Sellbase
NPM · SELLBASE · SCANNED OCT 5
Open source commerce in your own Supabase: catalog, checkout, orders and bookings, run by your AI.
Available components
How this component scores in each security and reliability category. Every signal is checked automatically from public evidence about the published package, including repeated runs of it in an isolated sandbox, and we only credit what we can confirm. How we score → Why this is hard to score →
Supply Chain Security98
- No malware found by supply-chain analysis.Pass
- No known CVEs affecting this package version or its production dependencies.Pass
- No install/post-install scripts declared.Pass
- 31 of 98 dependencies flagged as unhealthy. View diagnostics → Partial
Provenance & Transparency100
- Source repository is publicly reachable at the declared URL. View diagnostics → Pass
- Cryptographically verified build provenance (signed, bound to jlgavel011/sellbase). View diagnostics → Pass
- Clear OSI-approved license (MIT).Pass
- Actively maintained (last published 6 days ago).Pass
- Publishes a security disclosure policy (SECURITY.md).Pass
Schema Quality & AI Usability72
- AI-judged instruction clarity (good).Pass
- Context-footprint check failed: tool/resource definitions use about 3524 tokens (~113/item across 31 items; 31 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management0
- Stability not yet verified: not enough scan history yet (needs a 30-day window).Unverified
Tool Coverage75
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 26% of tool parameters carry a description.Partial
Tool Safety83
- No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
- 1 of 3 tool(s) whose name or description implies an irreversible operation declare an MCP destructiveHint annotation; "products_bulk" implies "publish" and declares no destructiveHint at all, which the MCP spec reads as destructive by default. See how to fix → Partial
- An AI judge read all 32 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
- Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass
Unverified: 1 category
A category scored 0 because we could not verify it: a data source with nothing on this package, evidence we could not reach, or a check we could not run. We only credit what we can confirm.
How do I install the Sellbase MCP server?
Sellbase runs locally as an npm package, launched with npx -y sellbase. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.
npm · sellbase
claude mcp add jlgavel011-sellbase -- npx -y sellbase
{
"mcpServers": {
"jlgavel011-sellbase": {
"command": "npx",
"args": [
"-y",
"sellbase"
]
}
}
} {
"servers": {
"jlgavel011-sellbase": {
"command": "npx",
"args": [
"-y",
"sellbase"
]
}
}
} codex mcp add jlgavel011-sellbase -- npx -y sellbase
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"jlgavel011-sellbase": {
"type": "local",
"command": [
"npx",
"-y",
"sellbase"
],
"enabled": true
}
}
} openclaw mcp add jlgavel011-sellbase --command npx --arg -y --arg sellbase
mcp_servers:
jlgavel011-sellbase:
command: "npx"
args: ["-y", "sellbase"] {
"McpServers": {
"jlgavel011-sellbase": {
"Transport": "stdio",
"Command": "npx",
"Arguments": [
"-y",
"sellbase"
]
}
}
} assistant mcp add jlgavel011-sellbase -t stdio -c npx -a -y sellbase
{
"mcpServers": {
"jlgavel011-sellbase": {
"command": "npx",
"args": [
"-y",
"sellbase"
]
}
}
} Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 29 Sept 26 +15
- Malware scan: unverified → pass ▲ security
- 28 Sept 26 62
First indexed and scored.
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 5 Oct 2026 · Analysed npm/sellbase@0.3.3
Provenance Verified
A signed build attestation was found and verified, binding this exact artifact to the source repository it claims to come from.
| Result | Verified |
|---|---|
| Ecosystem | npm |
| Reason | Verified |
| Discovered via | Registry attestation endpoint |
| Source repo | jlgavel011/sellbase |
| Certificate issuer | https://token.actions.githubusercontent.com |
| Certificate SAN | https://github.com/jlgavel011/sellbase/.github/workflows/release.yml@refs/tags/v0.3.3 |
| Rekor log index | 2985365987 |
| Predicate type | SLSA build provenance https://slsa.dev/provenance/v1 |
| Subject digest | sha512:dd71dc1a8059344f9a73e6267bcb24217d9f105a1cd6f551a4f4b51872759ca4603723e857ae0bf07a5d9fa2880d986f0baa151dbac7ecf2640fd9f62 |
Background: How many MCP packages publish verified provenance →
Dependencies 98 packages
| Packages resolved | 98 |
|---|---|
| Stale | 31 |
| Tree resolution | Complete |
Background: SBOMs and build attestations, explained →
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
availability_get Free times for a service ~75
Free start times for a service variant (next 14 days by default). Use it to verify the setup or to find a time to reschedule. Times are UTC instants; say them to the owner in `timezone`.
| Name | Type | Req | Description |
|---|---|---|---|
| from | string | – | – |
| to | string | – | – |
| variant_id | string | yes | – |
No output schema declared.
