# Sellbase (npm · sellbase)

Open source commerce in your own Supabase: catalog, checkout, orders and bookings, run by your AI.

- Trust score: 77/100 (medium)
- Change this week: +15
- Registry status: active
- Liveness: live
- Owner verified: no
- Last scored: 2026-10-05

## Components

- npm · `sellbase`: 77/100 (this document), [markdown](https://verifymcp.io/servers/jlgavel011-sellbase/sellbase.md), [page](https://verifymcp.io/servers/jlgavel011-sellbase/sellbase)

## Channel facts

- Registry: `npm`
- Package: `sellbase`
- Version: `0.3.3`
- Transport: `stdio`

## Trust breakdown

How this component scores in each security and reliability category. Every signal is checked automatically from public evidence about the published package, including repeated runs of it in an isolated sandbox, and we only credit what we can confirm. Scores are 0–100 per category. Scoring method: https://verifymcp.io/docs/scoring (what has changed: https://verifymcp.io/docs/scoring/changelog)

Scored 2026-10-05.

- **Supply Chain Security**: 98/100
  - No malware found by supply-chain analysis.
  - No known CVEs affecting this package version or its production dependencies.
  - No install/post-install scripts declared.
  - 31 of 98 dependencies flagged as unhealthy.
- **Provenance & Transparency**: 100/100
  - Source repository is publicly reachable at the declared URL.
  - Cryptographically verified build provenance (signed, bound to jlgavel011/sellbase).
  - Clear OSI-approved license (MIT).
  - Actively maintained (last published 6 days ago).
  - Publishes a security disclosure policy (SECURITY.md).
- **Schema Quality & AI Usability**: 72/100
  - AI-judged instruction clarity (good).
  - Context-footprint check failed: tool/resource definitions use about 3524 tokens (~113/item across 31 items; 31 tools + 0 resources), over budget; trim descriptions and params.
  - Usage-examples check failed: none of the tools include examples.
- **Stability & Change Management**: 0/100
  - Stability not yet verified: not enough scan history yet (needs a 30-day window).
- **Tool Coverage**: 75/100
  - 100% of tools have a non-trivial description (not blank, and not just the tool's name).
  - 26% of tool parameters carry a description.
- **Tool Safety**: 83/100
  - No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.
  - 1 of 3 tool(s) whose name or description implies an irreversible operation declare an MCP destructiveHint annotation; "products_bulk" implies "publish" and declares no destructiveHint at all, which the MCP spec reads as destructive by default.
  - An AI judge read all 32 captured unit(s) of tool text and found none that tries to manipulate the model reading it.
- **Capabilities**: 100/100
  - Implements a supported MCP spec version (2025-11-25); the latest is 2026-07-28.

**Unverified: 1 category.** A category scored 0 because we could not verify it: a data source with nothing on this package, evidence we could not reach, or a check we could not run. We only credit what we can confirm.

## Install

### How do I install the Sellbase MCP server?

Sellbase runs locally as an npm package, launched with npx -y sellbase. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.

### Claude

```bash
claude mcp add jlgavel011-sellbase -- npx -y sellbase
```

### Cursor

```json
{
  "mcpServers": {
    "jlgavel011-sellbase": {
      "command": "npx",
      "args": [
        "-y",
        "sellbase"
      ]
    }
  }
}
```

### VS Code

```json
{
  "servers": {
    "jlgavel011-sellbase": {
      "command": "npx",
      "args": [
        "-y",
        "sellbase"
      ]
    }
  }
}
```

### Codex

```bash
codex mcp add jlgavel011-sellbase -- npx -y sellbase
```

### opencode

```json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "jlgavel011-sellbase": {
      "type": "local",
      "command": [
        "npx",
        "-y",
        "sellbase"
      ],
      "enabled": true
    }
  }
}
```

### OpenClaw

```bash
openclaw mcp add jlgavel011-sellbase --command npx --arg -y --arg sellbase
```

### Hermes

```yaml
mcp_servers:
  jlgavel011-sellbase:
    command: "npx"
    args: ["-y", "sellbase"]
```

### Netclaw

```json
{
  "McpServers": {
    "jlgavel011-sellbase": {
      "Transport": "stdio",
      "Command": "npx",
      "Arguments": [
        "-y",
        "sellbase"
      ]
    }
  }
}
```

### Vellum

```bash
assistant mcp add jlgavel011-sellbase -t stdio -c npx -a -y sellbase
```

### Other

```json
{
  "mcpServers": {
    "jlgavel011-sellbase": {
      "command": "npx",
      "args": [
        "-y",
        "sellbase"
      ]
    }
  }
}
```

## Changelog

Every change recorded for this component, newest first. Days that predate change tracking, or that we cannot explain, say so: "we were watching and nothing happened" and "we were not watching" are different claims.

