@safecart/mcp
v0.2.0
Published
MCP server for the SafeCart Public API — EU Safety Gate recall checks, recalls search, Product Safety Passports, store scans, and monitoring status.
Maintainers
Readme
@safecart/mcp
A Model Context Protocol server for the SafeCart Public API — let AI agents (Claude Desktop, Claude Code, any MCP client) check products against EU Safety Gate recalls, search recalls, manage Product Safety Passports, create recall campaign drafts, scan storefronts, and read monitoring status.
It is a thin client of the SafeCart v1 REST API (docs/api/openapi.yaml); it holds
no database access of its own.
Prerequisites
- Node.js ≥ 18.
- A SafeCart API key — create one in SafeCart → Account Settings → API Keys.
The key's scopes determine which tools work (e.g.
safety:readforcheck_product_safety).
Run
SAFECART_API_KEY=safecart_live_xxx npx @safecart/mcpEnvironment variables:
| Var | Required | Default | Notes |
| ----------------------- | -------- | --------------------- | -------------------------------------------- |
| SAFECART_API_KEY | yes | — | Your live or test API key. |
| SAFECART_API_BASE_URL | no | https://safecart.eu | Point at a preview/staging origin if needed. |
| SAFECART_TENANT_ID | no | — | Default portfolio UUID for tenant tools. |
Tenant keys are permanently pinned to one portfolio, so SAFECART_TENANT_ID is
optional for them. Organization keys must select a portfolio for Product Safety Passport and
monitoring tools, either with this environment variable or the tool's
tenant_id argument. Global Safety Gate search/check tools do not require a
portfolio.
Install in an MCP client
All clients use the same launch command; only the config location differs. Use
a safecart_test_... key while wiring things up, then swap in a live key.
Claude Desktop
Add to claude_desktop_config.json
(macOS: ~/Library/Application Support/Claude/claude_desktop_config.json,
Windows: %APPDATA%\Claude\claude_desktop_config.json):
{
"mcpServers": {
"safecart": {
"command": "npx",
"args": ["-y", "@safecart/mcp"],
"env": {
"SAFECART_API_KEY": "safecart_live_xxx"
}
}
}
}Restart Claude Desktop; the SafeCart tools appear in the tool picker.
Claude Code
claude mcp add safecart --env SAFECART_API_KEY=safecart_live_xxx -- npx -y @safecart/mcpCursor
Add to ~/.cursor/mcp.json (global) or .cursor/mcp.json (per project) using
the same mcpServers block as Claude Desktop above.
Any other MCP client
The server speaks MCP over stdio. Point your client at the command
npx -y @safecart/mcp with SAFECART_API_KEY in its environment.
Tools
| Tool | Endpoint | Scope |
| ------------------------- | ------------------------ | ----------------- |
| check_product_safety | POST /safety/check | safety:read |
| search_recalls | GET /recalls | recalls:read |
| list_product_passports | GET /passports | passports:read |
| create_product_passport | POST /passports | passports:write |
| scan_store | POST /scan | scan:run |
| get_monitoring_status | GET /monitoring/status | monitoring:read |
| create_recall_campaign | POST /recall-campaigns | recall:write |
create_recall_campaign is deliberately draft-only. It cannot activate a
campaign, publish a storefront banner, block sales, or send customer email. Pass
a stable idempotency_key so retrying the same operation returns the original
draft instead of creating a duplicate. A different body with the same key is
rejected.
Rate limits and monthly quotas apply per plan; a 429 surfaces as a tool error
with the Retry-After hint. A missing scope surfaces as a 403 tool error.
Development
npm install
npm test # node:test smoke tests (mocked fetch)License
MIT © SafeCart. The client is open source; the SafeCart API and service it talks to remain proprietary and require an API key.
