Yandex Audience MCP
NPM · MCP-YANDEX-AUDIENCE · SCANNED OCT 3
MCP server for Yandex Audience API: segments (CRM, lookalike, pixel), pixels, grants.
Available components
How this component scores in each security and reliability category. Every signal is checked automatically from public evidence about the published package, including repeated runs of it in an isolated sandbox, and we only credit what we can confirm. How we score → Why this is hard to score →
Supply Chain Security98
- No malware found by supply-chain analysis.Pass
- No known CVEs affecting this package version or its production dependencies.Pass
- No install/post-install scripts declared.Pass
- 31 of 93 dependencies flagged as unhealthy. View diagnostics → Partial
Provenance & Transparency45
- Source repository is publicly reachable at the declared URL. View diagnostics → Pass
- Provenance check failed: no build-provenance attestation is published. See how to fix → View diagnostics → Fail
- Clear OSI-approved license (MIT).Pass
- Actively maintained (last published 45 days ago).Pass
- Disclosure check failed: no security disclosure policy was found in the source repository. See how to fix → Fail
Schema Quality & AI Usability71
- AI-judged instruction clarity (excellent).Pass
- Context-footprint check failed: tool/resource definitions use about 3753 tokens (~187/item across 20 items; 20 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management83
- Stability observed for 25 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage100
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 100% of tool parameters carry a description.Pass
Tool Safety100
- No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
- All 3 tool(s) whose name or description implies an irreversible operation declare an MCP destructiveHint annotation.Pass
- An AI judge read all 21 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
- Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
How do I install the Yandex Audience MCP server?
Yandex Audience MCP runs locally as an npm package, launched with npx -y mcp-yandex-audience. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.
npm · mcp-yandex-audience
claude mcp add a1-x-tech-mcp-yandex-audience -- npx -y mcp-yandex-audience
{
"mcpServers": {
"a1-x-tech-mcp-yandex-audience": {
"command": "npx",
"args": [
"-y",
"mcp-yandex-audience"
]
}
}
} {
"servers": {
"a1-x-tech-mcp-yandex-audience": {
"command": "npx",
"args": [
"-y",
"mcp-yandex-audience"
]
}
}
} codex mcp add a1-x-tech-mcp-yandex-audience -- npx -y mcp-yandex-audience
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"a1-x-tech-mcp-yandex-audience": {
"type": "local",
"command": [
"npx",
"-y",
"mcp-yandex-audience"
],
"enabled": true
}
}
} openclaw mcp add a1-x-tech-mcp-yandex-audience --command npx --arg -y --arg mcp-yandex-audience
mcp_servers:
a1-x-tech-mcp-yandex-audience:
command: "npx"
args: ["-y", "mcp-yandex-audience"] {
"McpServers": {
"a1-x-tech-mcp-yandex-audience": {
"Transport": "stdio",
"Command": "npx",
"Arguments": [
"-y",
"mcp-yandex-audience"
]
}
}
} assistant mcp add a1-x-tech-mcp-yandex-audience -t stdio -c npx -a -y mcp-yandex-audience
{
"mcpServers": {
"a1-x-tech-mcp-yandex-audience": {
"command": "npx",
"args": [
"-y",
"mcp-yandex-audience"
]
}
}
} Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 3 Oct 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 80 to 83. That category is still filling its 30-day observation window: 24 days of observed history at the previous scan, 25 at this one. The score rises as the window fills, whether or not the server changes.
- 2 Oct 26 −3
- Stability: pass → 0.80 functional
- 1 Oct 26 0
- Stability: 0.97 → pass security
- 30 Sept 26 +1
No change was recorded against any check on this day. Stability & Change Management went from 93 to 97. That category is still filling its 30-day observation window: 28 days of observed history at the previous scan, 29 at this one. The score rises as the window fills, whether or not the server changes.
