CCM
/MCP
SkillsMCPMarketplacesDigestToolsAdvertise

This week in Claude

Every Monday: Claude Code, Agent SDK, MCP, and the Anthropic platform moves worth your time.

Skills by Category
Frontend DevelopmentBackend & APIsTesting & QASecurityDevOps & CI/CDGit & Pull RequestsDocumentationCode Review & QualityAI & Agent BuildingSkill Development
MCP Servers by Category
Sales & MarketingWeb & Browser AutomationDatabasesAI & LLM ToolsCloud & InfrastructureCommunication & MessagingDeveloper ToolsDesign & CreativeDocuments & KnowledgeSearch & Web Crawling
Marketplaces by Category
AI Agents & OrchestrationLLM IntegrationDevelopment ToolsFrontend & UIBackend & APIsDatabasesTesting & Code QualityDevOps & CloudSecurity & ComplianceGit & Version Control

Claude Code Marketplaces

Discover Claude Code plugins, extensions, and tools. Automatically updated directory of Anthropic Claude AI marketplaces with development tools, productivity plugins, and integrations.

Resources

  • Browse Skills
  • Browse MCP Servers
  • Browse Marketplaces
  • Skill index
  • MCP index
  • Marketplace index
  • Plugins Reference

Community

  • About
  • Tools
  • Feedback
  • Privacy Policy
  • Advertise

Built for the Claude Code community with Claude Code by mertbuilds.com

Independent project, not affiliated with Anthropic
basic-bit avatar

VRChat MCP

basic-bit/vrchat-mcp
2STDIOregistry active
Summary

Connects Claude to VRChat's API for managing your social graph, tracking worlds and events, and querying local VRCX history. Exposes curated tools for common tasks like checking friend status, searching worlds, sending invites, and booping, plus generated read/write routers that cover the full API surface. Runs locally via stdio with auth cookies stored in your OS keychain. Write operations are enabled by default but gated through your MCP client's approval flow. Includes safety guardrails like group ID allowlists and rate limit backoff. Useful when you want to automate VRChat social workflows or pull instance data into an LLM conversation without leaving your editor.

CodeRabbit
CodeRabbit
AI writes the code. CodeRabbit catches the slop.
Try For Free →
ego lite browserego lite browser
ego lite browser
Fastest browser for AI agents to run web automation tasks, always free.
Download Free life-time →
Granola, the best AI meeting recorder
Granola, the best AI meeting recorder
Notes, actions and memory. Without a meeting bot. First month 100% off.
Download for free →
CodeHealth MCP ServerCodeHealth MCP Server
CodeHealth MCP Server
Protect your code quality, stop the AI slop.
Try For Free →
belt - the only tool your agent needs
belt - the only tool your agent needs
belt cli automatically finds the best tools and skills for your agent. image, video, music, tts...
one prompt install →
AppSignal
AppSignal
Monitor with ease. Code with confidence.
Start Free Trial →
Agent, connect blockchain
Agent, connect blockchain
Connect your Claude agent to live crypto prices and trading routes via 1inch
Get the MCP →
Block distraction from your iPhone for freeBlock distraction from your iPhone for free
Block distraction from your iPhone for free
Block distracting apps from your iPhone permanently without a 3rd party app. Free and open source.
Block now (100% free) →
CodeRabbit
CodeRabbit
AI writes the code. CodeRabbit catches the slop.
Try For Free →
ego lite browserego lite browser
ego lite browser
Fastest browser for AI agents to run web automation tasks, always free.
Download Free life-time →
Granola, the best AI meeting recorder
Granola, the best AI meeting recorder
Notes, actions and memory. Without a meeting bot. First month 100% off.
Download for free →
CodeHealth MCP ServerCodeHealth MCP Server
CodeHealth MCP Server
Protect your code quality, stop the AI slop.
Try For Free →
belt - the only tool your agent needs
belt - the only tool your agent needs
belt cli automatically finds the best tools and skills for your agent. image, video, music, tts...
one prompt install →
AppSignal
AppSignal
Monitor with ease. Code with confidence.
Start Free Trial →
Agent, connect blockchain
Agent, connect blockchain
Connect your Claude agent to live crypto prices and trading routes via 1inch
Get the MCP →
Block distraction from your iPhone for freeBlock distraction from your iPhone for free
Block distraction from your iPhone for free
Block distracting apps from your iPhone permanently without a 3rd party app. Free and open source.
Block now (100% free) →

VRChat MCP logo

VRChat MCP

Unofficial local Model Context Protocol tools for VRChat friends, worlds, groups, events, notifications, status, invites, and local VRCX history.

npm license

VRChat MCP runs locally through stdio by default and also offers an opt-in loopback-only Streamable HTTP mode. Your VRChat auth cookies stay on your machine and default to your OS keychain, with file storage as the fallback when a keychain backend is unavailable. Curated write tools, generated read/write tools, and read-only VRCX local-history tools are available by default; use your MCP client or agent harness to approve account-changing tool calls.