### 2026-09-29 (score 77, +15)

- [security improvement] Malware scan: unverified → pass

### 2026-09-28 (score 62)

First indexed and scored.

## MCP tools (31)

### `store_status` (~47 tokens)

Store status

Use first, and whenever unsure what to do next. Returns the setup checklist (schema, payments, emails, catalog, webhooks) with a hint for each pending item, plus store basics.

### `store_update_settings` (~109 tokens)

Update store settings

Change the store name, contact email, currency, locale, timezone, logo, brand color, tax (settings.tax.rate_bps: 1600 = 16%, mode inclusive|exclusive) and manual shipping (settings.shipping: flat_rate_amount, free_over_amount, pickup.enabled). Money is an integer in minor units: $199.90 MXN is 19990.

Input parameters:

- `changes` (object, required)
- `dry_run` (boolean): Validate and show what would happen without changing anything.

### `integration_connect` (~167 tokens)

Connect a provider

Connect Stripe (payments) or Resend (email) with API keys, stored encrypted in Supabase Vault. Stripe: when the project is deployed (public https URL) the webhook endpoint is created in Stripe for you; locally run `stripe listen --forward-to <webhooks URL>` and pass its whsec_ as webhook_secret. Use test keys (sk_test_…) until the owner says to go live; live keys (sk_live_…/rk_live_…) need confirm: true after the owner confirms customers will pay real money. Follow next_steps in the response.

Input parameters:

- `confirm` (boolean): true only for live Stripe keys, after the owner approved going live.
- `provider` (string, required)
- `secret_key` (string, required)
- `webhook_secret` (string)

### `payments_live_check` (~116 tokens)

Verify real payments

After connecting live Stripe keys: creates a Checkout for the smallest amount Stripe allows (10 MXN / 0.50 USD). The OWNER pays it with a real card; when the webhook arrives it is refunded automatically and store_status shows "Live payment check" as ok. Stripe keeps its small fee. Ask the owner before calling (confirm: true), give them the URL, then check store_status.

Input parameters:

- `confirm` (boolean, required)
- `success_url` (string): Where to land after paying; defaults to settings.site_url.

### `integration_test` (~26 tokens)

Test a provider

Check that a connected provider works and explain any error.

Input parameters:

- `provider` (string, required)

### `products_search` (~64 tokens)

Search products

List or search products (by title or SKU). Returns compact rows; use product_get for full detail.

Input parameters:

- `cursor` (string)
- `limit` (integer)
- `q` (string)
- `status` (string)
- `type` (string)

### `product_get` (~33 tokens)

Get product

Full product: variants with price, stock, shipping specs and attached files, plus images.

Input parameters:

- `id` (string, required)

### `product_upsert` (~137 tokens)

Create or update product

Create or update a whole product of any type in one call. Send id to update; variants with id are updated, without id are created, missing ones are archived. Every product needs at least one variant (use one titled "Default" when there are no options). Set status "active" to publish. Physical: variants[].physical and variants[].inventory.on_hand. Digital: afterwards attach the file with product_file_upload. Money is an integer in minor units: $199.90 MXN is 19990.

Input parameters:

- `dry_run` (boolean): Validate and show what would happen without changing anything.
- `product` (object, required)

### `media_add` (~77 tokens)

Add product image

Add an image to a product from a public URL or a local file path (max 5 MB). The first image is the one shown in listings.

Input parameters:

- `alt` (string)
- `file_path` (string): Absolute path to an image on this machine.
- `product_id` (string, required)
- `url` (string)

### `product_file_upload` (~102 tokens)

Attach file to digital product

Attach the file buyers receive to a digital variant, from a local path (max 10 MB). Buyers get a private, expiring download link by email after paying.

