Skip to content
verify mcp Beta VerifyMCP is currently in beta. If you notice any issues, get in touch and we’ll put it right.

Sellbase

NPM · SELLBASE · SCANNED OCT 5

Open source commerce in your own Supabase: catalog, checkout, orders and bookings, run by your AI.

Available components

+15 this week 77 Trust /100
Trust breakdown (7 categories)

How this component scores in each security and reliability category. Every signal is checked automatically from public evidence about the published package, including repeated runs of it in an isolated sandbox, and we only credit what we can confirm. How we score → Why this is hard to score →

Supply Chain Security98
  • No malware found by supply-chain analysis.Pass
  • No known CVEs affecting this package version or its production dependencies.Pass
  • No install/post-install scripts declared.Pass
  • 31 of 98 dependencies flagged as unhealthy. View diagnostics → Partial
Provenance & Transparency100
  • Source repository is publicly reachable at the declared URL. View diagnostics → Pass
  • Cryptographically verified build provenance (signed, bound to jlgavel011/sellbase). View diagnostics → Pass
  • Clear OSI-approved license (MIT).Pass
  • Actively maintained (last published 6 days ago).Pass
  • Publishes a security disclosure policy (SECURITY.md).Pass
Schema Quality & AI Usability72
  • AI-judged instruction clarity (good).Pass
  • Context-footprint check failed: tool/resource definitions use about 3524 tokens (~113/item across 31 items; 31 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
  • Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management0
  • Stability not yet verified: not enough scan history yet (needs a 30-day window).Unverified
Tool Coverage75
  • 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
  • 26% of tool parameters carry a description.Partial
Tool Safety83
  • No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
  • 1 of 3 tool(s) whose name or description implies an irreversible operation declare an MCP destructiveHint annotation; "products_bulk" implies "publish" and declares no destructiveHint at all, which the MCP spec reads as destructive by default. See how to fix → Partial
  • An AI judge read all 32 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
  • Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.Pass

Unverified: 1 category

A category scored 0 because we could not verify it: a data source with nothing on this package, evidence we could not reach, or a check we could not run. We only credit what we can confirm.

Install

How do I install the Sellbase MCP server?

Sellbase runs locally as an npm package, launched with npx -y sellbase. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.

npm · sellbase

# add to Claude Code
claude mcp add jlgavel011-sellbase -- npx -y sellbase
// .cursor/mcp.json
{
  "mcpServers": {
    "jlgavel011-sellbase": {
      "command": "npx",
      "args": [
        "-y",
        "sellbase"
      ]
    }
  }
}
// .vscode/mcp.json
{
  "servers": {
    "jlgavel011-sellbase": {
      "command": "npx",
      "args": [
        "-y",
        "sellbase"
      ]
    }
  }
}
# add to Codex CLI
codex mcp add jlgavel011-sellbase -- npx -y sellbase
// opencode.json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "jlgavel011-sellbase": {
      "type": "local",
      "command": [
        "npx",
        "-y",
        "sellbase"
      ],
      "enabled": true
    }
  }
}
# add to OpenClaw
openclaw mcp add jlgavel011-sellbase --command npx --arg -y --arg sellbase
# ~/.hermes/config.yaml
mcp_servers:
  jlgavel011-sellbase:
    command: "npx"
    args: ["-y", "sellbase"]
// ~/.netclaw/config/netclaw.json
{
  "McpServers": {
    "jlgavel011-sellbase": {
      "Transport": "stdio",
      "Command": "npx",
      "Arguments": [
        "-y",
        "sellbase"
      ]
    }
  }
}
# add to Vellum
assistant mcp add jlgavel011-sellbase -t stdio -c npx -a -y sellbase
// mcp.json
{
  "mcpServers": {
    "jlgavel011-sellbase": {
      "command": "npx",
      "args": [
        "-y",
        "sellbase"
      ]
    }
  }
}
Changelog

Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.

  • 29 Sept 26 +15
    • Malware scan: unverified → pass ▲ security
  • 28 Sept 26 62

    First indexed and scored.

