Wallapop MCP Server
Wallapop MCP Server
Wallapop マーケットプレイス向けのハイブリッド型・非公式 MCP サーバー。TypeScript で構築されています。
HTTP プライマリ: 非公開の
api.wallapop.comv3 エンドポイントへのリバースエンジニアリングによる呼び出しSSR フォールバック:
es.wallapop.comページの__NEXT_DATA__スクレイピング(商品詳細、出品者プロフィール)Playwright フォールバック: 最終手段としてオフスクリーンのヘッド付きブラウザを使用(Wallapop の CDN がヘッドレス Chrome をブロックするため)
認証: お気に入り、保存した検索、チャット、オファー用に、任意のメールアドレス/パスワードまたはブラウザ Cookie のインポート(トークン更新 + セッション永続化)
非公式であり、Wallapop とは無関係です。Wallapop の非公開 API を使用しています。この API はいつでも変更されたり、トラフィックをブロックしたりする可能性があります。自己責任で使用し、リクエスト量を抑え、Wallapop の利用規約を尊重してください。
ツール
ツール | 認証 | 説明 |
| – | カテゴリ / 価格 / 場所 / 半径 / 並び順フィルターによるキーワード検索、カーソルページネーション( |
| – | 重複排除、価格フィルタリング、詐欺フラグ付きの複数クエリキーワードスキャン(配送可能な出品) |
| – | 出品の完全な詳細: 説明、状態、価格、画像、閲覧数、お気に入り数、出品者、配送情報 |
| – | ID または Web スラッグによる出品者プロフィール: 評価(0〜100)、販売数/公開数、登録日、所在地 |
| – | ID 付きのマーケットプレイスカテゴリツリー |
| – | ヘルス / 認証 / ブラウザフォールバックのステータス |
| 必須 | 数値 ID、Web スラッグ、または商品 URL によるお気に入り登録/解除(API + ブラウザフォールバック) |
| 必須 | 保存した検索アラート |
| 必須 | チャットの受信トレイ: 相手ユーザー、商品、未読数、最後のメッセージ |
| 必須 | 会話の完全なメッセージ履歴 |
| 必須 | チャットメッセージを送信(リアルタイムチャネル) |
| 必須 | 購入オファーを送信(EUR)— 出品者はチャットで受け取り、承認/拒否できます |
Related MCP server: Bazos-MCP
クイックスタート
git clone <this-repo>
cd WallpopMCP
npm install
npm run build
cp .env.example .env # fill in your keys (see Configuration)
npm run smoke # live sanity check against the APIMCP クライアントに接続する
# Claude Code (stdio)
claude mcp add wallapop -- node /absolute/path/to/WallpopMCP/dist/index.js# Inspector (browse tools interactively)
npm run inspector設定(.env、.env.example を参照)
変数 | 目的 |
| 認証ツールを有効にする(お気に入り、保存した検索、チャット、オファー) |
| ログイン済みセッションからエクスポートしたブラウザ Cookie の任意の JSON 配列( |
| デフォルトの検索場所(バルセロナ中心部) |
| トークン/Cookie の永続化(デフォルト |
| API 呼び出し間の最小遅延(デフォルト 600) |
| 検索結果の上限、1〜200(デフォルト 200) |
|
|
注:
WALLAPOP_EMAIL/WALLAPOP_PASSWORDは、MFA または Keycloak フローを使用するアカウントでは失敗する可能性があります。その場合は、ログイン済みブラウザからWALLAPOP_COOKIES_FILEに Cookie をエクスポート(Cookie オブジェクトの JSON 配列)すると、サーバーはそれらを直接使用します。
仕組み
検索(2 段階 API フロー)
GET /api/v3/search/components→search_idGET /api/v3/search/section(40 件/ページ)→meta.next_pageJWT。サーバーはsearch_id+ カーソルを不透明なnextPageトークンにパックし、クライアントはそれをそのまま返すだけです。
チャットとオファー
メッセージはリアルタイムチャネル(PubNub)経由で送信され、インボックス API(
/bff/messaging/inbox)にも届きます。両方ともエンドツーエンドで検証済みです。オファーはクライアント生成のオファー ID を使用して
POST /api/v3/delivery/buyer/offersで作成され、出品者は会話内でそれを受け取ります。
認証
POST /api/v3/access/loginを試行し、アクセス/リフレッシュトークン + Cookie をセッションファイルに保存します。JWT の有効期限が近づくとPOST /api/v3/access/refreshで更新します。自動ブラウザログインにフォールバックします。MFA チャレンジは検出され、エラーとして表示されます(手動で完了させ、その後
WALLAPOP_COOKIES_FILEに Cookie をエクスポートしてください)。
フォールバックチェーン
ブラウザ風ヘッダー、UA ローテーション、429 での指数バックオフ、403 での
X-Signatureリトライを使用した API リクエストSSR HTML スクレイピング(
es.wallapop.com/item/...、/user/...)— 出品者にとってより豊富なデータ(評価、カウンター)Playwright 経由のオフスクリーンのヘッド付き Chrome(
api.wallapop.comの XHR レスポンスをキャプチャ)— Wallapop の CDN がヘッドレスモードをブロックするため、手動でブラウザをダウンロードせずにWALLAPOP_BROWSER=chromiumを使用しないでください。autoはインストール済みの Chrome/Edge を優先します。
注意点と既知の制限
search_productsの価格フィルタリング(minPrice/maxPrice)と半径フィルタリング(distance_in_km)は API 側のパラメータです。favorite_listing/unfavorite_listingはベストエフォートのエンドポイント候補を使用します。自分のアカウントで検証してください。エンドポイントは変更される可能性があります。商品の
conditionはget_listing経由でのみ確実に取得できます(検索結果では通常省略されます)。一部の出品者はオファーを無効にしています。その場合、
make_offerは 409 エラーを返します。
Available Tools
6 toolsget_listingGet full listing detailsA
Get detailed information about a single Wallapop listing: description, condition, price, images, location, views, favorites, seller id, shipping options. Accepts the numeric listing id, a web slug, or a full item URL. Falls back to server-side rendering when the API fails.
| Name | Required | Description | Default |
|---|---|---|---|
