npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

myhotlunchbox-mcp

v0.3.0

Published

My Hot Lunchbox MCP server for Claude — developed and maintained by AI (Claude Code)

Downloads

1,025

Readme

myhotlunchbox-mcp

MCP server for My Hot Lunchbox — read the school lunch calendar, manage students, place and change orders, and track deliveries and payments on a parent account.

Developed and maintained by AI (Claude Code). Use at your own discretion.

Install

npx myhotlunchbox-mcp

Or as a Claude Code plugin:

/plugin marketplace add chrischall/myhotlunchbox-mcp
/plugin install myhotlunchbox-mcp

Configure

[email protected]
MYHOTLUNCHBOX_PASSWORD=…

That is the whole setup. The server performs a real server-side sign-in against ordernow.myhotlunchbox.com (OAuth2 password grant) and renews the session with the refresh token it receives — no browser extension, no signed-in tab, no captured cookie. Nothing is written to disk.

MYHOTLUNCHBOX_BASE_URL overrides the app origin if it ever moves.

The server boots without credentials so a host's install-time tools/list probe still works; the configuration error surfaces on the first tool call.

Tools

34 tools, all prefixed mhlb_. All 20 read tools are verified live against a real parent account (node scripts/verify-reads.mjs); the 14 write tools are not — see below.

Accountmhlb_whoami, mhlb_session_reset

Studentsmhlb_list_students, mhlb_get_student_form, mhlb_new_student_form, mhlb_create_student, mhlb_update_student, mhlb_delete_student

Calendarmhlb_get_calendar, mhlb_get_day

Orderingmhlb_get_cart, mhlb_get_cart_tabs, mhlb_get_menu, mhlb_get_order_form, mhlb_get_order, mhlb_create_order, mhlb_update_order, mhlb_delete_order

Billingmhlb_list_transactions, mhlb_get_transaction, mhlb_list_subscriptions, mhlb_get_subscription_settings, mhlb_set_subscription_enabled, mhlb_unsubscribe_order, mhlb_list_gift_cards, mhlb_apply_gift_card, mhlb_get_coupon, mhlb_apply_coupon, mhlb_remove_coupon

Checkoutmhlb_init_checkout, mhlb_checkout

Reportsmhlb_print_calendar, mhlb_print_orders, mhlb_print_transaction. These return real PDFs; each writes the file and returns its path, or the bytes inline with inline: true. Set MYHOTLUNCHBOX_OUTPUT_DIR to choose where they land (defaults to the working directory); existing files are never overwritten.

Writes are confirm-gated

Every mutating tool takes confirm. Without confirm: true it makes no network call and returns a dry-run preview of exactly what it would send.

mhlb_checkout charges a real payment method. The server prices the charge from orderIds, so nothing client-side can bind the amount — there is no total in the request to check against. expectedTotal is therefore attribution, not a guard: you state what you expected, and it is recorded in the dry run and in the result so an unexpected charge is traceable to the call that made it. What the tool does refuse outright is paying a non-zero total with no orderIds.

Writes: shapes captured, acceptance unverified

npm run capture:writes runs every mutating tool against a local proxy that forwards reads to the real service but answers writes itself, so the payloads are built from genuine server models and nothing happens upstream. It also proves all 13 refuse to send anything without confirm: true.

What that established, and corrected: mhlb_delete_order and mhlb_unsubscribe_order take {orderId, eventDate, studentId, isRepeated, isSubscribed} — not the order model — and checkout takes {orderIds, checkoutType, couponCode, giftCardCode, schoolDonations}.

What is still unverified is whether the server accepts these bodies. Shape is not acceptance; only a real write shows that, and none has been made. Inspect the dry-run preview before confirming, and re-read afterwards — a 200 is not proof a write persisted.

Two limits on mhlb_checkout specifically:

  • It can only pay with a card already saved on the account. Paying with a new card needs a Stripe token minted by Stripe.js in a browser, which no server-side client can produce.
  • It generates an idempotency key and returns it. If a checkout fails ambiguously, retry with that same idempotencyKey rather than a fresh call — that is what stops a retry becoming a second charge.

Ordering is read-modify-write

There is no "add item X" call. Fetch the model, edit it, send it back whole:

  1. mhlb_get_menu — what is orderable for a student on a date
  2. mhlb_get_order_form — the order model to fill in
  3. mhlb_create_order — send it back (with confirm: true)
  4. mhlb_init_checkoutmhlb_checkout — price, then pay

Fields omitted from the payload are cleared, not preserved.

Shell skill

skills/myhotlunchbox covers the same account from a shell with curl — no MCP process needed. Useful in scripts, or on a machine where this server is not installed.

Notes

  • /deliveryInfo/* and /calendar/viewMatchedVendors look parent-facing in the compiled client but return 403 for a parent account — they belong to the school/vendor dashboards. No tool wraps them.
  • Only the parent role is wired. The same API also serves school-admin and vendor roles; those endpoints return 403, which the client reports as a role mismatch rather than a broken session.
  • docs/MYHOTLUNCHBOX-API.md records how the API was mapped and exactly what is verified. docs/api-surface.txt is the full 359-endpoint extraction.

Licence

MIT