The full upstream README, mirrored here for reference. Install config, tool schemas, adoption signals, and an original overview live on the VK MCP Server listing page.
Model Context Protocol (MCP) server for VKontakte (VK) — the largest social network in Russia and CIS countries.
This server allows AI assistants (Claude, Cursor, Windsurf, VS Code, etc.) to interact with VK through a standardized MCP interface.
VK_MCP_MODE=all; safe defaults expose a smaller subset) — users, wall, groups, friends, photos, videos, messages, market, stats, stories, polls, and moreads, secure).env support — load token from environment file for local developmentThe VK API schema is downloaded automatically on the first run. No manual steps needed.
Create a .env file in the project root:
Or get a token from:
Required permissions depend on your use case:
wall — posting and reading wallphotos — uploading photosgroups — community managementfriends, messages, market, stats — as neededSecurity: Never commit your token to git. The
.envfile is already in.gitignore.
Instead of manually configuring sections and methods, use a built-in profile via VK_MCP_PROFILE:
| Profile | Mode | Description | Warning |
|---|---|---|---|
minimal | read | Essential read methods | Safe |
social | read | Users, friends + extras | Safe |
content_read | read | ~25 content viewing methods | Safe |
content_publish | all | ~20 content creation methods | Can publish |
community_manager | all | Wall, board, groups management | Can modify communities |
messenger | all | Messages + user info | Requires messages scope |
analytics | read | Stats, wall, groups insights | Safe |
money | money | All financially sensitive methods allowed by money-mode filtering | Financially sensitive |
ads | money | Ads API + helper methods | Can spend money |
market | money | VK Market + upload helpers | Can modify shop |
commerce | money | Market, orders, store, gifts, donut | Financially sensitive |
search | read | ~10 search methods | Safe |
full_read | read | All read methods except ads/secure | Safe |
full | all | All VK API methods | Development only |
Profiles can be extended with environment variables:
Env extends profile: list variables (sections, methods, excludes) are merged with the profile; scalar
modeis overridden by env.
Create .vscode/mcp.json:
For local development from a cloned repository, use:
Create .cursor/mcp.json:
Edit claude_desktop_config.json:
~/Library/Application Support/Claude/claude_desktop_config.json%APPDATA%/Claude/claude_desktop_config.json~/.config/Claude/claude_desktop_config.jsonFor local development from a cloned repository, use:
Use the stdio transport and provide VK_ACCESS_TOKEN via environment variables.
By default, the server uses stdio transport for local MCP clients. To enable remote connections, switch to HTTP:
VK_MCP_TRANSPORT | Use case |
|---|---|
stdio (default) | Claude Desktop, Cursor, VS Code, Windsurf |
http | Grok, ChatGPT, remote MCP clients |
sse | Same as http (both endpoints enabled) |
| Variable | Default | Description |
|---|---|---|
VK_ACCESS_TOKEN | (required) | Your VK API access token |
VK_MCP_PROFILE | — | Built-in profile name (minimal, social, full, etc.) |
VK_MCP_MODE | read | read — read-only, write — non-financial writes, money — financially sensitive, all — everything |
VK_MCP_INCLUDE_SECTIONS | — | Comma-separated whitelist of API sections. Without a profile, safe subset (users, groups, wall, friends, photos) is used |
VK_MCP_EXCLUDE_SECTIONS | ads,secure,market,orders,store,gifts,donut,votes (without profile / without explicit includes) | Comma-separated blacklist of API sections. Skipped when VK_MCP_INCLUDE_SECTIONS or VK_MCP_INCLUDE_METHODS is set |
VK_MCP_INCLUDE_METHODS | — | Comma-separated whitelist of methods (e.g., users.get,wall.get) |
VK_MCP_EXCLUDE_METHODS | — | Comma-separated blacklist of methods |
VK_MCP_MAX_TOOLS | — | Limit the number of exposed tools |
VK_MCP_TRANSPORT | stdio | Transport type: stdio, http, or sse |
VK_MCP_PORT | 3000 | HTTP port (falls back to $PORT for PaaS like Render) |
VK_MCP_HOST | 127.0.0.1 | Bind address. Use 0.0.0.0 for public hosts |
VK_MCP_AUTH_TOKEN | — | Bearer token for HTTP transport auth (required when binding to non-loopback) |
The server automatically classifies each VK API method into risk levels:
| Mode | Description | Sections |
|---|---|---|
read | Read-only methods | Safe subset: users, groups, wall, friends, photos |
write | Read + non-financial writes | Can modify your account (post, edit, delete, send, etc.) |
money | Financially sensitive only | ads, market, orders, store, gifts, donut, votes, selected secure.* |
all | Everything | Read + write + money — no restrictions |
get*, search*, is*, are*, check*, resolve*, find*, count*, lookup*, list*secure.getAppBalance, etc.)Use VK_MCP_MODE=read to prevent the AI from making any changes to your VK account.
