Install
$ agentstack add mcp-dlbolshov-yandex-wiki-search-mcp ✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ● Environment & secrets Used
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
Verified badge
Passed review? Show it. Paste this badge into your README, it links to the public security report.
Reliability & compatibility
Declared compatibility
Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.
We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.
How agent discovery & health will work →About
English | [Русский](README_ru.md)
Yandex Wiki Search MCP
[](https://glama.ai/mcp/servers/dlbolshov/yandex-wiki-search-mcp) [](https://pypi.org/project/yandex-wiki-search-mcp/) [](https://pypi.org/project/yandex-wiki-search-mcp/) [](https://github.com/dlbolshov/yandex-wiki-search-mcp/actions/workflows/test.yml) [](https://app.codecov.io/gh/dlbolshov/yandex-wiki-search-mcp) [](LICENSE) [](https://github.com/dlbolshov/yandex-wiki-search-mcp/pkgs/container/yandex-wiki-search-mcp)
Connect Claude, Cursor, Windsurf, or any MCP client to Yandex Wiki: full-text search, pages, comments, attachments, and dynamic tables ("grids") — 27 tools with typed schemas.
An unofficial project — not affiliated with or endorsed by Yandex.
- 🔍 Full-text search across the entire wiki — the same backend that powers the Wiki web search bar, up to 50 results per query
- 📄 Full page lifecycle — create, update, append (top / bottom / anchor), clone, delete with a recovery token, comments, file uploads
- 📊 Dynamic tables (grids) — 11 write tools: rows, columns, cells, copy, sort
- 🔒 Server-side read-only mode —
WIKI_READ_ONLY=truesimply doesn't register write tools, so the agent can't bypass it - 🧩 Typed tool surface — every tool ships input and output JSON schemas plus safety annotations (read-only / destructive / idempotent hints)
- 🐳 Runs anywhere — stdio for desktop clients, streamable-http + Docker (with optional multi-user OAuth) for teams
Quick start
- Get a Yandex OAuth token with Wiki access (official guide) and your organization ID.
- Install into your client:
[](https://cursor.com/install-mcp?name=yandex-wiki-search&config=eyJjb21tYW5kIjoidXZ4IiwiYXJncyI6WyJ5YW5kZXgtd2lraS1zZWFyY2gtbWNwIl0sImVudiI6eyJXSUtJX1RPS0VOIjoiWU9VUl9UT0tFTiIsIldJS0lfT1JHX0lEIjoiWU9VUl9PUkdfSUQiLCJXSUtJX1JFQURfT05MWSI6InRydWUifX0=) [](https://insiders.vscode.dev/redirect/mcp/install?name=yandex-wiki-search&config=%7B%22name%22%3A%22yandex-wiki-search%22%2C%22command%22%3A%22uvx%22%2C%22args%22%3A%5B%22yandex-wiki-search-mcp%22%5D%2C%22env%22%3A%7B%22WIKITOKEN%22%3A%22YOURTOKEN%22%2C%22WIKIORGID%22%3A%22YOURORGID%22%2C%22WIKIREADONLY%22%3A%22true%22%7D%7D)
Claude Desktop / Windsurf / any JSON-config client (uvx)
{
"mcpServers": {
"yandex-wiki-search": {
"command": "uvx",
"args": ["yandex-wiki-search-mcp"],
"env": {
"WIKI_TOKEN": "YOUR_TOKEN",
"WIKI_ORG_ID": "YOUR_ORG_ID",
"WIKI_READ_ONLY": "true"
}
}
}
}
Claude Code (CLI)
claude mcp add yandex-wiki-search \
-e WIKI_TOKEN=YOUR_TOKEN -e WIKI_ORG_ID=YOUR_ORG_ID -e WIKI_READ_ONLY=true \
-- uvx yandex-wiki-search-mcp
Docker (no Python required)
{
"mcpServers": {
"yandex-wiki-search": {
"command": "docker",
"args": ["run","--rm","-i",
"-e","WIKI_TOKEN","-e","WIKI_ORG_ID","-e","WIKI_READ_ONLY=true",
"ghcr.io/dlbolshov/yandex-wiki-search-mcp:latest"],
"env": {"WIKI_TOKEN":"YOUR_TOKEN","WIKI_ORG_ID":"YOUR_ORG_ID"}
}
}
}
> [!TIP] > Start with WIKI_READ_ONLY=true — the server won't even register write tools. > Flip it to false once you trust your agent with edits.