- 28 Sept 26 +1
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 26 Sept 26 +1
- Package version: 1.0.0 → 1.1.1 functional
- 25 Sept 26 −3
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 24 Sept 26 0
- Stability: 0.97 → pass security
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 3 Oct 2026 · Analysed npm/mcp-yandex-audience@1.1.1
Provenance No attestation
The registry publishes no build provenance for this version, so there is nothing to verify.
| Result | No attestation |
|---|---|
| Ecosystem | npm |
Background: How many MCP packages publish verified provenance →
Dependencies 93 packages
| Packages resolved | 93 |
|---|---|
| Stale | 31 |
| Tree resolution | Complete |
Background: SBOMs and build attestations, explained →
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
add_segment_grant Выдать доступ к сегменту ~152
Создаёт разрешение на управление сегментом для указанного логина Яндекса. permission: edit — редактирование и использование сегмента, view — только просмотр/использование. Ответ — {"grant": {...}} (поле created_at заполняет сервер).
| Name | Type | Req | Description |
|---|---|---|---|
| comment | string | – | Комментарий к разрешению (до 255 символов). |
| permission | string | yes | Уровень доступа: edit (изменение) | view (просмотр). |
| segment_id | integer | yes | Идентификатор сегмента (id из list_segments или из ответа создания). |
| user_login | string | yes | Логин пользователя Яндекса, которому выдаётся доступ. |
No output schema declared.
No examples provided.
auth_status Статус подключения к Аудиториям ~105
Показывает, подключены ли Яндекс Аудитории: есть ли токен, откуда он взят (переменная окружения YANDEX_AUDIENCE_TOKEN или сохранённый вход), когда истекает и где лежит файл с сохранёнными данными. Ничего не отправляет в сеть и не показывает сам токен. Вызовите это, если инструменты Аудиторий отвечают, что подключение не настроено.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
confirm_segment Сохранить загруженный сегмент ~342
Сохраняет сегмент, созданный из файла (второй шаг после upload_segment_file / upload_segment_csv_file): задаёт имя, тип содержимого и параметры хеширования. content_type: idfa_gaid (идентификаторы мобильных устройств), mac (MAC-адреса) или crm (CSV с CRM-данными). hashing_alg — только SHA256 (MD5 не поддерживается API с 01.01.2025). device_matching_type: CROSS_DEVICE (по умолчанию) или IN_DEVICE (только для idfa_gaid). check_size=false позволяет сохранить сегмент меньше 100 записей (его нельзя использовать в Директе, пока размер не превысит 100). Ответ — {"segment": {...}}; обработка занимает время, статус смотрите через list_segments.
| Name | Type | Req | Description |
|---|---|---|---|
| check_size | boolean | – | false — разрешить сохранение сегмента меньше 100 записей (по умолчанию true). |
| content_type | string | yes | Тип содержимого файла: idfa_gaid | mac | crm. |
| device_matching_type | string | – | Режим сопоставления устройств: CROSS_DEVICE (по умолчанию) | IN_DEVICE (только для idfa_gaid). |
| hashed | boolean | – | Захешированы ли данные в файле. |
| hashing_alg | string | – | Алгоритм хеширования — только SHA256 (MD5 не поддерживается с 01.01.2025). |
| name | string | yes | Название сегмента. |
| segment_id | integer | yes | Идентификатор сегмента (id из list_segments или из ответа создания). |
No output schema declared.
No examples provided.
create_lookalike_segment Создать lookalike-сегмент ~291
Создаёт сегмент типа lookalike — пользователи, «похожие» по поведению в интернете на аудиторию исходного сегмента (lookalike_link). lookalike_value — степень похожести от 1 (максимальная точность, меньший охват) до 5 (максимальный охват). maintain_device_distribution / maintain_geo_distribution (по умолчанию true) сохраняют распределение по типам устройств и городам исходного сегмента. Ответ — {"segment": {...}}; сегмент обрабатывается асинхронно, статус смотрите через list_segments. Квота: 10/мин, 100/час, 500/сутки.
| Name | Type | Req | Description |
|---|---|---|---|
| lookalike_link | integer | yes | Идентификатор исходного сегмента, на который будут «похожи» пользователи. |
| lookalike_value | integer | yes | Степень «похожести»: 1 (точнее, уже) .. 5 (шире охват). |
| maintain_device_distribution | boolean | – | Сохранять распределение по типам у��тройств исходного сегмента (по умолчанию true). |
| maintain_geo_distribution | boolean | – | Сохранять распределение по городам исходного сегмента (по умолчанию true). |
| name | string | yes | Название сегмента. |
No output schema declared.
