MCP and agent skill
Availability
Section titled “Availability”The stdio MCP adapter and installable skill are implemented and tested locally.
They are not yet public npm releases, and there is no hosted MCP/OAuth endpoint.
Do not point an MCP client at the REST origin or invent an npx package name.
Production API access is a separate release step.
Install the supplied artifact
Section titled “Install the supplied artifact”Requirements: Node.js 22+ and an MCP host that supports stdio. Install the verified
archive from downloads. Read the manifest,
choose @csfolder/mcp, and verify the downloaded file’s SHA-256 and size before
installing. Downloads become public with this documentation deployment. The
checksum is not a signed release; use only the trusted documentation origin.
npm install --ignore-scripts /absolute/path/csfolder-mcp.tgzMaintainers can generate that archive with
pnpm --filter @csfolder/mcp pack --out /absolute/output/csfolder-mcp.tgz.
This installs the local file, not a similarly named registry package. The MCP
entrypoint is node_modules/@csfolder/mcp/dist/stdio.js.
Connect Codex
Section titled “Connect Codex”After explicitly choosing this integration, add this non-secret configuration to
the project’s .codex/config.toml or your existing Codex configuration. Replace
both paths with actual absolute paths; preserve other settings.
[mcp_servers.csfolder]command = "/absolute/path/to/node"args = ["/absolute/path/to/project/node_modules/@csfolder/mcp/dist/stdio.js"]env_vars = ["CSFOLDER_API_KEY"]startup_timeout_sec = 15tool_timeout_sec = 30Set CSFOLDER_API_KEY securely in the host environment before starting/restarting
the MCP connection. env_vars forwards its value without putting the secret in
this configuration. A project’s .env is not automatically loaded by the MCP
executable. Never paste the key into chat or CLI arguments. This uses Codex’s
documented stdio environment forwarding.
Other clients need their equivalent secure environment configuration.
Without a credential, discovery, prompts, resources and getStatus still work;
protected tools return invalid_api_key.
Try a bounded workflow
Section titled “Try a bounded workflow”Ask the agent:
Read csfolder://docs/integration and csfolder://openapi.Build my CS2 marketplace price comparison in the existing project.Use listItems to resolve exact item IDs, then getMarketPrices.Keep missing prices, unknown timestamps and asks/bids distinct.Use a server-side SDK route for the app, never expose the API key.Test empty data, pagination, 401 and 429. Do not deploy yet.The MCP prompt build_with_csfolder also accepts recipe:
market-comparison, openable-roi or portfolio, plus optional locale:
en (default) or ru.
Tool names match the JSON operation IDs. Example arguments:
{"query":{"q":"AK-47 | Redline","limit":5}}Pass that object to listItems, then use an actual returned item_id as
{"params":{"item_id":123}} for getMarketPrices; 123 is only a placeholder.
Private portfolios require a separate choice
Section titled “Private portfolios require a separate choice”By default, only 17 market/status tools are visible. To enable the five portfolio
tools, the owner must choose a personal csf_pat_ credential with access to selected
portfolios and set CSFOLDER_MCP_PORTFOLIOS=1 in the MCP process environment.
Retrieved private data enters the connected AI host/model. Enabling the tools
does not grant permission: the API still checks scopes, ownership, revocation and expiry.
Install the skill
Section titled “Install the skill”The package contains skill/csfolder-api/. Copy the whole directory from
node_modules/@csfolder/mcp/skill/csfolder-api/ into the consuming project’s
.agents/skills/csfolder-api/, or the host’s supported skill directory. Inspect an
existing destination before replacing it. No global configuration changes are needed.
Then ask: Use $csfolder-api to build my CS2 data integration in this project.
The skill can use MCP, a local OpenAPI artifact, or accessible documentation. It
does not issue a key, consent to private access, or authorize deployment for you.
Budgets and large datasets
Section titled “Budgets and large datasets”Each tool makes at most one HTTP request: no implicit retries or automatic next page. Default page size is 25, maximum 100; at most four calls run concurrently. The default deadline is 15 seconds. Oversized responses fail explicitly (128 KiB HTTP input, 256 KiB complete tool result), rather than returning a misleading partial result. Preserve cursors and use bounded date windows. Honor quota errors.
For the complete market matrix, use the SDK and streaming snapshot guide in a backend job. MCP deliberately does not place a full export in model context, write files or execute shell commands.
Protocol and synthetic-data integration tests prove tool interoperability, not that any arbitrary product can be completed by one prompt or that production has already been deployed.