Input parameters:

- `download_limit` (integer): Max downloads per purchase; unlimited if omitted.
- `file_path` (string, required): Absolute path to the file on this machine.
- `link_ttl_hours` (integer): Hours the link stays valid (default 72).
- `variant_id` (string, required)

### `inventory_adjust` (~83 tokens)

Adjust stock

Add or remove stock for a variant with a reason (e.g. +20 "restock", -1 "damaged"). Cannot go below units reserved by open checkouts.

Input parameters:

- `delta` (integer, required)
- `dry_run` (boolean): Validate and show what would happen without changing anything.
- `reason` (string, required)
- `variant_id` (string, required)

### `orders_search` (~103 tokens)

Search orders

Find orders, e.g. to fulfill today: fulfillment_status "unfulfilled". q matches an order number (#1001) or a customer email.

Input parameters:

- `channel` (string)
- `cursor` (string)
- `from` (string)
- `fulfillment_status` (string)
- `limit` (integer)
- `payment_status` (string)
- `q` (string)
- `status` (string)
- `to` (string)

### `order_get` (~32 tokens)

Get order

Full order: items (snapshots), totals, payments, shipping address and timeline.

Input parameters:

- `id` (string, required)

### `order_action` (~236 tokens)

Act on an order

fulfill: mark items shipped with carrier/tracking (omit items to ship everything pending); cancel: cancel an unfulfilled or partially fulfilled order (restocks by default; needs confirm=true; refunding needs order_refund permissions); note: add an internal note; resend_notification: email the confirmation (or "order_shipped") again; payment_link: a link to pay the balance of a deposit order. Confirm cancellations with the owner first.

Input parameters:

- `action` (string, required)
- `carrier` (string)
- `confirm` (boolean): Must be true to cancel.
- `items` (array)
- `note` (string): Required for note.
- `notify_customer` (boolean)
- `order_id` (string, required)
- `reason` (string): Required for cancel.
- `refund` (boolean): cancel only: also refund what was paid (needs refunds:write).
- `restock` (boolean)
- `success_url` (string): payment_link only: where the customer lands after paying the balance.
- `template` (string)
- `tracking_number` (string)
- `tracking_url` (string)

### `service_setup` (~147 tokens)

Set up who delivers a service and when

Create or update a resource (a person, room or equipment) with weekly hours and the service products it delivers. Hours are local times in the store time zone unless `timezone` is given (weekday 0 = Sunday … 6 = Saturday). Optionally block days off with `closed`. Create the service product first with product_upsert (type "service", variants[].service.duration_min).

Input parameters:

- `closed` (array)
- `hours` (array)
- `kind` (string)
- `name` (string, required)
- `resource_id` (string): Update this resource; omit to create one.
- `service_product_ids` (array)
- `timezone` (string)

### `availability_get` (~75 tokens)

Free times for a service

Free start times for a service variant (next 14 days by default). Use it to verify the setup or to find a time to reschedule. Times are UTC instants; say them to the owner in `timezone`.

Input parameters:

- `from` (string)
- `to` (string)
- `variant_id` (string, required)

### `bookings_search` (~63 tokens)

Search appointments

Appointments in a date range (the agenda), e.g. today's for a resource. Defaults to the next 14 days.

Input parameters:

- `from` (string)
- `resource_id` (string)
- `status` (string)
- `to` (string)

### `booking_action` (~115 tokens)

Act on an appointment

complete, no_show, cancel (needs reason and confirm=true; refund=true also refunds the booked line and needs refunds:write) or reschedule (needs starts_at from availability_get). The customer is emailed on cancel and reschedule.

Input parameters:

- `action` (string, required)
- `booking_id` (string, required)
- `confirm` (boolean)
- `notify_customer` (boolean)
- `reason` (string)
- `refund` (boolean)
- `resource_id` (string)
- `starts_at` (string)

### `order_refund` (~122 tokens)

Refund an order

Refund all or part of an order through the payment provider. Moves real money in live mode: get explicit approval from the owner and pass confirm=true. Needs the refunds:write scope (agent tokens do not have it unless the owner granted it). Money is an integer in minor units: $199.90 MXN is 19990.

