phone)

By default the server speaks stdio (local clients). Set YANDEX_LAVKA_MCP_TRANSPORT=streamable-http to expose it over HTTP so a hosted instance can back a claude.ai custom connector (phone / web).

A prebuilt Dockerfile is included. Secrets are injected at runtime — never baked into the image:

docker build -t yandex-lavka-mcp .
docker run -p 8000:8000 \
  -e YANDEX_LAVKA_MCP_TRANSPORT=streamable-http \
  -e YANDEX_LAVKA_MCP_CONFIG_JSON="$(cat ~/.config/yandex-lavka-mcp/config.json)" \
  yandex-lavka-mcp

(The image defaults to stdio; the TRANSPORT env above switches it to HTTP.)

Environment variables

VarPurpose
YANDEX_LAVKA_MCP_TRANSPORTstdio (default) or streamable-http.
YANDEX_LAVKA_MCP_HOST / _PORTBind address for HTTP (default 0.0.0.0:8000 in Docker).
YANDEX_LAVKA_MCP_CONFIG_JSONThe whole config.json as one secret (instead of a file).

Authentication (any OIDC provider)

A public endpoint spends real money, so protect it. claude.ai's custom connector UI only supports OAuth (no static bearer / custom header — that works only in Claude Code/Desktop). This server is a provider-agnostic OAuth 2.1 resource server: point it at any OpenID-Connect provider (Zitadel, Keycloak, Auth0, Google, …) and it validates JWT access tokens against that provider's JWKS and advertises it via OAuth protected-resource metadata.

Enable it by installing the server extra (pip install '.[server]', already in the Docker image) and setting:

VarPurpose
YANDEX_LAVKA_MCP_OAUTH_ISSUERYour provider's issuer URL (enables OAuth).
YANDEX_LAVKA_MCP_SERVER_URLPublic URL of this MCP server (the resource).
YANDEX_LAVKA_MCP_OAUTH_AUDIENCEExpected token audience (optional but recommended).
YANDEX_LAVKA_MCP_OAUTH_SCOPESSpace-separated required scopes (optional).
YANDEX_LAVKA_MCP_OAUTH_SUBJECTSAllow-list of token subs that may call the server (optional; strongest lock — every request spends your Lavka session).
YANDEX_LAVKA_MCP_OAUTH_JWKS_URLOverride JWKS URL (optional; else discovered).

A network-exposed HTTP transport refuses to start unless OAuth is configured (it spends real money). Set YANDEX_LAVKA_MCP_ALLOW_INSECURE=1 only if you front it with your own auth. Leaving OAuth unset is allowed for loopback/local use.

Session cookies expire; when calls start failing, re-capture them and update the YANDEX_LAVKA_MCP_CONFIG_JSON secret. There is no headless Yandex login.

Develop

uv pip install -e ".[dev]"
pytest

One account = one cart

Lavka keeps a single server-side cart per account, guarded by an optimistic cartVersion. This server serializes its own cart writes and retries on version conflicts, so parallel tool calls in one session are safe. But don't drive the same Yandex account from two places at once (e.g. this server and a second MCP session, and the Lavka app): they all write the one shared cart, and you'll see items from the other writer appear in yours. Use a single client at a time.

Security & privacy

  • Cookies and address live only in ~/.config/yandex-lavka-mcp/config.json (chmod 600), git-ignored. Never commit them.
  • The server never adds payment methods or changes account settings.
  • Ordering always requires an explicit confirmed total.

License

MIT. Unofficial project, not affiliated with Yandex.

Related MCP servers

AI astronomy wiki with open agent peer-review. Vote on evidence, propose edits, earn reputation.

1
Python
MIT
View repository →

Secure local access to MQTT topics through MCP.

Self-hosted MCP gateway. Turn any REST API into MCP tools via YAML (DADL). Authz, audit, policies.

5
Go
Apache-2.0
View repository →

23-in-1 developer utility toolkit — search, exchange rates, crypto, QR codes, and more

0
JavaScript
View repository →

Smart hands for your AI agents - write-capable KVM+BMC+SSH MCP server: gated, verified, audited.

4
Python
Apache-2.0
View repository →

Local-first memory for AI chats: save context in one chat, load it in any other via MCP.

View repository →