| itemId | Yes | Listing id (numeric string), web slug, or full item URL |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations, the description carries the burden of disclosing behavior. It adds a useful behavioral detail: 'Falls back to server-side rendering when the API fails,' which is beyond the schema. However, it does not explicitly state that this is a read-only operation (though 'get' implies it) or mention any side effects, rate limits, or authentication requirements. The fallback is a positive addition, but coverage remains moderate.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is two sentences, front-loaded with the core purpose and then quickly covering input variations and fallback behavior. Every sentence adds value with no repetition or fluff. It is appropriately sized for the tool's simplicity.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Given the low complexity (single parameter, no output schema), the description is nearly complete. It lists the returned data fields, specifies accepted input formats, and mentions a fallback mechanism. It doesn't cover error cases or example responses, but for a straightforward fetch operation, this is sufficient. Slight deduction for not explicitly stating what happens on not-found or invalid input.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema description coverage is 100%, so the parameter `itemId` is fully described in the schema as 'Listing id (numeric string), web slug, or full item URL.' The description simply repeats this information ('Accepts the numeric listing id, a web slug, or a full item URL') without adding new semantics. Baseline for high coverage is 3, and no extra value is provided beyond the schema.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states the tool's purpose: 'Get detailed information about a single Wallapop listing' and enumerates the specific fields (description, condition, price, images, etc.). This distinguishes it from siblings like get_seller, which focuses on seller data, and search_products, which is for searching. The verb 'get' and resource 'listing' are unambiguous.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description implies when to use this tool (when you need details of a single listing) and even provides flexible input formats (numeric id, slug, or URL). It does not explicitly exclude alternatives or mention when NOT to use it, but the context from sibling names and the clear purpose give sufficient guidance. The fallback note also hints at reliability handling.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
get_sellerGet seller informationA
Get a Wallapop seller profile by numeric user id (from a listing) or by web slug (e.g. 'sergiof-462579195'): rating, review count, sold/published counts, registration date, location.
| Name | Required | Description | Default |
|---|---|---|---|
| reference | Yes | Seller numeric id or web slug |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
Since no annotations are provided, the description carries the burden of explaining behavior. It clearly states the output fields (rating, review count, etc.) and the two accepted input formats Dropdown. It does not mention errors or side effects, but for a get operation, this is adequate.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is a single sentence that packs all essential info: what, how, and what you get. No fluff.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Provides clear input and output details, but lacks any error handling or edge cases; still complete for typical usage.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
The single parameter 'reference' is described in both the schema and the description, specifying it can be a numeric id or web slug, which is fully unambiguous.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states the tool gets a Wallapop seller profile using a numeric user id or web slug, and lists the specific fields returned (rating, counts, dates, location). This is specific to the seller resource and clearly differentiates from siblings like get_listing and search_products.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description explains the input format (numeric id or slug) and what to expect from the output, giving clear context for when to use this tool. It does not explicitly mention alternatives or when not to use it, but the scope is clearly defined.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
list_categoriesList Wallapop categoriesA
List all marketplace top-level categories with ids and subcategories.