No examples provided.
create_pixel Создать пиксель ~86
Создаёт пиксель Яндекс Аудиторий с заданным именем. В ответе — {"pixel": {...}} с полем url: код пикселя, который нужно вставить в рекламные материалы (баннеры), после чего на его основе можно строить сегменты инструментом create_pixel_segment.
| Name | Type | Req | Description |
|---|---|---|---|
| name | string | yes | Название пикселя. |
No output schema declared.
No examples provided.
create_pixel_segment Создать сегмент на основе пикселя ~403
Создаёт сегмент типа pixel — пользователи, которых пиксель (pixel_id из list_pixels) видел за последние period_length дней (1..90). Дополнительные условия объединяются по «И»: частота показов (times_quantity + times_quantity_operation: lt | eq | gt) и фильтры по UTM-меткам (utm_source, utm_medium, utm_campaign, utm_content, utm_term). device_matching_type присутствует в примере запроса API, но не описан в документации — считайте экспериментальным. Ответ — {"segment": {...}}. Квота: 10/мин, 100/час, 500/сутки.
| Name | Type | Req | Description |
|---|---|---|---|
| device_matching_type | string | – | Режим сопоставления устройств (недокументирован для pixel-сегментов, экспериментально). |
| name | string | yes | Название сегмента. |
| period_length | integer | – | Период в сутках (1..90), за который пользователь был замечен пикселем. |
| pixel_id | integer | yes | Идентификатор пикселя (id из list_pixels), на основе которого строится сегмент. |
| times_quantity | integer | – | Пороговое количество срабатываний пикселя (используется вместе с times_quantity_operation). |
| times_quantity_operation | string | – | Условие по частоте: lt (меньше), eq (равно), gt (больше) относительно times_quantity. |
| utm_campaign | string | – | Фильтр по метке utm_campaign. |
| utm_content | string | – | Фильтр по метке utm_content. |
| utm_medium | string | – | Фильтр по метке utm_medium. |
| utm_source | string | – | Фильтр по метке utm_source. |
| utm_term | string | – | Фильтр по метке utm_term. |
No output schema declared.
No examples provided.
delete_pixel Удалить пиксель ~90
Удаляет указанный пиксель Яндекс Аудиторий. Успешный ответ — {"success": true}. В API существует метод восстановления удалённого пикселя (POST /v1/management/pixel/{id}/undelete) — при необходимости он доступен через raw_request.
| Name | Type | Req | Description |
|---|---|---|---|
| pixel_id | integer | yes | Идентификатор пикселя (id из list_pixels). |
No output schema declared.
No examples provided.
delete_segment Удалить сегмент ~72
Удаляет указанный сегмент Яндекс Аудиторий. Операция необратима (метода восстановления сегмента в API нет). Успешный ответ — {"success": true}.
| Name | Type | Req | Description |
|---|---|---|---|
| segment_id | integer | yes | Идентификатор сегмента (id из list_segments или из ответа создания). |
No output schema declared.
No examples provided.
delete_segment_grant Отозвать доступ к сегменту ~78
Удаляет разрешение на управление сегментом у указанного пользователя. Успешный ответ — {"success": true}.
| Name | Type | Req | Description |
|---|---|---|---|
| segment_id | integer | yes | Идентификатор сегмента (id из list_segments или из ответа создания). |
| user_login | string | yes | Логин пользователя, у которого отзывается доступ. |
No output schema declared.
No examples provided.
finish_login Завершить подключение Аудиторий ~125
Второй шаг подключения: обменивает код подтверждения из start_login на токен доступа, сохраняет его в файл только для владельца (0600) и сразу проверяет живым запросом к Аудиториям. После успеха остальные инструменты работают немедленно — перезапускать клиент не нужно. Код одноразовый и живёт 10 минут: если он не принят, вызовите start_login заново и попросите свежий.
| Name | Type | Req | Description |
|---|---|---|---|
| code | string | yes | Код подтверждения, который Яндекс показал пользователю после входа. |
No output schema declared.