Diagnostics

Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.

Captured 5 Oct 2026 · Analysed npm/sellbase@0.3.3

Provenance Verified

A signed build attestation was found and verified, binding this exact artifact to the source repository it claims to come from.

Result Verified
Ecosystem npm
Reason Verified
Discovered via Registry attestation endpoint
Source repo jlgavel011/sellbase
Certificate issuer https://token.actions.githubusercontent.com
Certificate SAN https://github.com/jlgavel011/sellbase/.github/workflows/release.yml@refs/tags/v0.3.3
Rekor log index 2985365987
Predicate type SLSA build provenance https://slsa.dev/provenance/v1
Subject digest sha512:dd71dc1a8059344f9a73e6267bcb24217d9f105a1cd6f551a4f4b51872759ca4603723e857ae0bf07a5d9fa2880d986f0baa151dbac7ecf2640fd9f62

Background: How many MCP packages publish verified provenance →

Dependencies 98 packages
Packages resolved 98
Stale 31
Tree resolution Complete

Background: SBOMs and build attestations, explained →

MCP tools · 31 exposed · ~3,425 tokens

The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →

Tool Tokens
availability_get ~75

Free start times for a service variant (next 14 days by default). Use it to verify the setup or to find a time to reschedule. Times are UTC instants; say them to the owner in `timezone`.

NameTypeReqDescription
fromstring––
tostring––
variant_idstringyes–

No output schema declared.

No examples provided.

booking_action ~115

complete, no_show, cancel (needs reason and confirm=true; refund=true also refunds the booked line and needs refunds:write) or reschedule (needs starts_at from availability_get). The customer is emailed on cancel and reschedule.

NameTypeReqDescription
actionstringyes–
booking_idstringyes–
confirmboolean––
notify_customerboolean––
reasonstring––
refundboolean––
resource_idstring––
starts_atstring––

No output schema declared.

No examples provided.

bookings_search ~63

Appointments in a date range (the agenda), e.g. today's for a resource. Defaults to the next 14 days.

NameTypeReqDescription
fromstring––
resource_idstring––
statusstring––
tostring––

No output schema declared.

No examples provided.

collection_upsert ~99

Group products (e.g. "Lo más vendido", "Regalos"). Send id to update. product_ids replaces the products in that order; omit it to keep them. The storefront filters with ?collection=<slug>. Use delete: true with id to remove the collection (products are kept).

NameTypeReqDescription
collectionobject––
deleteobject––
dry_runboolean–Validate and show what would happen without changing anything.

No output schema declared.

No examples provided.

customers_search ~64

Find customers by email, name or phone, with orders count and total spent. Pass id for one customer with addresses, orders and appointments.

NameTypeReqDescription
cursorstring––
idstring––
limitinteger––
qstring––

No output schema declared.

No examples provided.

discount_upsert ~125

Discount codes and automatic discounts. kind "percent": value in basis points (1000 = 10%). kind "fixed": value in minor units. kind "free_shipping": value 0. code null = automatic (applies without a code). Codes are uppercase. Send id to update (every field is replaced). Call without discount to list the current ones. Money is an integer in minor units: $199.90 MXN is 19990.

NameTypeReqDescription
discountobject––
dry_runboolean–Validate and show what would happen without changing anything.

No output schema declared.

No examples provided.

docs_search ~61

Search guides, skills and the API reference bundled with Sellbase (e.g. "going live with Stripe", "shipping options", "refund scope"). Use it before guessing how a feature works.

NameTypeReqDescription
limitinteger––
querystringyes–

No output schema declared.

No examples provided.

feedback_draft ~215

Use it when you find a Sellbase bug (unexpected error, wrong docs, a workaround you had to write), or when you build something on top of Sellbase that other stores would need (kind "extension"). Returns a redacted draft and a prefilled GitHub issue link. Nothing is sent: show the draft to the owner, ask if they want to share it, and give them the link to submit. Never include customer data, order contents, secrets or private code.

