Install
$ agentstack add mcp-sgfgov-medusa-mcp ✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
Verified badge
Passed review? Show it. Paste this badge into your README, it links to the public security report.
Reliability & compatibility
Declared compatibility
Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.
We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.
How agent discovery & health will work →About
[](https://mseep.ai/app/sgfgov-medusa-mcp)
medusa-mcp
Overview
medusa-mcp is a Model Context Protocol (MCP) server designed for integration with the Medusa JavaScript SDK. It provides a scalable backend layer for managing and interacting with Medusa’s data models, enabling automation, orchestration, and intelligent service extensions.
🧩 What is an MCP Server?
An MCP server is a modular, extensible backend that:
- Enables real-time service orchestration
- Supports standardized, high-throughput communication
- Acts as a bridge between AI/automation tools and real-world systems
These servers are used in areas like AI, IoT, and enterprise software to connect various services and automate tasks using standardized protocols like JSON-RPC.
🔑 Key Features
- Modular Architecture – Composable services for flexibility
- High Efficiency – Optimized for speed and scale
- Extensible Design – Add new capabilities easily
- Cross-Environment Deployment – Cloud, on-prem, or hybrid
- AI-Ready Interfaces – Integrate LLMs and tools seamlessly
🧠 Role in AI Systems
MCP servers allow AI agents to:
- Access real-time data from APIs, files, or databases
- Automate business processes (e.g., order fulfillment, pricing updates)
- Interact with external services in a secure and controlled way
🚀 Medusa JS + MCP
Using medusa-mcp, Medusa JS can:
- Automate workflows (e.g., inventory or pricing adjustments)
- Connect with external tools (email, analytics, etc.)
- Use AI agents to analyze trends and trigger actions
- Enable scalable, modular architecture for commerce platforms
✨ Features
- ✅ Model Context Protocol (MCP) support
- 📈 Scalable infrastructure
- 🧱 Extensible plugin architecture
- 🔗 Integrated with Medusa JS SDK
🛠️ Installation
Clone the repository and install dependencies:
npm install
Build the project:
npm run build
▶️ Usage
Start the server:
npm start
Test using the MCP Inspector:
npx @modelcontextprotocol/inspector ./dist/index.js
> Note: Restart the Inspector and your browser after each rebuild.
🛠️ Generating a Claude Skill from this MCP server
You can convert this MCP server into a Claude Skill using the mcp-to-skill.py script from the mcp-to-skill-converter project, which is included in this repo as mcp-to-skill.py.
- Build the MCP server (so the command in the config works):
``bash npm run build ``
- Ensure Python and the
mcppackage are available:
``bash pip install mcp ``
- Generate a Skill for this server using the provided
mcp-to-skill.jsonconfig:
``bash python mcp-to-skill.py --mcp-config mcp-to-skill.json --output-dir ./skills/medusa-mcp ``
This will create:
SKILL.md– instructions for Claudeexecutor.py– MCP communication handlermcp-config.json– MCP server configurationpackage.json– minimal dependencies for the skill
- Install the Skill for Claude:
``bash cd skills/medusa-mcp pip install mcp cp -r . ~/.claude/skills/medusa-mcp ``
Claude will automatically discover the new Skill on next startup.
🌍 Environment Variables
| Variable | Description | |-----------------------|--------------------------------------| | MEDUSA_BACKEND_URL | Your Medusa backend URL | | PUBLISHABLE_KEY | Your Medusa publishable API key | | MEDUSA_USERNAME | Medusa admin username (for admin) | | MEDUSA_PASSWORD | Medusa admin password (for admin) |
Server runs at: http://localhost:3000
🧠 Architecture Diagram
Here's how the medusa-mcp server fits into a typical setup with Medusa JS and external systems:
+-------------------------+
| AI Assistant / |
| LLM / Automation |
+-----------+-------------+
|
v
+--------------+--------------+
| MCP Server (medusa-mcp) |
|-----------------------------|
| - JSON-RPC Communication |
| - AI-Ready Interface |
| - Plugin Support |
+------+----------------------+
|
+
|
v
+-------------------+
| Medusa Backend |
| (Products, Orders)|
+-------------------+
|
|
v
+--------------+
| Medusa Store |
| Frontend |
+--------------+
|
|
v
+-------------------------+
| External Services / API |
| (e.g., Payments, Email) |
+-------------------------+
🧪 Customization
To tailor the server to your Medusa setup:
> Replace admin.json and store.json with your own OAS definitions for fine-grained control.
- Replace the OpenAPI schemas in the
oas/folder: admin.json– Admin endpointsstore.json– Storefront endpoints
Use the @medusajs/medusa-oas-cli to regenerate these files.
You can also fork this project to build your own custom MCP-powered Medusa integration.
🤝 Contributing
We welcome contributions! Please see our [CONTRIBUTING.md](CONTRIBUTING.md) guide.
📄 License
This project is licensed under the MIT License. See the [LICENSE](LICENSE) file for details.
Source & license
This open-source MCP server is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: SGFGOV
- Source: SGFGOV/medusa-mcp
- License: MIT
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet, be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.