No examples provided.
list_pixels Список пикселей ~102
Возвращает список пикселей Яндекс Аудиторий пользователя. Ответ — {"pixels": [...]}: у каждого пикселя id, name, create_time, url (код пикселя для вставки в рекламные материалы), охваты user_quantity_7 / user_quantity_30 / user_quantity_90 (уникальные пользователи за 7/30/90 дней) и segments — сегменты, построенные на этом пикселе.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
list_segment_grants Список доступов к сегменту ~82
Возвращает список разрешений на управление сегментом. Ответ — {"grants": [...]}: у каждого разрешения user_login (логин пользователя), permission (edit — редактирование, view — просмотр), comment и created_at.
| Name | Type | Req | Description |
|---|---|---|---|
| segment_id | integer | yes | Идентификатор сегмента (id из list_segments или из ответа создания). |
No output schema declared.
No examples provided.
list_segments Список сегментов ~247
Возвращает список сегментов Яндекс Аудиторий, доступных пользователю (все типы: uploading, metrika, appmetrica, lookalike, geo, pixel). Ответ — {"segments": [...]}: у каждого сегмента id, name, type, status (uploaded | is_processed | processed | processing_failed | is_updated | few_data), create_time, owner и типоспецифичные поля (у файловых — content_type, hashed, item_quantity, matched_quantity и др.). Пагинация: limit (по умолчанию 10000) и offset; параметр pixel фильтрует по сегментам, созданным на основе указанного пикселя. Отдельного метода получения одного сегмента в API нет — фильтруйте этот список по id.
| Name | Type | Req | Description |
|---|---|---|---|
| limit | integer | – | Сколько сегментов вернуть (по умолчанию 10000). |
| offset | integer | – | Порядковый номер сегмента, с которого начать выдачу (первый — 0). |
| pixel | integer | – | Идентификатор пикселя: вернуть только сегменты, созданные на его основе. |
No output schema declared.
No examples provided.
logout Отключить Аудитории ~87
Удаляет сохранённый токен Аудиторий с диска. Токен, заданный переменной окружения YANDEX_AUDIENCE_TOKEN, не трогает — его нужно убирать из конфигурации клиента вручную. Доступ, выданный приложению, остаётся активным на стороне Яндекса: отозвать его можно в Яндекс ID.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
raw_request Произвольный запрос к API Аудиторий ~205
Escape hatch: прямой вызов любого пути Yandex Audience API, для эндпоинтов без выделенного инструмента (например, PUT "v1/management/segment/{id}/reprocess" — пересчёт сегмента, или POST "v1/management/pixel/{id}/undelete" — восстановление пикселя). Путь указывается относительно хоста API; query-параметры включайте прямо в path (например, "v1/management/segments?limit=5"). body отправляется как JSON для POST/PUT. Заголовок Authorization подставляется автоматически; путь на чужой хост будет отклонён.
| Name | Type | Req | Description |
|---|---|---|---|
| body | object | – | JSON-тело запроса (для POST/PUT). |
| method | string | – | HTTP-метод. По умолчанию GET (безопасный). |
| path | string | yes | Относительный путь API, например "v1/management/segments?limit=5". |
No output schema declared.
No examples provided.
rename_segment Переименовать сегмент ~92
Изменяет сегмент. В схеме изменения доступно только поле name, так что фактически это переименование. Работает с сегментом любого типа; ответ — {"segment": {...}} с обновлёнными данными.
| Name | Type | Req | Description |
|---|---|---|---|
| name | string | yes | Новое название сегмента. |
| segment_id | integer | yes | Идентификатор сегмента (id из list_segments или из ответа создания). |
No output schema declared.