NameTypeReqDescription
agentstring–Your name, e.g. "Claude Code".
areastring––
detailsstring–Error code/message/hint, tool output, doctor output (redacted automatically).
expectedstring––
kindstringyes–
stepsstring––
summarystringyesWhat happened, or what the store needed.
titlestringyes–
workaroundstring–For extensions and bugs: what you built or changed to get around it.

No output schema declared.

No examples provided.

integration_connect ~167

Connect Stripe (payments) or Resend (email) with API keys, stored encrypted in Supabase Vault. Stripe: when the project is deployed (public https URL) the webhook endpoint is created in Stripe for you; locally run `stripe listen --forward-to <webhooks URL>` and pass its whsec_ as webhook_secret. Use test keys (sk_test_…) until the owner says to go live; live keys (sk_live_…/rk_live_…) need confirm: true after the owner confirms customers will pay real money. Follow next_steps in the response.

NameTypeReqDescription
confirmboolean–true only for live Stripe keys, after the owner approved going live.
providerstringyes–
secret_keystringyes–
webhook_secretstring––

No output schema declared.

No examples provided.

integration_test ~26

Check that a connected provider works and explain any error.

NameTypeReqDescription
providerstringyes–

No output schema declared.

No examples provided.

inventory_adjust ~83

Add or remove stock for a variant with a reason (e.g. +20 "restock", -1 "damaged"). Cannot go below units reserved by open checkouts.

NameTypeReqDescription
deltaintegeryes–
dry_runboolean–Validate and show what would happen without changing anything.
reasonstringyes–
variant_idstringyes–

No output schema declared.

No examples provided.

media_add ~77

Add an image to a product from a public URL or a local file path (max 5 MB). The first image is the one shown in listings.

NameTypeReqDescription
altstring––
file_pathstring–Absolute path to an image on this machine.
product_idstringyes–
urlstring––

No output schema declared.

No examples provided.

order_action ~236

fulfill: mark items shipped with carrier/tracking (omit items to ship everything pending); cancel: cancel an unfulfilled or partially fulfilled order (restocks by default; needs confirm=true; refunding needs order_refund permissions); note: add an internal note; resend_notification: email the confirmation (or "order_shipped") again; payment_link: a link to pay the balance of a deposit order. Confirm cancellations with the owner first.

NameTypeReqDescription
actionstringyes–
carrierstring––
confirmboolean–Must be true to cancel.
itemsarray––
notestring–Required for note.
notify_customerboolean––
order_idstringyes–
reasonstring–Required for cancel.
refundboolean–cancel only: also refund what was paid (needs refunds:write).
restockboolean––
success_urlstring–payment_link only: where the customer lands after paying the balance.
templatestring––
tracking_numberstring––
tracking_urlstring––

No output schema declared.

No examples provided.

order_create ~148

Record a sale made outside the storefront (in person, WhatsApp, phone). payment.mode "paid" with method cash/spei/card/other when the money was already received: needs confirm: true after the owner checks the total. payment.mode "link" to get a Stripe payment link for the customer (the order waits as pending_payment and opens when paid). Stock is taken immediately; unit_price_amount overrides the price for this order only. Services must be booked from the storefront. Money is an integer in minor units: $199.90 MXN is 19990.

NameTypeReqDescription
dry_runboolean–Validate and show what would happen without changing anything.
orderobjectyes–

No output schema declared.

No examples provided.

order_get ~32

Full order: items (snapshots), totals, payments, shipping address and timeline.

NameTypeReqDescription
idstringyes–

No output schema declared.

No examples provided.

order_refund ~122

Refund all or part of an order through the payment provider. Moves real money in live mode: get explicit approval from the owner and pass confirm=true. Needs the refunds:write scope (agent tokens do not have it unless the owner granted it). Money is an integer in minor units: $199.90 MXN is 19990.

NameTypeReqDescription
amountinteger–Minor units; omit to refund everything left.
confirmbooleanyes–
notify_customerboolean––
order_idstringyes–
reasonstringyes–

No output schema declared.