- Ask your agent something — see below.
Need the old MCP SDK (1.x)?
The server runs on MCP Python SDK v2. That is invisible to clients — one v2 server answers every protocol revision back to 2024-11-05 as well as the current one, so there is nothing to change on your side and nothing to reinstall.
The only reason to hold back is a shared environment that pins `mcp
What can it do
> "Find our onboarding docs and summarize the key steps." > > "What do we have on incident response? Open the most relevant page." > > "Create a page team/weekly-notes and append today's standup summary." > > "Add a row to the on-call rotation grid: alice, next week." > > "Upload this PDF to the project page and link it at the bottom." > > "Delete the draft page, but keep the recovery token in case I change my mind."
Tools
27 tools. All write tools disappear when WIKI_READ_ONLY=true.
Search & read (8)
| Tool | What it does | |---|---| | page_search | Full-text search across the entire Wiki (pages and files), up to 50 ranked results with a text excerpt each | | page_get | Get a page by page_id or slug (accepts full Wiki URLs too) | | page_get_descendants | Traverse a page subtree — one flat list of {id, slug} from all nesting levels; from_root=true walks the whole Wiki; fetch_all drains the cursor in one call | | page_get_comments | List page comments (fetch_all supported) | | page_get_resources | List page resources (attachments + grids) with server-side title search (fetch_all supported) | | page_get_attachments | List page attachments (fetch_all supported) | | page_get_grids | List grids attached to a page (fetch_all supported) | | grid_get | Get a grid by grid_id with row/column/revision filters |
Pages: write (8)
| Tool | What it does | |---|---| | page_create | Create a page | | page_update | Update page title and/or full content | | page_append_content | Append content to top, bottom, or a named anchor | | page_clone | Copy a page to a new slug — the copy gets a new id; children, comments, and history stay with the original; occupied slugs are refused. The API has no true move/rename ([details](docs/api-notes.md#pages)) | | page_add_comment | Add a comment or reply in a thread | | page_delete | Delete a page and receive a recovery token | | page_recover | Recover a deleted page by recovery token | | page_upload_attachment | Upload a local file in chunks and attach it to a page — not registered under OAUTH_ENABLED=true, where "local" would mean the shared server's filesystem |
Grids: write (11)
Expand the table
| Tool | What it does | |---|---| | grid_create | Create a grid on a page | | grid_update | Update grid title and/or default sort | | grid_copy | Copy a grid to an existing target page (async operation) | | grid_delete | Delete a grid | | grid_add_rows | Add rows at a position or after a given row | | grid_update_cells | Update individual cells by row + column | | grid_delete_rows | Delete rows | | grid_move_row | Move a row | | grid_add_columns | Add typed columns | | grid_delete_columns | Delete columns by slug | | grid_move_column | Move a column |
Grid specifics:
- Mutations use optimistic locking — fetch the grid first and pass the latest
revision. grid_update.default_sorttakes[{"column": "status", "direction": "asc"}]entries; the server converts them to the wire format the API expects.grid_add_columnsrequiresrequiredon every column because the real API validates it.grid_copyreturns operation metadata, not a ready copied grid object.
How it compares
Facts verified against the alternatives' docs and published code, July–August 2026; the official hosted server's tool list captured live from mcp.wiki.yandex.net (wiki-mcp-server 1.28.1, 2026-08-11).
