- Python 99.6%
- Shell 0.4%
| Filename | Latest commit message | Latest commit date |
|---|---|---|
- Behavioral tests for the search and list_status_codes tools (matches, read-only exemption, bad arguments, per-model permission errors, unknown status class), the named-argument/filters conflict error, and unit tests for choice labels and build_query_params conflicts. - The two new tools join the exact-set visibility expectation: their views need only an authenticated identity (IsAuthenticatedOrReadScope). - Hand-written output schemas for both tools (their outputs are dynamic dicts with no serializer to introspect), satisfying the every-tool-has- a-schema guard. - The attachment tests assumed the is_image filter, which doesn't exist on 1.3.x cores (only is_link/is_file) - assert version-appropriate behavior instead of failing on older cores. Suite: 127 tests, all passing against InvenTree 1.3.5. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01GgxrJxsXeZVqVNhna1kqhF |
||
| .github/workflows | ||
| inventree_mcp | ||
| .gitignore | ||
| .pre-commit-config.yaml | ||
| AGENTS.md | ||
| biome.json | ||
| codecov.yml | ||
| LICENSE | ||
| MANIFEST.in | ||
| pyproject.toml | ||
| README.md | ||
| run_tests.sh | ||
| setup.cfg | ||
InvenTreeMCP
An MCP (Model Context Protocol) server for InvenTree, exposed as an InvenTree plugin. It lets MCP clients (Claude, other MCP-aware agents) query InvenTree inventory data over a Streamable HTTP endpoint.
Design
Every tool is a thin wrapper around InvenTree's own REST API view classes (see
inventree_mcp/proxy.py), dispatched as the authenticated caller - MCP
requests go through exactly the same permission checks, filtering, and serialization as the regular
REST API. Tool code never queries the Django ORM directly.
Currently read-only, covering parts, stock items/locations, part categories, purchase/sales/return/
build orders (with line items and allocations), companies, contacts, addresses, manufacturer/
supplier parts, BOM items, attachments, parameters, stock tracking history, test results, and
project codes. Once write tools land, the MCP_READ_ONLY setting (see Configuration) will block
them by default regardless of the calling user's permissions.
Each tool's outputSchema and filter/ordering options are derived live from InvenTree's own
serializers and views (not hand-maintained), so they can't drift as InvenTree evolves. Call
describe_filters(resource) to see what's available for a given resource. The set of tools an MCP
client sees is also filtered to what the calling user can actually use - though every call is still
permission-checked in full regardless of what was advertised.
Setup
1. Install the plugin
Install via the InvenTree plugin manager, or via pip:
pip install inventree-mcp
Then enable the plugin under Admin > Plugins, and configure its settings (see Configuration below).
2. Create a token for your MCP client
Create an InvenTree API token for your MCP client.
3. Configure your MCP client
The endpoint is <your-inventree-server>/plugin/inventree-mcp/mcp/, using Streamable HTTP
transport with an Authorization: Token <token> header.
For a client that supports remote Streamable HTTP servers directly, add:
{
"mcpServers": {
"inventree": {
"url": "https://<your-inventree-server>/plugin/inventree-mcp/mcp/",
"headers": {
"Authorization": "Token <your-api-token>"
}
}
}
}
For a client that only supports local (stdio) servers, bridge it with
mcp-remote:
{
"mcpServers": {
"inventree": {
"command": "npx",
"args": [
"mcp-remote",
"https://<your-inventree-server>/plugin/inventree-mcp/mcp/",
"--header",
"Authorization: Token <your-api-token>"
]
}
}
}
Configuration
Under Settings > Plugin Settings:
- Require Authentication (
REQUIRE_AUTH, defaultTrue): reject unauthenticated requests. Only disable for local testing. - Read Only (
MCP_READ_ONLY, defaultTrue): block all write actions via MCP, regardless of the calling user's permissions. A plugin-wide kill switch, independent of per-user roles.
Authentication
Access follows the calling user's normal InvenTree role assignments. Supported auth methods:
- An InvenTree API token:
Authorization: Token <token>. - Basic auth (username/password).
- An OAuth2 bearer token:
Authorization: Bearer <token>. A scoped token (e.g.r:view:part) narrows access below the underlying user's roles - useful for issuing an agent a tightly-scoped token without creating a separate low-privilege user.
Session/cookie auth is not supported (not meaningful for a machine client).