This project is unofficial and is not affiliated with VRChat Inc.

Policy and Safety Boundaries

VRChat does not provide a public OAuth flow for third-party API applications. VRChat's Creator Guidelines say API applications should not request or store VRChat login credentials, auth tokens, or session data, should identify themselves with a clear User-Agent, should cache/back off instead of sending unmetered requests, and should not act on behalf of another user.

This project is therefore intended only as a local, user-controlled personal tool. Do not run it as a hosted/public MCP service, do not collect anyone else's credentials or cookies, do not automate spam or harassment, and do not use it to evade VRChat enforcement or moderation. Use write tools only for actions you would intentionally perform yourself in VRChat.

Install

Requirements:

  • Node.js 24.15.0 or newer.
  • An MCP client that can run local stdio servers.
  • Native dependencies are installed for keychain and VRCX SQLite support (keytar, better-sqlite3).

On headless Linux or containers without a keychain daemon such as libsecret, set VRCHAT_MCP_COOKIE_STORE=file for explicit persistent cookie storage.

The npm package is the normal install path:

npx -y @basicbit/vrchat-mcp

The server is also published to the official MCP Registry as io.github.BASIC-BIT/vrchat-mcp.

MCP Client Config

Most clients use one of these shapes. No environment variables are required for the default setup.

OpenCode

OpenCode uses an array-valued command field.

Add this to ~/.config/opencode/opencode.json:

{
  "mcp": {
    "vrchat": {
      "type": "local",
      "command": ["npx", "-y", "@basicbit/vrchat-mcp"],
      "enabled": true
    }
  }
}

Claude Desktop, Cursor, Kiro, Roo, Windsurf

These clients usually split the executable into command plus args.

Use this in clients that expect an mcpServers object:

{
  "mcpServers": {
    "vrchat": {
      "command": "npx",
      "args": ["-y", "@basicbit/vrchat-mcp"]
    }
  }
}

VS Code

VS Code uses a servers object instead of mcpServers.

Use this in .vscode/mcp.json:

{
  "servers": {
    "vrchat": {
      "type": "stdio",
      "command": "npx",
      "args": ["-y", "@basicbit/vrchat-mcp"]
    }
  }
}

OpenAI Codex

Add this to ~/.codex/config.toml or .codex/config.toml:

[mcp_servers.vrchat]
command = "npx"
args = ["-y", "@basicbit/vrchat-mcp"]
startup_timeout_sec = 40

If your Windows client cannot spawn npx directly, use cmd as the command and put /c, npx, -y, and @basicbit/vrchat-mcp in the argument list.

Local Streamable HTTP

Use native Streamable HTTP when an MCP client needs to connect to a long-running local server instead of spawning its own stdio child process. STDIO remains the default and recommended setup for ordinary desktop clients.

HTTP mode:

  • Binds only to 127.0.0.1.
  • Uses the MCP endpoint http://127.0.0.1:8765/mcp by default.
  • Requires Authorization: Bearer <token> on every MCP request.
  • Supports stateful sessions, SSE notifications, resource subscriptions, and session termination.
  • Reaps abandoned sessions after 30 minutes of inactivity while preserving active response streams.
  • Shares one local VRChat login, cache, and pipeline connection across all connected HTTP clients.
  • Is not a hosted or multi-user mode.

Generate a secret and launch the server in PowerShell:

$env:VRCHAT_MCP_HTTP_BEARER_TOKEN = node -e "console.log(require('node:crypto').randomBytes(32).toString('hex'))"
npx -y @basicbit/vrchat-mcp --transport http

Then configure the MCP client to use http://127.0.0.1:8765/mcp and send the token from VRCHAT_MCP_HTTP_BEARER_TOKEN as a bearer token. Keep the token in an environment variable or secret store; do not put it in a URL or commit it to a client configuration.