| | yandex-wiki-search-mcp | Yandex's official MCP (hosted) | ya-yandex-wiki-mcp | slartus/mcp-yandex-wiki | ya-wiki-mcp | |---|---|---|---|---|---| | Full-text search | ✅ up to 50 results, client-side filters | ❌ no search tool | ❌ | ✅ up to 10 results | ❌ | | Pages: create / update / append / delete + recover | ✅ all | partial — no append / recover; adds partial edits via text replacement | ✅ all | partial — no append / recover | partial — no recover | | Pages: clone to a new slug | ✅ page_clone | ❌ | ❌ | ❌ | ✅ | | Grids: write tools | ✅ 11 | ✅ 12, incl. column update + row pin/color | ✅ 11 | ❌ read-only | ✅ 11, incl. clone | | Comments, attachment upload | ✅ | comments ✅ / upload ❌ (download + preview instead) | ✅ | ❌ | ❌ | | Server-side read-only mode | ✅ | ❌ | ✅ | ❌ | ❌ | | Typed output schemas + tool annotations | ✅ | ❌ | ❌ | ❌ | ❌ tools return plain strings | | YFM helpers | ✅ syntax cheat sheet resource + yfm_warnings in write tools | ❌ | ❌ | ❌ | ✅ Markdown→YFM converter + page-tree cache, prompt templates | | Docker / PyPI / MCP Registry | ✅ / ✅ / ✅ | — hosted service, closed source, nothing to install | ✅ / ✅ / ✅ | ❌ manual install | PyPI only; no source repo linked | | Multi-user OAuth for HTTP deployments | ✅ | ❌ per-user token pasted into static headers, no OAuth flow | ✅ | ❌ | ❌ |
Also worth knowing:
- best-doctor/mcp-yandex-wiki (Python) — page create / update plus reads, with a separate
-roread-only entry point; no delete / recover, no grids, no search; PyPI only - brekhov-ilya/yandex-wiki-mcp (npm) — pages read / write / move, grids read-only; interactive PKCE token flow with auto-refresh, no full-text search
- n-r-w/yandex-mcp (Go) — Yandex Tracker + Wiki in one server, read-only by design (5 wiki read tools), no search; auth via IAM tokens from the
ycCLI only — Yandex OAuth tokens are not supported
As of August 2026, full-text search exists only here (up to 50 results) and in slartus (up to 10) — Yandex's own hosted server ships without a search tool — and the combination of search, grid writes, server-side read-only mode, and typed schemas is unique to this project.
This project is a fork of ya-yandex-wiki-mcp and builds on findings from slartus/mcp-yandex-wiki — see [Credits](#credits).
Full-text search
page_search wraps the POST /v1/search endpoint — the same backend that powers the Wiki web search bar, undocumented until Yandex published its API reference in August 2026. Search first, then open a result with page_get by its slug.
- Up to 50 results per call (
limitis clamped to 1–50; the API rejects anything else). - Search is global only for now —
slug_prefixandresult_typefilters are applied client-side after fetching, so combine them withlimit=50to avoid missing matches (the API's new server-side filters are on the [roadmap](ROADMAP.md)). - Quoted
"exact phrase"queries work;pageresults get absolutehttps://wiki.yandex.ru/...links,fileresults get direct download links. contentis a ~510-character excerpt, not the page and not a summary: it is cut from wherever the match sits, nothing is highlighted, the query terms need not be inside it, and its line breaks and tabs are the page's own layout (table cells arrive tab-separated) rather than separators between fragments. Read the page withpage_getbefore answering from it. Empty forfileresults.
Traversing the tree
page_get_descendants returns a subtree as one flat list of {id, slug} from every nesting level. Passing from_root=true instead of page_id/slug walks the whole Wiki — the way in when no starting slug is known, so search is not the only entry point. Prefer a section slug when you have one: wikis run to thousands of pages, and fetch_all stops at its ~500-item cap with truncated: true.
More verified API behavior (scopes, 403 semantics, error envelopes, limits): [docs/api-notes.md](docs/api-notes.md).