No examples provided.
booking_action Act on an appointment ~115
complete, no_show, cancel (needs reason and confirm=true; refund=true also refunds the booked line and needs refunds:write) or reschedule (needs starts_at from availability_get). The customer is emailed on cancel and reschedule.
| Name | Type | Req | Description |
|---|---|---|---|
| action | string | yes | – |
| booking_id | string | yes | – |
| confirm | boolean | – | – |
| notify_customer | boolean | – | – |
| reason | string | – | – |
| refund | boolean | – | – |
| resource_id | string | – | – |
| starts_at | string | – | – |
No output schema declared.
No examples provided.
bookings_search Search appointments ~63
Appointments in a date range (the agenda), e.g. today's for a resource. Defaults to the next 14 days.
| Name | Type | Req | Description |
|---|---|---|---|
| from | string | – | – |
| resource_id | string | – | – |
| status | string | – | – |
| to | string | – | – |
No output schema declared.
No examples provided.
collection_upsert Create or update collection ~99
Group products (e.g. "Lo más vendido", "Regalos"). Send id to update. product_ids replaces the products in that order; omit it to keep them. The storefront filters with ?collection=<slug>. Use delete: true with id to remove the collection (products are kept).
| Name | Type | Req | Description |
|---|---|---|---|
| collection | object | – | – |
| delete | object | – | – |
| dry_run | boolean | – | Validate and show what would happen without changing anything. |
No output schema declared.
No examples provided.
customers_search Search customers ~64
Find customers by email, name or phone, with orders count and total spent. Pass id for one customer with addresses, orders and appointments.
| Name | Type | Req | Description |
|---|---|---|---|
| cursor | string | – | – |
| id | string | – | – |
| limit | integer | – | – |
| q | string | – | – |
No output schema declared.
No examples provided.
discount_upsert Create or update discount ~125
Discount codes and automatic discounts. kind "percent": value in basis points (1000 = 10%). kind "fixed": value in minor units. kind "free_shipping": value 0. code null = automatic (applies without a code). Codes are uppercase. Send id to update (every field is replaced). Call without discount to list the current ones. Money is an integer in minor units: $199.90 MXN is 19990.
| Name | Type | Req | Description |
|---|---|---|---|
| discount | object | – | – |
| dry_run | boolean | – | Validate and show what would happen without changing anything. |
No output schema declared.
No examples provided.
docs_search Search the Sellbase docs ~61
Search guides, skills and the API reference bundled with Sellbase (e.g. "going live with Stripe", "shipping options", "refund scope"). Use it before guessing how a feature works.
| Name | Type | Req | Description |
|---|---|---|---|
| limit | integer | – | – |
| query | string | yes | – |
No output schema declared.
No examples provided.
feedback_draft Draft feedback for the Sellbase maintainers ~215
Use it when you find a Sellbase bug (unexpected error, wrong docs, a workaround you had to write), or when you build something on top of Sellbase that other stores would need (kind "extension"). Returns a redacted draft and a prefilled GitHub issue link. Nothing is sent: show the draft to the owner, ask if they want to share it, and give them the link to submit. Never include customer data, order contents, secrets or private code.
| Name | Type | Req | Description |
|---|---|---|---|
| agent | string | – | Your name, e.g. "Claude Code". |
| area | string | – | – |
| details | string | – | Error code/message/hint, tool output, doctor output (redacted automatically). |
| expected | string | – | – |
| kind | string | yes | – |
| steps | string | – | – |
| summary | string | yes | What happened, or what the store needed. |
| title | string | yes | – |
| workaround | string | – | For extensions and bugs: what you built or changed to get around it. |
No output schema declared.