CLI overrides:

npx -y @basicbit/vrchat-mcp --transport http --port 9000 --path /vrchat-mcp

The HTTP listener deliberately cannot bind to a LAN or public interface. Public hosting remains unsupported because VRChat does not provide the OAuth/account-isolation model needed for a hosted personal-account service.

Login

After adding the server to your MCP client, ask it to call vrchat_auth_begin. The tool returns a local browser login URL.

After logging in, call vrchat_auth_status to confirm the session. By default, cookies are stored in the OS keychain so the login survives MCP server restarts. If the OS keychain is unavailable, VRChat MCP falls back to file storage.

Do not ask another person to use this login flow for you. Do not send the local login URL, cookies, or session files to hosted tools or third-party services.

Useful auth tools:

  • vrchat_auth_begin: start local browser login.
  • vrchat_auth_status: check whether the server is logged in.
  • vrchat_auth_logout: clear the stored session.

Headless Login for Bot Accounts

Browser login needs a person. VRChat's twoFactorAuth cookie lasts 30 days, and changing an account's 2FA method revokes its session immediately, so an unattended deployment would otherwise need someone to log in again each time. For an account you own and operate with authenticator (TOTP) 2FA, such as a dedicated bot account, the server can log itself back in.

Set all three variables to turn it on. If any of them is missing or empty, nothing changes.

VariableUse
VRCHAT_MCP_USERNAMEVRChat username or email.
VRCHAT_MCP_PASSWORDVRChat password.
VRCHAT_MCP_TOTP_SECRETBase32 authenticator secret. VRChat's space-grouped lowercase form is accepted too.

When a VRChat API request returns 401, the server logs in once with the password and a freshly generated TOTP code, saves the new cookies to the configured cookie store, and retries the request once. If VRChat asks for an email code instead of TOTP, the server submits no code and returns the normal 401 error with a note to use vrchat_auth_begin. VRChat only reveals the 2FA method after the password step, so that still counts as a failed attempt for the backoff below.

Automatic logins are rate limited, and the limit is persisted so it holds when the host spawns a fresh server process for every call:

  • At most one automatic attempt every 10 minutes.
  • After a failed attempt (wrong password, rejected code, VRChat error) no automatic attempt for 60 minutes. An attempt that never recorded an outcome, for example because the process was killed mid-login, counts as failed.
  • While in cooldown, the tool error says so and gives the time of the next allowed attempt.
  • The record is <cookie file>.autologin.json (mode 0600), beside the configured cookie file path. Keychain storage uses the same path. A short-lived .lock file stops two processes from claiming the same attempt. If the record cannot be written, the server does not try to log in.
  • With VRCHAT_MCP_COOKIE_STORE=memory there is no file, so the limit lives in memory and only applies within one process. That is much weaker: with a process per call, every process would log in. Use file storage for headless deployments.

The password, TOTP secret, generated codes, and cookie values are never logged or included in tool results or errors. vrchat_auth_logout still clears the session, but while the variables are set the next API call logs back in.

Some MCP hosts, OpenClaw included, replace the child environment with the server entry's env block instead of merging it into their own. Do not put the password or TOTP secret inline in the host config. Keep them in a root-owned env file with mode 0600 and point the host at a small wrapper script that loads the file and execs the server. The host must run the wrapper as a user that can read the file. Quote values that contain shell metacharacters. If the host's env block does not pass PATH, set it in the wrapper or use absolute paths.

#!/bin/sh
# /usr/local/bin/vrchat-mcp-bot
set -a
. /etc/vrchat-mcp/bot.env
set +a
exec vrchat-mcp "$@"
# /etc/vrchat-mcp/bot.env (owner root, mode 0600)
VRCHAT_MCP_COOKIE_STORE=file
VRCHAT_MCP_COOKIE_FILE=/var/lib/vrchat-mcp/cookies.json
VRCHAT_MCP_USERNAME='bot-account'
VRCHAT_MCP_PASSWORD='...'
VRCHAT_MCP_TOTP_SECRET='abcd efgh ijkl mnop qrst uvwx yz23 4567'

What You Can Ask

Examples:

Show my VRChat status and current location.
Which friends are online, grouped by world?
Search my friends for Alice and show their profile.
Find public VRChat events happening today.
Invite Bob to my current instance.
Show recent worlds from my local VRCX history.

