The full upstream README, mirrored here for reference. Install config, tool schemas, adoption signals, and an original overview live on the 222wcnm Bilistalkermcp listing page.
BiliStalkerMCP is a Bilibili MCP server and command-line tool built on Model Context Protocol (MCP), designed for AI agents that need to analyze a specific Bilibili user or creator.
It is optimized for workflows that start from a target uid or username, then retrieve that user's profile, videos, dynamics, articles, subtitles, and followings with structured tools.
If you are searching for a Bilibili MCP server, a Bilibili Model Context Protocol server, or an MCP server for tracking and analyzing a specific Bilibili user, this repository is designed for that use case.
English | 中文说明
Copy and send the following to Claude Code, Codex, or other AI agents:
Configuration paths and syntax may vary across different clients.
Then replace /path/to/BiliStalkerMCP below with your actual absolute path:
Prefer
uv run --directory ...for faster local updates when PyPI release propagation is delayed. You can still useuvx bili-stalker-mcpfor quick one-off usage.
Auth: Provide
SESSDATAdirectly, or put it inBILI_COOKIE_FILE. Obtain it from Browser DevTools (F12) > Application > Cookies >.bilibili.com.
From this checkout, use the CLI to query any of the 12 tools without configuring an MCP client or starting a persistent server:
tools lists names and descriptions; tools TOOL returns the full MCP schema,
including required arguments, defaults, and limits. call TOOL accepts the same
names and JSON arguments as the MCP tools. IDs declared as strings in the schema
must remain quoted, including numeric UIDs and long article/dynamic IDs.
doctor prints JSON diagnostics for credential sources, refresh configuration,
proxy settings, and dependency versions. By default it does not use the network,
change credential files, or print credential values. doctor --network adds a TCP
connectivity check; it does not verify login or an API response.
For larger arguments or to avoid shell quoting issues, read a UTF-8 JSON file or pipe a JSON object through stdin:
Set the environment variables below in the calling shell, for example
$env:BILI_COOKIE_FILE = 'D:\BiliStalkerSecrets\bili-cookie.txt' in PowerShell.
An MCP client's env configuration is not automatically inherited by a separate
terminal. The CLI uses the same credential, refresh, proxy, and rate-limit behavior
as MCP. Help, version, and tool discovery do not require login credentials.
If the checkout already has a .env file, load it explicitly for the command;
neither the CLI nor a plain uv run automatically loads it:
Successful queries write one UTF-8 JSON value to stdout; logs and errors go to
stderr. Redirect stdout to save a result. Exit codes are 0 for success, 1 for
query/configuration failures (including an unhealthy doctor report), 2 for
invalid commands or arguments, and 130 for interruption. Query and argument
failures end with a JSON error object on stderr; risk-control errors
retain code and retry_after. A snapshot can succeed with incomplete
sections: inspect its errors field before interpreting it.
uv run python -m bili_stalker_mcp ... accepts the same arguments. With an
installed package, use bili-stalker-mcp ... directly. Running without a subcommand
still starts the MCP stdio server; bili-stalker-mcp serve makes that explicit.
| Key | Req | Description |
|---|---|---|
SESSDATA | Conditional | Bilibili session token; required unless BILI_COOKIE_FILE provides it. |
BILI_JCT | No | CSRF protection token. |
BUVID3 | No | Hardware fingerprint (reduces rate-limiting risk). |
BILI_COOKIE_FILE | No | Path to a plain Cookie file. |
BILI_REFRESH_TOKEN_FILE | No | Path to the separate refresh-token file; never set the token through an environment variable. |
BILI_ENABLE_COOKIE_REFRESH | No | true enables safe automatic refresh; default: false. |
BILI_COOKIE_REFRESH_CHECK_INTERVAL_SECONDS | No | Refresh-check interval; default: 21600, minimum: 60. |
BILI_PROXY | No | Route all upstream requests (bilibili_api and the built-in HTTP clients) through this proxy. Recommended when the system proxy is not picked up automatically or DNS resolution for Bilibili hosts is unstable. If the proxy is unreachable at startup, the server falls back to direct connections and logs a warning. |
BILI_REQUEST_JITTER_MODE | No | Upstream jitter behavior: adaptive (default; sleeps only without a configured login or after recent 412/429/403), always, never. |
BILI_REQUEST_JITTER_MIN_MS / BILI_REQUEST_JITTER_MAX_MS | No | Jitter sleep range; default: 200–1200. |
BILI_REQUEST_JITTER_BUDGET_MS | No | Total jitter sleep allowed per tool call; default: 500. |
BILI_RISK_PRESSURE_WINDOW_SECONDS | No | How long a 412/429/403 keeps adaptive jitter engaged; default: 300. |
BILI_LOG_LEVEL | No | DEBUG, INFO (Default), WARNING. |
BILI_TIMEZONE | No | Output time zone for formatted timestamps (default: Asia/Shanghai). |
Automatic refresh is disabled by default. Enable it only when the Cookie file and
refresh-token file are existing, readable, writable regular files. The Cookie file
may contain only ordinary Cookie values (SESSDATA, bili_jct, buvid3,
buvid4, and DedeUserID); the refresh token belongs only in its own file.
When refresh is enabled, do not set SESSDATA, BILI_JCT, or DEDEUSERID in
the environment: those rotating values must come from the Cookie file so a restart
cannot reload stale credentials. BUVID3 and BUVID4 may still be provided through
the environment. Refresh checks are rate-limited, and concurrent MCP calls or server
processes sharing these files use one refresh lock. Pending confirmation is recovered
before another refresh. The .bili-cookie-refresh.lock sidecar may remain on disk
between runs.