No examples provided.
integration_connect Connect a provider ~167
Connect Stripe (payments) or Resend (email) with API keys, stored encrypted in Supabase Vault. Stripe: when the project is deployed (public https URL) the webhook endpoint is created in Stripe for you; locally run `stripe listen --forward-to <webhooks URL>` and pass its whsec_ as webhook_secret. Use test keys (sk_test_…) until the owner says to go live; live keys (sk_live_…/rk_live_…) need confirm: true after the owner confirms customers will pay real money. Follow next_steps in the response.
| Name | Type | Req | Description |
|---|---|---|---|
| confirm | boolean | – | true only for live Stripe keys, after the owner approved going live. |
| provider | string | yes | – |
| secret_key | string | yes | – |
| webhook_secret | string | – | – |
No output schema declared.
No examples provided.
integration_test Test a provider ~26
Check that a connected provider works and explain any error.
| Name | Type | Req | Description |
|---|---|---|---|
| provider | string | yes | – |
No output schema declared.
No examples provided.
inventory_adjust Adjust stock ~83
Add or remove stock for a variant with a reason (e.g. +20 "restock", -1 "damaged"). Cannot go below units reserved by open checkouts.
| Name | Type | Req | Description |
|---|---|---|---|
| delta | integer | yes | – |
| dry_run | boolean | – | Validate and show what would happen without changing anything. |
| reason | string | yes | – |
| variant_id | string | yes | – |
No output schema declared.
No examples provided.
media_add Add product image ~77
Add an image to a product from a public URL or a local file path (max 5 MB). The first image is the one shown in listings.
| Name | Type | Req | Description |
|---|---|---|---|
| alt | string | – | – |
| file_path | string | – | Absolute path to an image on this machine. |
| product_id | string | yes | – |
| url | string | – | – |
No output schema declared.
No examples provided.
order_action Act on an order ~236
fulfill: mark items shipped with carrier/tracking (omit items to ship everything pending); cancel: cancel an unfulfilled or partially fulfilled order (restocks by default; needs confirm=true; refunding needs order_refund permissions); note: add an internal note; resend_notification: email the confirmation (or "order_shipped") again; payment_link: a link to pay the balance of a deposit order. Confirm cancellations with the owner first.
| Name | Type | Req | Description |
|---|---|---|---|
| action | string | yes | – |
| carrier | string | – | – |
| confirm | boolean | – | Must be true to cancel. |
| items | array | – | – |
| note | string | – | Required for note. |
| notify_customer | boolean | – | – |
| order_id | string | yes | – |
| reason | string | – | Required for cancel. |
| refund | boolean | – | cancel only: also refund what was paid (needs refunds:write). |
| restock | boolean | – | – |
| success_url | string | – | payment_link only: where the customer lands after paying the balance. |
| template | string | – | – |
| tracking_number | string | – | – |
| tracking_url | string | – | – |
No output schema declared.
No examples provided.
order_create Record a manual order ~148
Record a sale made outside the storefront (in person, WhatsApp, phone). payment.mode "paid" with method cash/spei/card/other when the money was already received: needs confirm: true after the owner checks the total. payment.mode "link" to get a Stripe payment link for the customer (the order waits as pending_payment and opens when paid). Stock is taken immediately; unit_price_amount overrides the price for this order only. Services must be booked from the storefront. Money is an integer in minor units: $199.90 MXN is 19990.
| Name | Type | Req | Description |
|---|---|---|---|
| dry_run | boolean | – | Validate and show what would happen without changing anything. |
| order | object | yes | – |
No output schema declared.
No examples provided.
order_get Get order ~32
Full order: items (snapshots), totals, payments, shipping address and timeline.
| Name | Type | Req | Description |
|---|---|---|---|
| id | string | yes | – |
No output schema declared.
No examples provided.
order_refund Refund an order ~122
Refund all or part of an order through the payment provider. Moves real money in live mode: get explicit approval from the owner and pass confirm=true. Needs the refunds:write scope (agent tokens do not have it unless the owner granted it). Money is an integer in minor units: $199.90 MXN is 19990.
| Name | Type | Req | Description |
|---|---|---|---|
| amount | integer | – | Minor units; omit to refund everything left. |
| confirm | boolean | yes | – |
| notify_customer | boolean | – | – |
| order_id | string | yes | – |
| reason | string | yes | – |
No output schema declared.
No examples provided.
orders_search Search orders ~103
Find orders, e.g. to fulfill today: fulfillment_status "unfulfilled". q matches an order number (#1001) or a customer email.
| Name | Type | Req | Description |
|---|---|---|---|
| channel | string | – | – |
| cursor | string | – | – |
| from | string | – | – |
| fulfillment_status | string | – | – |
| limit | integer | – | – |
| payment_status | string | – | – |
| q | string | – | – |
| status | string | – | – |
| to | string | – | – |
No output schema declared.