Tools

VRChat MCP exposes curated tools plus generated read/write/delete routers by default. Curated tools cover common tasks with compact, agent-friendly inputs and outputs.

Common curated tools include:

  • vrchat_me
  • vrchat_friends_overview
  • vrchat_friends_search
  • vrchat_friend_details
  • vrchat_worlds_search
  • vrchat_group_profile
  • vrchat_events_upcoming
  • vrchat_notifications_recent
  • vrchat_instance_link_event
  • vrchat_gallery_image_upload
  • vrchat_invite
  • vrchat_group_invite
  • vrchat_friend_request
  • vrchat_boop
  • vrcx_instances_recent

Generated OpenAPI API-gap coverage uses three router tools:

  • vrchat_read for available GET operations; pass operationId plus path/query/header/cookie values under params.
  • vrchat_write for available POST/PUT/PATCH operations; pass operationId, params, and JSON payloads under body.
  • vrchat_delete for available DELETE operations; pass operationId, params, and optional JSON payloads under body.

Use vrchat_operations to list available generated operation IDs and vrchat_operation_details for exact per-operation params/body schemas.

Generated read and write tools are enabled by default. VRCHAT_MCP_DISABLE_GENERATED_READ_TOOLS=true hides vrchat_read. VRCHAT_MCP_DISABLE_GENERATED_WRITE_TOOLS=true hides both vrchat_write and vrchat_delete, which share the generated-write switch. JSON config can also narrow either surface to specific operation IDs; generatedWriteTools.operationIds covers DELETE operations too, so a list holding only POST/PUT/PATCH IDs also hides vrchat_delete:

{
  "generatedReadTools": { "enabled": true, "operationIds": ["getAvatarStyles"] },
  "generatedWriteTools": { "enabled": true, "operationIds": ["selectAvatar"] }
}

When an operationIds list is empty and that generated tool class is enabled, all generated operations in that class are available through its router except hard-skipped operations and operations with curated replacements. Prefer curated tools for common workflows, but generated routers keep the local server capable as the VRChat API evolves without duplicating known curated coverage or exposing generated endpoints this client cannot reliably call.

See docs/tools-guide.md for a short guide and docs/tools.md for the generated catalog.

Write Controls

Curated write tools and generated write tools for API gaps are enabled by default so the local MCP server is usable from the first run. Your MCP client or agent harness is expected to control tool-call permission, approval, and denial for account-changing actions.

To force read-only mode, add this env fragment inside the server entry for your MCP client:

{
  "env": {
    "VRCHAT_MCP_ALLOW_WRITES": "false"
  }
}

Only use write tools when you intend this local MCP server to perform VRChat account actions. Bulk social tools are capped and back off on 429s, but you are responsible for avoiding spam, harassment, or unwanted automation.

vrchat_gallery_image_upload uploads a validated static PNG to the signed-in account's personal gallery. It accepts only imagePath; group authorization is enforced later by the group post or event tool that attaches the returned file ID. Configure at least one absolute uploads.allowedRoots entry before using it.

For group write tools, you can restrict writes to specific group IDs with a JSON config file:

{
  "groups": {
    "allowlist": ["grp_abc123"]
  }
}

Then set VRCHAT_MCP_CONFIG_FILE to that file path in your MCP client config.

Configuration

Configuration is optional. Defaults cover normal local use.

Common environment variables:

VariableUse
VRCHAT_MCP_CONFIG_FILEPath to a JSON config file.
VRCHAT_MCP_USER_AGENTDescriptive user agent for VRChat API requests.
VRCHAT_MCP_LOG_LEVELdebug, info, warn, or error.
VRCHAT_MCP_COOKIE_STOREkeychain, file, or memory. Defaults to keychain.
VRCHAT_MCP_COOKIE_FILECookie file path when VRCHAT_MCP_COOKIE_STORE=file.
VRCHAT_MCP_USERNAMEUsername for headless login.
VRCHAT_MCP_PASSWORDPassword for headless login.
VRCHAT_MCP_TOTP_SECRETBase32 TOTP secret for headless login.
VRCHAT_MCP_ALLOW_WRITESSet to false for read-only mode.
VRCHAT_MCP_UPLOAD_ROOTSAbsolute roots allowed for local PNG uploads.
VRCHAT_MCP_TRANSPORTstdio (default) or http.
VRCHAT_MCP_HTTP_BEARER_TOKENRequired 32+ character secret for HTTP mode.
VRCHAT_MCP_HTTP_PORTLoopback HTTP port. Defaults to 8765.
VRCHAT_MCP_HTTP_PATHMCP endpoint path. Defaults to /mcp.
VRCHAT_MCP_HTTP_MAX_SESSIONSMaximum concurrent HTTP sessions. Defaults to 8.
VRCHAT_MCP_HTTP_RATE_LIMIT_PER_MINUTEPer-client HTTP request limit. Defaults to 300.
VRCHAT_MCP_HTTP_SESSION_IDLE_TIMEOUT_MSAbandoned-session timeout. Defaults to 1800000.