Input parameters:

- `amount` (integer): Minor units; omit to refund everything left.
- `confirm` (boolean, required)
- `notify_customer` (boolean)
- `order_id` (string, required)
- `reason` (string, required)

### `test_purchase` (~88 tokens)

Test purchase

Buy one active physical and one active digital product in payment TEST mode and report each step (cart, checkout, payment, order, delivery, email, download). Stock is restored afterwards. Run it after setting up the store and after any change to payments or products.

Input parameters:

- `email` (string): Where the test confirmation goes (default test-purchase@example.com).
- `variant_ids` (array)

### `products_import` (~161 tokens)

Import products from CSV

Import or update many products from a CSV: our template (title,price,sku,stock,status,type,option1 name,option1 value,image), Spanish headers (nombre,precio,existencias…) or a Shopify export. Rows with the same handle become variants; existing products (same handle) are updated and variants match by SKU; variants missing from the file are archived. Services are not imported (use product_upsert). Run with dry_run: true first and show the owner the summary and any row errors.

Input parameters:

- `csv` (string): CSV text, when there is no file.
- `dry_run` (boolean): Validate and show what would happen without changing anything.
- `file_path` (string): Absolute path to a .csv on this machine.

### `products_bulk` (~139 tokens)

Bulk product changes

Publish, unpublish (draft), archive or reprice many products at once. Prices: price.mode "percent" in basis points (-1000 = 10% off, 500 = 5% up), "amount" adds minor units (negative lowers), "set" sets the price. Price changes return a preview of old → new prices; only send confirm: true after the owner approves that preview. Money is an integer in minor units: $199.90 MXN is 19990.

Input parameters:

- `action` (string, required)
- `confirm` (boolean)
- `price` (object)
- `product_ids` (array, required)

### `order_create` (~148 tokens)

Record a manual order

Record a sale made outside the storefront (in person, WhatsApp, phone). payment.mode "paid" with method cash/spei/card/other when the money was already received: needs confirm: true after the owner checks the total. payment.mode "link" to get a Stripe payment link for the customer (the order waits as pending_payment and opens when paid). Stock is taken immediately; unit_price_amount overrides the price for this order only. Services must be booked from the storefront. Money is an integer in minor units: $199.90 MXN is 19990.

Input parameters:

- `dry_run` (boolean): Validate and show what would happen without changing anything.
- `order` (object, required)

### `webhook_setup` (~283 tokens)

Outbound webhooks

Send store events (orders, refunds, shipments, bookings, products) to another system such as an ERP, a sheet or an automation tool. action "list" shows endpoints and delivery health; "create" needs the webhooks:write scope (agent tokens do not have it unless the owner granted it) and confirm: true after the owner approved the URL and events, since customer and order data will be sent there; it returns the signing secret ONCE (give it to the owner to store in the receiving system, never print it again); "test" sends a signed webhook.test now; "delete" removes one. Receivers verify the Sellbase-Signature header: t=<unix>,v1=HMAC-SHA256(secret, "<t>.<body>"). Events: order.created, order.paid, order.deposit_paid, order.cancelled, payment.succeeded, refund.created, fulfillment.shipped, booking.rescheduled, booking.cancelled, product.created, product.updated, product.archived, inventory.oversold.

Input parameters:

- `action` (string, required)
- `confirm` (boolean): create only: true after the owner approved sending data to this URL.
- `description` (string)
- `events` (array): Empty or omitted = every event.
- `id` (string): Endpoint id for test and delete.
- `url` (string)

### `docs_search` (~61 tokens)

Search the Sellbase docs

Search guides, skills and the API reference bundled with Sellbase (e.g. "going live with Stripe", "shipping options", "refund scope"). Use it before guessing how a feature works.

Input parameters:

- `limit` (integer)
- `query` (string, required)

### `feedback_draft` (~215 tokens)

Draft feedback for the Sellbase maintainers

Use it when you find a Sellbase bug (unexpected error, wrong docs, a workaround you had to write), or when you build something on top of Sellbase that other stores would need (kind "extension"). Returns a redacted draft and a prefilled GitHub issue link. Nothing is sent: show the draft to the owner, ask if they want to share it, and give them the link to submit. Never include customer data, order contents, secrets or private code.