No examples provided.
payments_live_check Verify real payments ~116
After connecting live Stripe keys: creates a Checkout for the smallest amount Stripe allows (10 MXN / 0.50 USD). The OWNER pays it with a real card; when the webhook arrives it is refunded automatically and store_status shows "Live payment check" as ok. Stripe keeps its small fee. Ask the owner before calling (confirm: true), give them the URL, then check store_status.
| Name | Type | Req | Description |
|---|---|---|---|
| confirm | boolean | yes | – |
| success_url | string | – | Where to land after paying; defaults to settings.site_url. |
No output schema declared.
No examples provided.
product_file_upload Attach file to digital product ~102
Attach the file buyers receive to a digital variant, from a local path (max 10 MB). Buyers get a private, expiring download link by email after paying.
| Name | Type | Req | Description |
|---|---|---|---|
| download_limit | integer | – | Max downloads per purchase; unlimited if omitted. |
| file_path | string | yes | Absolute path to the file on this machine. |
| link_ttl_hours | integer | – | Hours the link stays valid (default 72). |
| variant_id | string | yes | – |
No output schema declared.
No examples provided.
product_get Get product ~33
Full product: variants with price, stock, shipping specs and attached files, plus images.
| Name | Type | Req | Description |
|---|---|---|---|
| id | string | yes | – |
No output schema declared.
No examples provided.
product_upsert Create or update product ~137
Create or update a whole product of any type in one call. Send id to update; variants with id are updated, without id are created, missing ones are archived. Every product needs at least one variant (use one titled "Default" when there are no options). Set status "active" to publish. Physical: variants[].physical and variants[].inventory.on_hand. Digital: afterwards attach the file with product_file_upload. Money is an integer in minor units: $199.90 MXN is 19990.
| Name | Type | Req | Description |
|---|---|---|---|
| dry_run | boolean | – | Validate and show what would happen without changing anything. |
| product | object | yes | – |
No output schema declared.
No examples provided.
products_bulk Bulk product changes ~139
Publish, unpublish (draft), archive or reprice many products at once. Prices: price.mode "percent" in basis points (-1000 = 10% off, 500 = 5% up), "amount" adds minor units (negative lowers), "set" sets the price. Price changes return a preview of old → new prices; only send confirm: true after the owner approves that preview. Money is an integer in minor units: $199.90 MXN is 19990.
| Name | Type | Req | Description |
|---|---|---|---|
| action | string | yes | – |
| confirm | boolean | – | – |
| price | object | – | – |
| product_ids | array | yes | – |
No output schema declared.
No examples provided.
products_import Import products from CSV ~161
Import or update many products from a CSV: our template (title,price,sku,stock,status,type,option1 name,option1 value,image), Spanish headers (nombre,precio,existencias…) or a Shopify export. Rows with the same handle become variants; existing products (same handle) are updated and variants match by SKU; variants missing from the file are archived. Services are not imported (use product_upsert). Run with dry_run: true first and show the owner the summary and any row errors.
| Name | Type | Req | Description |
|---|---|---|---|
| csv | string | – | CSV text, when there is no file. |
| dry_run | boolean | – | Validate and show what would happen without changing anything. |
| file_path | string | – | Absolute path to a .csv on this machine. |
No output schema declared.
No examples provided.
products_search Search products ~64
List or search products (by title or SKU). Returns compact rows; use product_get for full detail.
| Name | Type | Req | Description |
|---|---|---|---|
| cursor | string | – | – |
| limit | integer | – | – |
| q | string | – | – |
| status | string | – | – |
| type | string | – | – |
No output schema declared.
No examples provided.
report_summary Sales summary ~49
Sales today, last 7 and 30 days (paid minus refunded), daily series, top products, orders waiting to ship and appointments today. Use it to answer "how is the store doing?".
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
service_setup Set up who delivers a service and when ~147
Create or update a resource (a person, room or equipment) with weekly hours and the service products it delivers. Hours are local times in the store time zone unless `timezone` is given (weekday 0 = Sunday … 6 = Saturday). Optionally block days off with `closed`. Create the service product first with product_upsert (type "service", variants[].service.duration_min).
| Name | Type | Req | Description |
|---|---|---|---|
| closed | array | – | – |
| hours | array | – | – |
| kind | string | – | – |
| name | string | yes | – |
| resource_id | string | – | Update this resource; omit to create one. |
| service_product_ids | array | – | – |
| timezone | string | – | – |
No output schema declared.