No examples provided.
start_login Начать подключение Аудиторий ~137
Первый шаг подключения Яндекс Аудиторий без правки конфигурации и без перезапуска клиента. Возвращает ссылку на страницу Яндекс OAuth. Покажите ссылку пользователю целиком и попросите: открыть её в браузере под аккаунтом Яндекса, которому принадлежат нужные сегменты (или которому они доверены), подтвердить доступ на чтение и изменение сегментов и прислать показанный код подтверждения. Полученный код передайте в finish_login. Код действует 10 минут. Сам по себе код бесполезен для постороннего: обменять его может только этот сервер.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
update_pixel Переименовать пиксель ~78
Изменяет указанный пиксель (в схеме изменения доступно только поле name — переименование). Ответ — {"pixel": {...}} с обновлёнными данными.
| Name | Type | Req | Description |
|---|---|---|---|
| name | string | yes | Новое название пикселя. |
| pixel_id | integer | yes | Идентификатор пикселя (id из list_pixels). |
No output schema declared.
No examples provided.
upload_segment_csv_file Загрузить CSV-файл сегмента (CRM-данные) ~250
Создаёт сегмент из CSV-файла с CRM-данными. Первая строка — заголовок: колонки email, phone, ext_id (или external_id) и произвольные дополнительные поля; минимум 100 записей, до 1 ГБ. Это первый шаг двухфазного создания: в ответе сегмент со статусом uploaded и его id — затем сегмент нужно сохранить инструментом confirm_segment (content_type: crm). Источник данных: file_path (путь к локальному файлу) или content (содержимое строкой) — ровно одно из двух. Квота на создание сегментов: 10/мин, 100/час, 500/сутки.
| Name | Type | Req | Description |
|---|---|---|---|
| content | string | – | Содержимое файла строкой (для небольших сегментов). Укажите либо content, либо file_path (ровно одно). |
| file_name | string | – | Имя файла для загрузки. По умолчанию — имя из file_path или стандартное имя. |
| file_path | string | – | Путь к локальному файлу с данными. Укажите либо file_path, либо content (ровно одно). |
No output schema declared.
No examples provided.
upload_segment_file Загрузить файл сегмента (device id / MAC / хеши) ~260
Создаёт сегмент из TSV/TXT-файла с данными: идентификаторы устройств (IDFA/GAID), MAC-адреса или SHA256-хеши, по одной записи в строке; минимум 100 записей, до 1 ГБ, UTF-8. Это первый шаг двухфазного создания: в ответе сегмент со статусом uploaded и его id — затем сегмент нужно сохранить инструментом confirm_segment (имя, тип содержимого, хеширование). Источник данных: file_path (путь к локальному файлу) или content (содержимое строкой) — ровно одно из двух. Квота на создание сегментов: 10/мин, 100/час, 500/сутки.
| Name | Type | Req | Description |
|---|---|---|---|
| content | string | – | Содержимое файла строкой (для небольших сегментов). Укажите либо content, либо file_path (ровно одно). |
| file_name | string | – | Имя файла для загрузки. По умолчанию — имя из file_path или стандартное имя. |
| file_path | string | – | Путь к локальному файлу с данными. Укажите либо file_path, либо content (ровно одно). |
No output schema declared.
No examples provided.
What is the Yandex Audience MCP server?
Yandex Audience MCP is listed in the public MCP registry as io.github.A1-x-Tech/mcp-yandex-audience. MCP server for Yandex Audience API: segments (CRM, lookalike, pixel), pixels, grants. This page covers its npm package (mcp-yandex-audience).
Is the Yandex Audience MCP server safe to use?
Yandex Audience MCP scores 81 out of 100 on VerifyMCP. We found no known CVEs affecting it as of 3 October 2026. It declares no install or post-install scripts. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.
What tools does the Yandex Audience MCP server expose?
Yandex Audience MCP exposes 20 tools: auth_status, start_login, finish_login, logout, list_segments, and 15 more. Their descriptions and schemas cost roughly 3,284 tokens of context every time the server is loaded.
Is the Yandex Audience MCP server still maintained?
Yandex Audience MCP is still listed as active in the MCP registry. We last reached this channel on 3 October 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.
What licence is the Yandex Audience MCP server under?
Yandex Audience MCP declares the MIT licence, which is OSI-approved. That covers the source only, and says nothing about the cost of any service it calls.