Configuration
| Variable | Required | Default | Description | |---|---|---|---| | WIKI_TOKEN | one of the two | — | Yandex OAuth token (takes precedence when both are set) | | WIKI_IAM_TOKEN | | — | IAM token (Yandex Cloud organizations) | | WIKI_ORG_ID | exactly one of the two | — | Yandex 360 organization ID (X-Org-Id) | | WIKI_CLOUD_ORG_ID | | — | Yandex Cloud organization ID (X-Cloud-Org-Id) | | WIKI_READ_ONLY | no | false | true disables all write tools server-side | | TRANSPORT | no | stdio | stdio \| sse \| streamable-http | | HOST / PORT | no | 0.0.0.0 / 8000 | HTTP transports only | | STATELESS_HTTP / JSON_RESPONSE | no | true / true | streamable-http only: keep no per-session state / answer with JSON instead of SSE | | LOG_LEVEL | no | INFO | Logs go to stderr; DEBUG additionally logs Wiki API requests (method, path, status, duration — never headers or bodies) | | WIKI_API_BASE_URL | no | https://api.wiki.yandex.net | Wiki API endpoint | | WIKI_WEB_BASE_URL | no | https://wiki.yandex.ru | Base for absolute page links in page_search results | | WIKI_AUTH_SCHEME | no | OAuth | Authorization header scheme for WIKI_TOKEN (OAuth \| Bearer) | | WIKI_MAX_RETRIES | no | 2 | Retries for dropped connections and 429/502/503/504 on read requests; 0 disables them | | TOOL_RESULT_TEXT | no | pretty | Text duplicate of structured tool results: pretty (indent=2) \| compact (single line, 10-30% off the text block) \| none (structured only — check your client renders structuredContent first) |
Multi-user OAuth + Redis (HTTP deployments only)
With OAUTH_ENABLED=true the server becomes an OAuth provider: each MCP user authorizes with their own Yandex account, and requests to the Wiki API are made with their personal token. page_upload_attachment is not registered in this mode: it reads files from the machine the server runs on, which is not the caller's machine in a shared deployment.
| Variable | Default | Description | |---|---|---| | OAUTH_ENABLED | false | Enable the OAuth provider | | OAUTH_STORE | memory | memory \| redis | | OAUTH_SERVER_URL | https://oauth.yandex.ru | Yandex OAuth server | | OAUTH_USE_SCOPES | true | Request Wiki scopes during authorization | | OAUTH_CLIENT_ID / OAUTH_CLIENT_SECRET | — | Your Yandex OAuth app credentials | | OAUTH_CLIENT_SECRET_EXPIRY_SECONDS | 2592000 (30 days) | Lifetime of a dynamically registered MCP client. Registration is unauthenticated by protocol design, so without an expiry every registration is kept forever; clients are told the deadline at registration and re-register when it passes. Empty disables it | | MCP_SERVER_PUBLIC_URL | — | Public URL of this server (OAuth callbacks) | | OAUTH_ENCRYPTION_KEYS | — | Comma-separated base64 32-byte keys (required for redis store) | | REDIS_ENDPOINT / REDIS_PORT / REDIS_DB / REDIS_PASSWORD / REDIS_POOL_MAX_SIZE | localhost / 6379 / 0 / — / 10 | Redis connection |
Choosing the organization per user. WIKI_ORG_ID / WIKI_CLOUD_ORG_ID are optional under OAuth, because each request can name its own organization: append ?orgId=... (or ?cloudOrgId=...) to the MCP server URL your client connects to. A query parameter wins over the server-wide setting, so one deployment can serve several organizations. If a request carries neither, the tool call fails with a message pointing at both options — set the environment variable as the default if all your users share one organization.
See [.env.example](.env.example) for the full annotated list and [compose.yaml](compose.yaml) for a Redis baseline.
Deployment
flowchart LR
C["MCP client<br/>Claude / Cursor / Windsurf / VS Code"]
S["yandex-wiki-search-mcp"]
W["Yandex Wiki API"]
R[("Redis<br/>optional OAuth token store")]
C -- "stdio (local, single user)" --> S
C -- "streamable-http (+ OAuth, multi-user)" --> S
S --> W
S -.-> R
HTTP server via Docker (the MCP endpoint is http://localhost:8000/mcp):
docker run --env-file .env -e TRANSPORT=streamable-http -p 8000:8000 \
--log-opt max-size=10m --log-opt max-file=3 \
ghcr.io/dlbolshov/yandex-wiki-search-mcp:latest
> [!NOTE] > The server writes no log files of its own — everything goes to stderr, which > Docker's default json-file driver stores without a size limit. The > --log-opt fl
…
Source & license
This open-source MCP server is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: dlbolshov
- Source: dlbolshov/yandex-wiki-search-mcp
- License: Apache-2.0
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet, be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.