No examples provided.

orders_search ~103

Find orders, e.g. to fulfill today: fulfillment_status "unfulfilled". q matches an order number (#1001) or a customer email.

NameTypeReqDescription
channelstring––
cursorstring––
fromstring––
fulfillment_statusstring––
limitinteger––
payment_statusstring––
qstring––
statusstring––
tostring––

No output schema declared.

No examples provided.

payments_live_check ~116

After connecting live Stripe keys: creates a Checkout for the smallest amount Stripe allows (10 MXN / 0.50 USD). The OWNER pays it with a real card; when the webhook arrives it is refunded automatically and store_status shows "Live payment check" as ok. Stripe keeps its small fee. Ask the owner before calling (confirm: true), give them the URL, then check store_status.

NameTypeReqDescription
confirmbooleanyes–
success_urlstring–Where to land after paying; defaults to settings.site_url.

No output schema declared.

No examples provided.

product_file_upload ~102

Attach the file buyers receive to a digital variant, from a local path (max 10 MB). Buyers get a private, expiring download link by email after paying.

NameTypeReqDescription
download_limitinteger–Max downloads per purchase; unlimited if omitted.
file_pathstringyesAbsolute path to the file on this machine.
link_ttl_hoursinteger–Hours the link stays valid (default 72).
variant_idstringyes–

No output schema declared.

No examples provided.

product_get ~33

Full product: variants with price, stock, shipping specs and attached files, plus images.

NameTypeReqDescription
idstringyes–

No output schema declared.

No examples provided.

product_upsert ~137

Create or update a whole product of any type in one call. Send id to update; variants with id are updated, without id are created, missing ones are archived. Every product needs at least one variant (use one titled "Default" when there are no options). Set status "active" to publish. Physical: variants[].physical and variants[].inventory.on_hand. Digital: afterwards attach the file with product_file_upload. Money is an integer in minor units: $199.90 MXN is 19990.

NameTypeReqDescription
dry_runboolean–Validate and show what would happen without changing anything.
productobjectyes–

No output schema declared.

No examples provided.

products_bulk ~139

Publish, unpublish (draft), archive or reprice many products at once. Prices: price.mode "percent" in basis points (-1000 = 10% off, 500 = 5% up), "amount" adds minor units (negative lowers), "set" sets the price. Price changes return a preview of old → new prices; only send confirm: true after the owner approves that preview. Money is an integer in minor units: $199.90 MXN is 19990.

NameTypeReqDescription
actionstringyes–
confirmboolean––
priceobject––
product_idsarrayyes–

No output schema declared.

No examples provided.

products_import ~161

Import or update many products from a CSV: our template (title,price,sku,stock,status,type,option1 name,option1 value,image), Spanish headers (nombre,precio,existencias…) or a Shopify export. Rows with the same handle become variants; existing products (same handle) are updated and variants match by SKU; variants missing from the file are archived. Services are not imported (use product_upsert). Run with dry_run: true first and show the owner the summary and any row errors.

NameTypeReqDescription
csvstring–CSV text, when there is no file.
dry_runboolean–Validate and show what would happen without changing anything.
file_pathstring–Absolute path to a .csv on this machine.

No output schema declared.

No examples provided.

products_search ~64

List or search products (by title or SKU). Returns compact rows; use product_get for full detail.

NameTypeReqDescription
cursorstring––
limitinteger––
qstring––
statusstring––
typestring––

No output schema declared.

No examples provided.

report_summary ~49

Sales today, last 7 and 30 days (paid minus refunded), daily series, top products, orders waiting to ship and appointments today. Use it to answer "how is the store doing?".

Input schema present but exposes no named parameters.

No output schema declared.

No examples provided.

service_setup ~147

Create or update a resource (a person, room or equipment) with weekly hours and the service products it delivers. Hours are local times in the store time zone unless `timezone` is given (weekday 0 = Sunday … 6 = Saturday). Optionally block days off with `closed`. Create the service product first with product_upsert (type "service", variants[].service.duration_min).

