Enables AI agents to manage products, inventory, collections, orders, and customers in a Medusa v2 store via the Admin API.
Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.
Install from
M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.
Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.
@modelcontextprotocol/sdk has cross-client data leak via shared server/transport instance reuse
Anthropic's MCP TypeScript SDK has a ReDoS vulnerability
Model Context Protocol (MCP) TypeScript SDK does not enable DNS rebinding protection by default
process.env. You'll be asked to provide them before it can run.MCP_AUTH_TOKEN— token (). It refuses to start without one.MEDUSA_ADMIN_API_KEY— Copy the printed token into in .env, then delete theMEDUSA_ADMIN_EMAIL— Option B — Email + password. Just set andMEDUSA_ADMIN_PASSWORD— in .env and leave MEDUSA_ADMIN_API_KEY empty. TheMEDUSA_BACKEND_URL— Open .env. is already filled in. You need adminOAUTH_JWT_SECRET— 64+ random hex chars: node -e "console.log(require('crypto').randomBytes(48).toString('hex'))">OWNER_PASSWORD— a password you'll type to approve access>PORT— ( is injected by Railway automatically.)PUBLIC_URL— is auto-detected from Railway's RAILWAY_PUBLIC_DOMAIN. The static[](https://m8ven.ai/mcp/oumaru894-timelib-mcp-1y0673)