wishlist-mcp
Hosted MCP server that lets Claude, ChatGPT, or Codex read and update a user's wishlist.fit wishlist on their behalf, with tool parity matching the web app's capabilities.
README
wishlist-mcp
The hosted MCP server for wishlist.fit. It lets Claude, ChatGPT, or Codex read and update your wishlist on your behalf.
https://mcp.wishlist.fit/mcp
Connect it from app.wishlist.fit/connect, which has per-client setup steps. You need a wishlist account first; this server never creates one.
docs/connecting.md has the longer version: exact commands for each client, what has actually been verified against production, and the two Codex flags that waste an afternoon if you get them wrong.
What it is
A pure OAuth 2.1 resource server in front of the wishlist REST API. It holds no database and no business rules. Visibility, rate limits, and invite handling all live in the wishlist API, and this server inherits them by calling that API with the user's own access token.
That split is deliberate. The alternative, a second service with its own copy of the rules, is how two surfaces quietly start disagreeing about who may see what.
Claude / ChatGPT / Codex
│ MCP over HTTP, bearer token
▼
this server ──── verifies the token (issuer + audience)
│
│ the same token, forwarded
▼
api.wishlist.fit ──── applies visibility, rate limits, invite rules
│
▼
Postgres
WorkOS AuthKit is the authorization server. This server issues nothing and shows no consent screen; it only verifies what AuthKit signed.
The tools
Fourteen, one per thing you can already do by hand in the web app. Parity is the rule: no agent-only privileges, and nothing the app itself cannot do.
| Tool | Kind |
|---|---|
wishlist_search_people |
read |
wishlist_get_gift_guide |
read |
wishlist_get_profile |
read |
wishlist_get_wishlist |
read |
wishlist_get_my_profile |
read |
wishlist_get_my_wishlist |
read |
wishlist_list_circle |
read |
wishlist_preview_invite |
read |
wishlist_add_item |
write |
wishlist_update_item |
write |
wishlist_update_my_profile |
write |
wishlist_accept_invite |
write |
wishlist_create_invite |
destructive |
wishlist_delete_item |
destructive |
wishlist_get_gift_guide returns a person's profile and wishlist together. It is the
reason anyone connects this server, and without it the gift-giver journey costs three
round trips.
The two destructive tools carry destructiveHint: true, so clients that confirm
irreversible actions will ask first. Sending an invite emails a real person and cannot be
unsent. Accepting one is reciprocal: the inviter gains access to your circle-only fields
as well as you gaining access to theirs.
One connection, everything
There are no scopes. WorkOS cannot express custom ones, so a connection carries the whole tool surface. Protection on writes is behavioural rather than structural: the annotations above, the tool descriptions, and the rate limits the API applies.
Running it locally
uv sync
cp .env.example .env # point it at a local API and the Local WorkOS environment
uv run python -m wishlist_mcp.main
uv run pytest
uv run ruff format --check . && uv run ruff check .
Tests stub the wishlist API with respx. What they check is this server's own job:
verifying tokens, shaping requests, and turning API errors into sentences a model can act
on. The rules themselves belong to the API and are tested there.
Configuration
Every variable is prefixed WISHLIST_MCP_. See .env.example.
| Variable | Purpose |
|---|---|
API_BASE_URL |
The wishlist REST API to call |
AUTHKIT_DOMAIN |
WorkOS AuthKit issuer. Empty means the server refuses to start |
RESOURCE_URI |
Canonical URI. Every token's audience must match it exactly |
HOST |
The server 404s on any other host |
API_TIMEOUT |
Seconds to wait on the API |
RESOURCE_URI must match the resource indicator configured in WorkOS character for
character, including the /mcp path. A mismatch is the most common reason a client
refuses to connect.
Things worth knowing before you change this
Each of these is a bug that reached production once.
get_http_headers()stripsauthorization. Ask for it explicitly. Without that, every tool call reports "no access token" whileinitializeandtools/liststill succeed, because those are answered before any tool body runs. A green handshake is not evidence the tools work.- The MCP app is mounted at the root and owns its own path. Mounting it at
/mcpmakes Starlette redirect/mcpto/mcp/, and the address every client is handed has no trailing slash. X-Forwarded-Protois trusted. Cloud Run terminates TLS, so without it every generated URL claimshttp://. Combined with the redirect above, that once meant a client would have sent its bearer token in the clear.- FastMCP's lifespan is chained into the app's. Mounting an ASGI app does not start its lifespan, and without it every tool call fails with "Task group is not initialized" while unit tests still pass.
TestClientfollows redirects by default. Passfollow_redirects=Falsewhen the point is that a path answers directly.- FastMCP matches
Acceptby substring. It answers406 Client must accept application/jsonto a client sending*/*, which already does, and to one sending no header at all, which under RFC 9110 also does.WildcardAcceptspells those out before FastMCP sees them. Plaincurlsends*/*, so this was the first thing anyone hit.
Deployment
Cloud Run, asia-southeast1, in the same project as the rest of wishlist. main deploys
on push. Infrastructure lives in wishlist-infrastructure.
Licence
MIT. See LICENSE.
推荐服务器
Baidu Map
百度地图核心API现已全面兼容MCP协议,是国内首家兼容MCP协议的地图服务商。
Playwright MCP Server
一个模型上下文协议服务器,它使大型语言模型能够通过结构化的可访问性快照与网页进行交互,而无需视觉模型或屏幕截图。
Magic Component Platform (MCP)
一个由人工智能驱动的工具,可以从自然语言描述生成现代化的用户界面组件,并与流行的集成开发环境(IDE)集成,从而简化用户界面开发流程。
Audiense Insights MCP Server
通过模型上下文协议启用与 Audiense Insights 账户的交互,从而促进营销洞察和受众数据的提取和分析,包括人口统计信息、行为和影响者互动。
VeyraX
一个单一的 MCP 工具,连接你所有喜爱的工具:Gmail、日历以及其他 40 多个工具。
graphlit-mcp-server
模型上下文协议 (MCP) 服务器实现了 MCP 客户端与 Graphlit 服务之间的集成。 除了网络爬取之外,还可以将任何内容(从 Slack 到 Gmail 再到播客订阅源)导入到 Graphlit 项目中,然后从 MCP 客户端检索相关内容。
Kagi MCP Server
一个 MCP 服务器,集成了 Kagi 搜索功能和 Claude AI,使 Claude 能够在回答需要最新信息的问题时执行实时网络搜索。
e2b-mcp-server
使用 MCP 通过 e2b 运行代码。
Neon MCP Server
用于与 Neon 管理 API 和数据库交互的 MCP 服务器
Exa MCP Server
模型上下文协议(MCP)服务器允许像 Claude 这样的 AI 助手使用 Exa AI 搜索 API 进行网络搜索。这种设置允许 AI 模型以安全和受控的方式获取实时的网络信息。