For a quicker initial setup, copy the complete Cookie header value from a Bilibili
browser request and ac_time_value from Local Storage, then run:
For a PyPI-only invocation without cloning this repository:
The script hides both pasted values, refuses directories inside the repository and
existing credential files, and prints only a non-secret MCP env block. Do not
paste an entire cURL command: paste only the value after its cookie: header.
All verification commands use mocks and do not require Bilibili credentials:
| Tool | Capability | Parameters |
|---|---|---|
search_users | Lightweight user candidates with numeric UIDs | keyword, limit |
get_user_snapshot | One-call overview: profile + recent videos/dynamics/articles fetched concurrently | user_id_or_username, video_limit, dynamic_limit, article_limit (0 skips a section) |
get_user_info | Rich profile: level, official title, VIP, live room, ban status, following/follower, total video views/article views/likes (needs bili_jct) | user_id_or_username |
get_user_videos | Lightweight video list | user_id_or_username, page, limit |
search_user_videos | Keyword search in one user's video list | user_id_or_username, keyword, page, limit |
get_video_detail | Full video detail + optional subtitles | bvid, fetch_subtitles (default: false), subtitle_mode (smart/full/minimal), subtitle_lang (default: auto), subtitle_max_chars |
get_user_dynamics | Structured dynamics with image metadata and cursor pagination | user_id_or_username, cursor, limit, dynamic_type |
get_user_articles | Lightweight article list | user_id_or_username, page, limit |
get_article_content | Full article markdown content | article_id |
get_user_followings | Subscription list analysis | user_id_or_username, page, limit |
get_content_comments | Comments for a video, article, or dynamic (including images and note metadata) | content_type, content_id, cursor, limit, sort |
get_content_comment_replies | Full sub-replies for a video, article, or dynamic comment | content_type, content_id, root_rpid, page, limit |
When starting from a username, call search_users once and reuse the returned numeric
UID for subsequent tools. Implicit username resolution accepts exact matches only; it
does not silently select the first similar search result.
Comment pictures contain the original image URLs. Regular long comments retain the
full text returned by Bilibili. Note-style comments may contain only a preview; use
the returned note.cvid with get_article_content to retrieve the full note.
For video comments, pass content_type="video" and a BVID, AV number, or video URL
as content_id. Use a top-level comment's rpid as root_rpid when fetching its
complete reply thread.
dynamic_type)ALL (default): Text, Draw, Reposts, and Video dynamics.ALL_RAW: Unfiltered (additionally includes Articles and unknown types).VIDEO, ARTICLE, DRAW, TEXT: Specific category filtering.REVIEW: Recognized five-slot rating cards only. Each result exposes
review.rating (filled stars, 0-5), review.title, review.text, cover and
jump URLs, plus the source score description when available. This filter does
not independently classify whether the rated title is an anime.Each dynamic item includes an images list. Every image contains url, width,
and height; invalid URLs are omitted, and unavailable dimensions are null.
image_count always equals the number of returned images. Reposts expose the same
fields under origin.images and origin.image_count. Non-image dynamics return
an empty images list.
Pagination: Responses include next_cursor. Pass this to subsequent requests for seamless scrolling.
get_video_detail)smart (default when fetch_subtitles=true): fetch metadata for all pages, download only one best-matched subtitle track text.full: download text for all subtitle tracks (higher cost).minimal: skip subtitle metadata and subtitle text fetching.subtitle_lang can force a language (for example en-US); auto uses built-in priority fallback.
subtitle_max_chars caps returned subtitle text size to avoid token explosion.
Subtitle text is returned once via full_text; tracks carry metadata only
(text is always empty). In full mode with multiple tracks, each segment in
full_text is prefixed with a [language · part] label.
The repository ships a ready-to-use AI agent skill in skills/bili-content-analysis/:
Guides compatible AI agents (Gemini, Claude, etc.) through a structured 6-step workflow for deep Bilibili content analysis using MCP tools or the CLI:
Copy the bili-content-analysis folder into your project's skill directory:
The agent will automatically activate the skill when user requests involve Bilibili creator tracking, transcript interpretation, timeline reconstruction, or content analysis.
Credentials: The release script uses
UV_PUBLISH_TOKENwhen set; otherwise it reads the matching[pypi]or[testpypi]token from$HOME\.pypirc. Twine is invoked transiently throughuvxonly for package metadata validation and is not a project dependency.
Runs via stdio transport. No ports exposed.
SESSDATA or provide BUVID3.BILI_PROXY. bilibili_api's curl_cffi client ignores system and environment proxies unless an explicit proxy is set.bilibili-api-python is pinned to ==17.4.2. Its upstream repository has been
permanently shut down following a legal notice from Bilibili, so no further
maintenance or fixes can be expected from that project. Additionally, the
package is licensed GPL-3.0-or-later, which means its source cannot be
vendored or forked into this MIT-licensed repository.
The mitigation path is incremental migration of the remaining SDK-backed
endpoints (user info, video lists, subtitles in video details, dynamics, articles)
onto this project's own raw HTTP stack (SharedRawHttpClient), which already
serves comments, followings, relation stats, and video details without subtitles
independently of the SDK. The pin
should be kept exact so installs never pick up an unknown future version.
MIT
Disclaimer: For personal research and learning only. Bulk profiling, harassment, or commercial surveillance is prohibited.
This project is built and maintained with the help of AI.