Use VK_MCP_MODE=money when you need ads, market, or payment-related tools.
With npm/npx:
With a cloned repository:
For full MCP protocol testing, use the MCP Inspector:
Then select:
Streamable HTTP is session-based. A raw tools/list request must be sent only after an initialize request and with the returned Mcp-Session-Id header.
In the Inspector UI select Streamable HTTP and enter http://127.0.0.1:3000/mcp.
| Category | Examples | Count |
|---|---|---|
| Wall | vk_wall_get, vk_wall_post, vk_wall_edit, vk_wall_delete, vk_wall_search | 10+ |
| Users | vk_users_get, vk_users_search, vk_users_get_followers | 5+ |
| Groups | vk_groups_get, vk_groups_get_members, vk_groups_search, vk_groups_join | 20+ |
| Photos | vk_photos_get, vk_photos_get_upload_server, vk_photos_save | 15+ |
| Videos | vk_video_get, vk_video_search, vk_video_save | 10+ |
| Messages | vk_messages_get_history, vk_messages_get_conversations, vk_messages_send | 20+ |
| Friends | vk_friends_get, vk_friends_get_online, vk_friends_add | 10+ |
| Market | vk_market_get, vk_market_search, vk_market_get_orders | 10+ |
| Stories | vk_stories_get, vk_stories_get_upload_server | 5+ |
| Polls | vk_polls_create, vk_polls_get_by_id, vk_polls_add_vote | 5+ |
| Stats | vk_stats_get, vk_stats_get_post_reach | 2+ |
| Ads | vk_ads_get_campaigns, vk_ads_get_ads, vk_ads_get_statistics | 15+ |
| + 60 more sections | docs, notes, board, fave, notifications, pages, storage, etc. | — |
Total: 180+ tools auto-generated from the official VK API schema.
For Render, Railway, Fly.io, or similar PaaS:
Render note: Render provides the port via the
$PORTenvironment variable. The server automatically falls back to it whenVK_MCP_PORTis not set.
Note: The published npm package includes runtime files only (
src/,README.md,LICENSE,server.json). Tests and development files are kept in the GitHub repository.
The VK API schema is not included in this repository to keep it lightweight. On the first run (server or tests), it is downloaded automatically from the official VK repository:
The schema is saved to vk-api-schema/ in the project root and cached for subsequent runs.
To get the latest VK API changes, delete the cached folder and restart:
.env or your MCP client's secure environment variables. Never commit tokens.VK_MCP_MODE=read if the AI only needs to read data.ads, secure if not needed.127.0.0.1 only. If you bind to 0.0.0.0 (public), VK_MCP_AUTH_TOKEN is required — the server will refuse to start without it. Always use HTTPS in production.| Issue | Solution |
|---|---|
VK_ACCESS_TOKEN is required | Create .env file or set the environment variable |
Unknown tool | Check that the method name uses snake_case (vk_wall_get not vk.wall.get) |
Access denied | Your token lacks the required VK permission scope |
| Too many tools | Use VK_MCP_INCLUDE_SECTIONS or VK_MCP_MODE=read to filter |
HTTP Not Acceptable | Add header Accept: application/json, text/event-stream |
HTTP VK_MCP_AUTH_TOKEN is required | Set auth token when binding to 0.0.0.0 |
MIT
Pull requests are welcome! Please open an issue first to discuss major changes.
Made for the Model Context Protocol ecosystem