Tiny (Olist Tiny)
Tiny (Olist Tiny) e-commerce ERP, one of the most used by online stores and marketplace sellers in B
- 0.1.0
- Version
- remote
- Transport
- 20
- Tools
Security review
Review passedReviewed Jan 1, 2000.
- tools: 20 tools scanned
- metadata: scanned
No findings.
Tools (20)
tiny_list_accounts
Lista as empresas (CNPJ) Tiny conectadas a este install — id, label.
tiny_list_products
Pesquisa produtos (produtos.pesquisa.php). Paginado. Use `search` pra buscar por nome/código e `filters` (JSON) pra situacao, idCategoria, etc.
tiny_get_product
Detalha um produto pelo `id` (produto.obter.php). Bulk support: accepts ids for batched execution.
tiny_get_product_stock
Saldo de estoque de um produto pelo `id` (produto.obter.estoque.php). Bulk support: accepts ids for batched execution.
tiny_list_orders
Pesquisa pedidos de venda (pedidos.pesquisa.php). Paginado. `filters` (JSON) aceita dataInicial/dataFinal (DD/MM/AAAA), situacao, numeroPedido, nomeCliente, cpf_cnpj etc.
tiny_get_order
Detalha um pedido pelo `id` (pedido.obter.php). Bulk support: accepts ids for batched execution.
tiny_list_contacts
Pesquisa contatos (contatos.pesquisa.php). Paginado. `search` busca por nome; `filters` (JSON) aceita cpf_cnpj, situacao, idVendedor etc.
tiny_get_contact
Detalha um contato pelo `id` (contato.obter.php). Bulk support: accepts ids for batched execution.
tiny_create_contact
Cadastra um contato (cliente/fornecedor) — contato.incluir.php. `data` é um JSON string com os campos do contato conforme a doc oficial (comuns: nome, tipoPessoa 'F'|'J', cpf_cnpj, email, fone, endereco, cidade, uf, cep). Doc: tiny.com.br/api-docs (contato.incluir).
tiny_list_invoices
Pesquisa notas fiscais (notas.fiscais.pesquisa.php). Paginado. `filters` (JSON) aceita dataInicial/dataFinal (DD/MM/AAAA), situacao, numeroNota, cpf_cnpj etc.
tiny_get_invoice
Detalha uma nota fiscal pelo `id` (nota.fiscal.obter.php). Bulk support: accepts ids for batched execution.
tiny_list_payables
Lista contas a pagar (contas.pagar.pesquisa.php). Paginado. `filters` (JSON) aceita dataInicial/dataFinal (DD/MM/AAAA), situacao (aberto/pago), nomeCliente etc. Pareia com o Banco MCP na conciliação.
tiny_list_receivables
Lista contas a receber (contas.receber.pesquisa.php). Paginado. `filters` (JSON) aceita dataInicial/dataFinal (DD/MM/AAAA), situacao (aberto/recebido), nomeCliente etc.
tiny_list_sellers
Pesquisa vendedores (vendedores.pesquisa.php). Paginado. `search` busca por nome.
show_version
Show the current MCP platform and adapter versions.
report_bug
Report a bug, missing feature, or send feedback. Include the conversation array with recent messages for reproduction.
connect
Returns connection status and URLs. When all providers are connected, returns authenticated:true and empty pending[]. When credentials are missing, returns connect_url for the toolkit and per-install URLs.
toolkit_info
Returns the current toolkit state: installed MCPs, their connection status, the accounts connected to each one, and how many catalog tools each exposes.
marketplace
The official mcp.ai marketplace — the in-platform catalog of every MCP/tool, AND the way to run them. Covers capability requests like "find an MCP that does X", "consulta um CPF", "is there a tool for Y". Core flow: action=search discovers MCPs by intent → describe returns one MCP's full profile (every tool with its id + params, pricing, auth) so you pick the right tool_id → invoke RUNS that tool. KEY: invoke works even when the MCP is NOT installed — it runs the tool pontualmente (one-off), without adding the MCP to the toolkit and without bloating the tool list. If the MCP needs a credential/login, invoke returns a connect link; if it is paid and the wallet is empty, invoke returns a checkout/top-up link (the user opens it, then you retry). Use install only to make an MCP PERMANENT in the active toolkit (its tools then show up natively in future sessions); prefer invoke for a single/occasional use. list_tools lists what is callable right now. subscribe/cancel handle per-MCP billing;
authenticate
MCP.AI for IDE agents (Cursor, etc.): log in in the browser, copy the access token. Best: add it to this server's config as a header `Authorization: Bearer <token>` for a permanent, non-expiring connection. Or paste it here for a session-only login: call with { token: "<jwt>" } after the user pastes, or with no args to get the link.