No examples provided.
store_status Store status ~47
Use first, and whenever unsure what to do next. Returns the setup checklist (schema, payments, emails, catalog, webhooks) with a hint for each pending item, plus store basics.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
store_update_settings Update store settings ~109
Change the store name, contact email, currency, locale, timezone, logo, brand color, tax (settings.tax.rate_bps: 1600 = 16%, mode inclusive|exclusive) and manual shipping (settings.shipping: flat_rate_amount, free_over_amount, pickup.enabled). Money is an integer in minor units: $199.90 MXN is 19990.
| Name | Type | Req | Description |
|---|---|---|---|
| changes | object | yes | – |
| dry_run | boolean | – | Validate and show what would happen without changing anything. |
No output schema declared.
No examples provided.
storefront_scaffold Plan the storefront ~139
Given what the owner wants to sell (e.g. "tienda de playeras", "agenda de citas para mi consultorio", "vender un curso"), returns which storefront components to add (React) or which <sellbase-*> elements to place (any other site, framework "web"), suggested pages and next steps. Run the command in the project, then follow the add-storefront skill.
| Name | Type | Req | Description |
|---|---|---|---|
| framework | string | – | react: Next.js or Vite + React. web: any other site (plain HTML, WordPress, Vue, Astro…) using <sellbase-*> web components. |
| intent | string | yes | – |
No output schema declared.
No examples provided.
test_purchase Test purchase ~88
Buy one active physical and one active digital product in payment TEST mode and report each step (cart, checkout, payment, order, delivery, email, download). Stock is restored afterwards. Run it after setting up the store and after any change to payments or products.
| Name | Type | Req | Description |
|---|---|---|---|
| string | – | Where the test confirmation goes (default test-purchase@example.com). | |
| variant_ids | array | – | – |
No output schema declared.
No examples provided.
webhook_setup Outbound webhooks ~283
Send store events (orders, refunds, shipments, bookings, products) to another system such as an ERP, a sheet or an automation tool. action "list" shows endpoints and delivery health; "create" needs the webhooks:write scope (agent tokens do not have it unless the owner granted it) and confirm: true after the owner approved the URL and events, since customer and order data will be sent there; it returns the signing secret ONCE (give it to the owner to store in the receiving system, never print it again); "test" sends a signed webhook.test now; "delete" removes one. Receivers verify the Sellbase-Signature header: t=<unix>,v1=HMAC-SHA256(secret, "<t>.<body>"). Events: order.created, order.paid, order.deposit_paid, order.cancelled, payment.succeeded, refund.created, fulfillment.shipped, booking.rescheduled, booking.cancelled, product.created, product.updated, product.archived, inventory.oversold.
| Name | Type | Req | Description |
|---|---|---|---|
| action | string | yes | – |
| confirm | boolean | – | create only: true after the owner approved sending data to this URL. |
| description | string | – | – |
| events | array | – | Empty or omitted = every event. |
| id | string | – | Endpoint id for test and delete. |
| url | string | – | – |
No output schema declared.
No examples provided.
What is the Sellbase MCP server?
Sellbase is an MCP server listed in the public MCP registry as io.github.jlgavel011/sellbase. Open source commerce in your own Supabase: catalog, checkout, orders and bookings, run by your AI. This page covers its npm package (sellbase).
Is the Sellbase MCP server safe to use?
Sellbase scores 77 out of 100 on VerifyMCP. We found no known CVEs affecting it as of 5 October 2026. It declares no install or post-install scripts. Its build provenance is signed and verified. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.
What tools does the Sellbase MCP server expose?
Sellbase exposes 31 tools: store_status, store_update_settings, integration_connect, payments_live_check, integration_test, and 26 more. Their descriptions and schemas cost roughly 3,425 tokens of context every time the server is loaded.
Is the Sellbase MCP server still maintained?
Sellbase is still listed as active in the MCP registry. We last reached this channel on 5 October 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.
What licence is the Sellbase MCP server under?
Sellbase declares the MIT licence, which is OSI-approved. That covers the source only, and says nothing about the cost of any service it calls.