NameTypeReqDescription
closedarray––
hoursarray––
kindstring––
namestringyes–
resource_idstring–Update this resource; omit to create one.
service_product_idsarray––
timezonestring––

No output schema declared.

No examples provided.

store_status ~47

Use first, and whenever unsure what to do next. Returns the setup checklist (schema, payments, emails, catalog, webhooks) with a hint for each pending item, plus store basics.

Input schema present but exposes no named parameters.

No output schema declared.

No examples provided.

store_update_settings ~109

Change the store name, contact email, currency, locale, timezone, logo, brand color, tax (settings.tax.rate_bps: 1600 = 16%, mode inclusive|exclusive) and manual shipping (settings.shipping: flat_rate_amount, free_over_amount, pickup.enabled). Money is an integer in minor units: $199.90 MXN is 19990.

NameTypeReqDescription
changesobjectyes–
dry_runboolean–Validate and show what would happen without changing anything.

No output schema declared.

No examples provided.

storefront_scaffold ~139

Given what the owner wants to sell (e.g. "tienda de playeras", "agenda de citas para mi consultorio", "vender un curso"), returns which storefront components to add (React) or which <sellbase-*> elements to place (any other site, framework "web"), suggested pages and next steps. Run the command in the project, then follow the add-storefront skill.

NameTypeReqDescription
frameworkstring–react: Next.js or Vite + React. web: any other site (plain HTML, WordPress, Vue, Astro…) using <sellbase-*> web components.
intentstringyes–

No output schema declared.

No examples provided.

test_purchase ~88

Buy one active physical and one active digital product in payment TEST mode and report each step (cart, checkout, payment, order, delivery, email, download). Stock is restored afterwards. Run it after setting up the store and after any change to payments or products.

NameTypeReqDescription
emailstring–Where the test confirmation goes (default test-purchase@example.com).
variant_idsarray––

No output schema declared.

No examples provided.

webhook_setup ~283

Send store events (orders, refunds, shipments, bookings, products) to another system such as an ERP, a sheet or an automation tool. action "list" shows endpoints and delivery health; "create" needs the webhooks:write scope (agent tokens do not have it unless the owner granted it) and confirm: true after the owner approved the URL and events, since customer and order data will be sent there; it returns the signing secret ONCE (give it to the owner to store in the receiving system, never print it again); "test" sends a signed webhook.test now; "delete" removes one. Receivers verify the Sellbase-Signature header: t=<unix>,v1=HMAC-SHA256(secret, "<t>.<body>"). Events: order.created, order.paid, order.deposit_paid, order.cancelled, payment.succeeded, refund.created, fulfillment.shipped, booking.rescheduled, booking.cancelled, product.created, product.updated, product.archived, inventory.oversold.

NameTypeReqDescription
actionstringyes–
confirmboolean–create only: true after the owner approved sending data to this URL.
descriptionstring––
eventsarray–Empty or omitted = every event.
idstring–Endpoint id for test and delete.
urlstring––

No output schema declared.

No examples provided.

Common questions

What is the Sellbase MCP server?

Sellbase is an MCP server listed in the public MCP registry as io.github.jlgavel011/sellbase. Open source commerce in your own Supabase: catalog, checkout, orders and bookings, run by your AI. This page covers its npm package (sellbase).

Is the Sellbase MCP server safe to use?

Sellbase scores 77 out of 100 on VerifyMCP. We found no known CVEs affecting it as of 5 October 2026. It declares no install or post-install scripts. Its build provenance is signed and verified. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.

What tools does the Sellbase MCP server expose?

Sellbase exposes 31 tools: store_status, store_update_settings, integration_connect, payments_live_check, integration_test, and 26 more. Their descriptions and schemas cost roughly 3,425 tokens of context every time the server is loaded.

Is the Sellbase MCP server still maintained?

Sellbase is still listed as active in the MCP registry. We last reached this channel on 5 October 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.

What licence is the Sellbase MCP server under?

Sellbase declares the MIT licence, which is OSI-approved. That covers the source only, and says nothing about the cost of any service it calls.