Install
$ agentstack add mcp-stoa-hq-stoa ✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
Verified badge
Passed review? Show it. Paste this badge into your README, it links to the public security report.
Reliability & compatibility
Declared compatibility
Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.
We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.
How agent discovery & health will work →About
Stoa
[](https://stoahq.eu) [](https://buymeacoffee.com/stoahq) [](https://matrix.to/#/#stoa-dev:matrix.pineconeops.com)
A lightweight, open-source headless, agentic commerce platform built with Go. Ships as a single binary with the admin panel and storefront embedded.
Features
- Headless Architecture -- REST API (JSON)
- Single Binary -- Go backend with embedded SvelteKit frontends (Admin + Storefront)
- MCP Servers -- AI agents can shop in and manage the store via the Model Context Protocol
- Plugin System -- Extensible via hooks and custom API endpoints
- Multi-language -- Translation tables with locale-based API
- Property Groups & Variants -- Color, size, etc. with automatic combination generation
- Full-text Search -- PostgreSQL-based
- RBAC -- Role-based access control with granular API key permissions
Prerequisites
| Tool | Version | Purpose | |------|---------|---------| | Docker + Docker Compose | latest | Database (and optional app container) | | Go | 1.23+ | Build backend (local development only) | | Node.js | 20+ | Build frontends (local development only) | | PostgreSQL | 16+ | Database (provided via Docker) |
Quick Start
git clone https://github.com/stoa-hq/stoa.git && cd stoa
cp config.example.yaml config.yaml
docker compose up -d
docker compose exec stoa ./stoa migrate up
docker compose exec stoa ./stoa admin create --email admin@example.com --password your-password
| What | URL | |------|-----| | Storefront | http://localhost:8080 | | Admin Panel | http://localhost:8080/admin | | API | http://localhost:8080/api/v1/health |
Documentation
Full documentation is available in the StoA Docs:
- Introduction -- what Stoa is and why it exists
- Quick Start -- get up and running in minutes
- Configuration -- all config options explained
- API Overview -- authentication, endpoints, and usage
- MCP Servers -- AI agent integration
- Plugin System -- extend Stoa without forking
- Payment Integration -- integrate any PSP
License
Apache 2.0 -- see [LICENSE](LICENSE).
Source & license
This open-source MCP server is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: stoa-hq
- Source: stoa-hq/stoa
- License: Apache-2.0
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet, be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.