Input parameters:

- `agent` (string): Your name, e.g. "Claude Code".
- `area` (string)
- `details` (string): Error code/message/hint, tool output, doctor output (redacted automatically).
- `expected` (string)
- `kind` (string, required)
- `steps` (string)
- `summary` (string, required): What happened, or what the store needed.
- `title` (string, required)
- `workaround` (string): For extensions and bugs: what you built or changed to get around it.

### `storefront_scaffold` (~139 tokens)

Plan the storefront

Given what the owner wants to sell (e.g. "tienda de playeras", "agenda de citas para mi consultorio", "vender un curso"), returns which storefront components to add (React) or which <sellbase-*> elements to place (any other site, framework "web"), suggested pages and next steps. Run the command in the project, then follow the add-storefront skill.

Input parameters:

- `framework` (string): react: Next.js or Vite + React. web: any other site (plain HTML, WordPress, Vue, Astro…) using <sellbase-*> web components.
- `intent` (string, required)

### `collection_upsert` (~99 tokens)

Create or update collection

Group products (e.g. "Lo más vendido", "Regalos"). Send id to update. product_ids replaces the products in that order; omit it to keep them. The storefront filters with ?collection=<slug>. Use delete: true with id to remove the collection (products are kept).

Input parameters:

- `collection` (object)
- `delete` (object)
- `dry_run` (boolean): Validate and show what would happen without changing anything.

### `discount_upsert` (~125 tokens)

Create or update discount

Discount codes and automatic discounts. kind "percent": value in basis points (1000 = 10%). kind "fixed": value in minor units. kind "free_shipping": value 0. code null = automatic (applies without a code). Codes are uppercase. Send id to update (every field is replaced). Call without discount to list the current ones. Money is an integer in minor units: $199.90 MXN is 19990.

Input parameters:

- `discount` (object)
- `dry_run` (boolean): Validate and show what would happen without changing anything.

### `customers_search` (~64 tokens)

Search customers

Find customers by email, name or phone, with orders count and total spent. Pass id for one customer with addresses, orders and appointments.

Input parameters:

- `cursor` (string)
- `id` (string)
- `limit` (integer)
- `q` (string)

### `report_summary` (~49 tokens)

Sales summary

Sales today, last 7 and 30 days (paid minus refunded), daily series, top products, orders waiting to ship and appointments today. Use it to answer "how is the store doing?".

## Diagnostics

Captured diagnostic sections: Provenance, Dependencies. The full working is on the page: https://verifymcp.io/servers/jlgavel011-sellbase/sellbase#diagnostics

## Score history

- 2026-10-05: 77
- 2026-10-04: 77
- 2026-10-03: 77
- 2026-10-02: 77
- 2026-10-01: 77
- 2026-09-30: 77
- 2026-09-29: 77
- 2026-09-28: 62

## Common questions

### What is the Sellbase MCP server?

Sellbase is an MCP server listed in the public MCP registry as io.github.jlgavel011/sellbase. Open source commerce in your own Supabase: catalog, checkout, orders and bookings, run by your AI. This page covers its npm package (sellbase).

### Is the Sellbase MCP server safe to use?

Sellbase scores 77 out of 100 on VerifyMCP. We found no known CVEs affecting it as of 5 October 2026. It declares no install or post-install scripts. Its build provenance is signed and verified. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.

### What tools does the Sellbase MCP server expose?

Sellbase exposes 31 tools: store_status, store_update_settings, integration_connect, payments_live_check, integration_test, and 26 more. Their descriptions and schemas cost roughly 3,425 tokens of context every time the server is loaded.

### Is the Sellbase MCP server still maintained?

Sellbase is still listed as active in the MCP registry. We last reached this channel on 5 October 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.

### What licence is the Sellbase MCP server under?

Sellbase declares the MIT licence, which is OSI-approved. That covers the source only, and says nothing about the cost of any service it calls.

## Links

- npm package: https://www.npmjs.com/package/sellbase
- Socket report: https://socket.dev/npm/package/sellbase
- Repository: https://github.com/jlgavel011/sellbase
- Website: https://jlgavel011.github.io/sellbase/
- Changelog RSS feed: https://verifymcp.io/servers/jlgavel011-sellbase/sellbase.xml
- Changelog JSON feed: https://verifymcp.io/servers/jlgavel011-sellbase/sellbase.json
- HTML version of this page: https://verifymcp.io/servers/jlgavel011-sellbase/sellbase
