The full upstream README, mirrored here for reference. Install config, tool schemas, adoption signals, and an original overview live on the Voila Sdk listing page.
Voila MCP is a Model Context Protocol server for safe personal Voila grocery automation. It exposes small, auditable tools for product search, category browsing, discounts, delivery slots, cart deltas, and completed order history without exposing checkout or order placement.
Published on npm as @firfi/voila-mcp. The repository also includes @firfi/voila-sdk and @firfi/voila-cli.
packages/voila-sdk: @firfi/voila-sdk, the TypeScript SDK for Voila sessions, search, categories, cart, order history, slots, and checkout-readiness helpers.packages/voila-mcp: @firfi/voila-mcp, a stdio MCP server exposing small auditable tools.packages/voila-cli: @firfi/voila-cli, a user CLI that reuses the MCP operation registry.The root package is private. Publishable packages live under packages/.
Voila does not publish a documented third-party customer API. This server uses the same same-origin JSON endpoints as the web app, so authenticated use is session-based. Capture a session interactively with the CLI; do not store a Voila password in MCP config.
If the session is missing, expired, or guest-only, tool results include authGuidance with the exact CLI login command to run. The MCP server itself does not launch a browser. A login performed while the server is running takes effect on its next tool call, without a restart.
With an explicit VOILA_AUTH_SESSION_PATH and guest mode off, the MCP server
also runs a read-only authenticated-session keepalive. Set VOILA_KEEPALIVE=0
to disable it; VOILA_KEEPALIVE_INTERVAL_SECONDS defaults to 86400 seconds
and must be at least 3600. The keepalive never bootstraps a guest and stops
as misconfigured if its configured session snapshot disappears.
voila_check_session_health: report active, guest, expired, or retryable session state.voila_get_active_shopping_context: read current region, destination, delivery method, and cart context.voila_get_slot_listings: list delivery slots for an explicit destination and region.voila_reserve_slot: reserve a caller-selected slot only with explicit confirmation flags.voila_search_products: search products for the current session context.voila_get_category_products: fetch products for a Voila category id.voila_get_discounted_products: scan promotions and return meaningful discounted products.voila_get_completed_orders: read completed orders with cursor pagination.voila_get_order_details: read item-level details for one completed order.voila_get_completed_order_items: aggregate previously ordered items across completed orders.voila_get_cart: read active cart totals, limited items, unavailable data, and pricing notices.voila_add_cart_items: add quantity deltas using Voila product UUIDs.voila_remove_cart_items: remove quantity deltas using Voila product UUIDs.The server does not expose checkout or order-placement tools. Cart mutations use quantity deltas and return server notices for limited, unavailable, and pricing-change cases.
Stdio is the default for local MCP clients:
HTTP is available for registry inspection and deployments behind a trusted gateway:
The HTTP endpoint is /mcp unless MCP_HTTP_PATH is set. VOILA_GUEST=1 forces guest-session behavior for safe introspection environments such as Glama. Do not expose HTTP with a real session file directly to the public internet; put authentication and access control in front of /mcp.
The CLI default session path is ~/.config/voila/session.json. Browser login uses a persistent Playwright profile at ~/.cache/voila/browser-profile unless --profile is provided; log in manually and close the browser window to save.
Live endpoint smoke tests remain opt-in. Do not run live cart mutation tests against a real account unless the test cleans up and the caller explicitly asks for it.