Example JSON config:

{
  "auth": { "cookieStore": "file" },
  "writes": { "allow": false },
  "http": {
    "port": 8765,
    "path": "/mcp",
    "maxSessions": 8,
    "rateLimitPerMinute": 300,
    "sessionIdleTimeoutMs": 1800000
  },
  "groups": { "allowlist": ["grp_abc123"] },
  "uploads": { "allowedRoots": ["C:\\Users\\you\\Pictures\\VRChat Uploads"] },
  "cache": { "enabled": true },
  "vrcx": { "enabled": true }
}

See src/config/defaults.json for all defaults.

Local Development

git clone https://github.com/BASIC-BIT/vrchat-mcp.git
cd vrchat-mcp
npm install
npm run build
npm run check

Useful scripts:

  • npm run dev: run from src/index.ts.
  • npm run start: run the built server from dist/.
  • npm run dev -- --transport http: run the local Streamable HTTP server from source.
  • npm run start -- --transport http: run the built local Streamable HTTP server.
  • npm run mcp:login: start login through the local harness.
  • npm run mcp:status: check auth through the local harness.
  • npm run smoke:live: run the opt-in live smoke check.
  • npm run generate:tools-docs: regenerate docs/tools.md.
  • npm run generate:schemas: regenerate OpenAPI schemas.
  • npm run mcpb:build: build a local MCPB bundle under mcpb/.

Live E2E tests and LLM evals are opt-in. See docs/evals.md for details.

License

MIT. See LICENSE.

Featured
CodeRabbit
CodeRabbit
AI writes the code. CodeRabbit catches the slop.
Try For Free →
ego lite browserego lite browser
ego lite browser
Fastest browser for AI agents to run web automation tasks, always free.
Download Free life-time →
Granola, the best AI meeting recorder
Granola, the best AI meeting recorder
Notes, actions and memory. Without a meeting bot. First month 100% off.
Download for free →
CodeHealth MCP ServerCodeHealth MCP Server
CodeHealth MCP Server
Protect your code quality, stop the AI slop.
Try For Free →
belt - the only tool your agent needs
belt - the only tool your agent needs
belt cli automatically finds the best tools and skills for your agent. image, video, music, tts...
one prompt install →
AppSignal
AppSignal
Monitor with ease. Code with confidence.
Start Free Trial →
Agent, connect blockchain
Agent, connect blockchain
Connect your Claude agent to live crypto prices and trading routes via 1inch
Get the MCP →
Block distraction from your iPhone for freeBlock distraction from your iPhone for free
Block distraction from your iPhone for free
Block distracting apps from your iPhone permanently without a 3rd party app. Free and open source.
Block now (100% free) →

Configuration

VRCHAT_MCP_CONFIG_FILE

Path to a JSON config file for settings not supplied through environment variables.

VRCHAT_MCP_USER_AGENT

Descriptive User-Agent for VRChat API requests.

VRCHAT_MCP_LOG_LEVELdefault: info

Log level for stderr diagnostics.

VRCHAT_MCP_COOKIE_STOREdefault: keychain

Cookie storage backend for VRChat authentication. The keychain mode falls back to file storage if the OS keychain is unavailable.

VRCHAT_MCP_COOKIE_FILE

Cookie file path used when VRCHAT_MCP_COOKIE_STORE is file.

VRCHAT_MCP_ALLOW_WRITESdefault: true

Allow non-GET VRChat API write operations. Defaults to true for local full-capability use; set to false for read-only mode.

Registryactive
Package@basicbit/vrchat-mcp
TransportSTDIO
UpdatedJun 3, 2026
View on GitHub