| Name | Required | Description | Default |
|---|---|---|---|
No parameters | |||
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations, the description carries the burden of behavioral disclosure. It states that it returns top-level categories with ids and subcategories, indicating a read-only operationhol, but it doesn't describe the exact structure or any potential variations, which is a minor gap.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is a single concise sentence that efficiently conveys the tool's purpose. It loses a point for not being front-loaded with the action, but it's clear and to the point.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Given that the tool has no parameters, no output schema, and the description provides a clear indication of what is returned (categories with ids and subcategories), the description is adequate. It could have mentioned whether the subcategories are nested or a flat list, but the description's level of detail is sufficient for an agent to use the tool correctly.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
The schema has zero parameters, and the schema coverage is 100%, so there are no parameters, and the description adds that it's a simple read operation. Since there are no parameters, the description explains the return format (ids and subcategories, which is the purpose, but it might be a simple operation. This is a simple read-only and the description. This is a simple read-only, but I'm not the memory of the context, but the schema covers all the 0 parameters and the description is clear, but it is a simple description. The description doesn't need to explain parameters beyond that, and it doesn't add much beyond the schema, but the schema itself is empty, so the description is the main source of parameter semantics, which it handles by describing what the tool returns, but not in terms of parameters. With 0 parameters, the baseline is 4 because there are no parameter details to provide, but the description could have mentioned the output format or usage. The description does state the output includes ids and subcategories, which is helpful for the agent knowing what to expect, so a 4 is appropriate.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states the tool lists all marketplace top-level categories with ids and subcategories, which is specific and distinguishes it from the sibling tools (search_products, get_listing, etc.).
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description implies that this tool is used to obtain the full category tree, which is useful before searching or scanning. It doesn't explicitly mention when not to use it, but the purpose is clear in the context of the other tools.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
scan_productsScan multiple searches for phone candidatesA
Runs several keyword searches (default nationwide radius) and dedupes results, keeping only in-range, shippable listings and flagging suspicious ones (scam wording or book-slug retitled listings). Returns compact candidate list, ready for get_listing/verify.
| Name | Required | Description | Default |
|---|---|---|---|
| queries | Yes | Keyword/price-range combos to scan (deduped across queries) | |
| distanceKm | No | Search radius in km (default 1500 = all Spain) | |
| maxResultsPerQuery | No | Max results per query (default 200) |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations provided, the description carries the behavioral burden and does a good job: it discloses deduplication, default nationwide radius, filtering to in-range/shippable listings, and suspicious-item flagging. It does not explicitly state that no data is modified, but 'scan' and 'returns compact candidate list' strongly imply a read-only pipeline.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
Two dense sentences cover the entire behavior without wasted words. The description is front-loaded with the core action and then provides filtering details and the downstream purpose.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Given the tool's moderate complexity, no annotations, and no output schema, the description is complete enough: it states input behavior, filtering logic, output type, and downstream usage. It does not detail edge cases, but the essential context for selecting and invoking the tool is present.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema coverage is 100%, so the schema already documents all parameters. The description adds modest value by explaining the default nationwide radius and the purpose of deduplication, which aligns with the queries array, but it does not add meaningful syntax or format details beyond the schema.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description uses a specific verb and resource: 'Runs several keyword searches' for phone candidates, and clearly distinguishes itself from a basic search by mentioning deduplication and filtering. It also differentiates from siblings by explicitly stating the output is ready for get_listing/verify.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description implies when to use this tool: when multiple keyword/price searches are needed and results should be deduped and filtered into a candidate list. It names downstream tools (get_listing/verify) but does not explicitly contrast with search_products or state when not to use it.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
search_productsSearch Wallapop listingsA
Search Wallapop for products with optional filters: category, price range, location (latitude/longitude), radius, sort order. Paginate with the nextPage cursor returned. Reserved listings are filtered out. Returns up to maxResults listings (default 40, capped at 200).
| Name | Required | Description | Default |
|---|---|---|---|
| orderBy | No | Sort order | |
| keywords | Yes | Search keywords, e.g. 'iphone 15 pro' | |
| latitude | No | Search origin latitude (defaults to Barcelona center) | |
| maxPrice | No | Maximum price in EUR | |
| minPrice | No | Minimum price in EUR | |
| nextPage | No | Opaque pagination cursor from a previous search call | |
| longitude | No | Search origin longitude (defaults to Barcelona center) | |
| categoryId | No | Restrict to a category, see list_categories | |
| distanceKm | No | Search radius in km | |
| maxResults | No | Max results to return (default 40, capped 200) |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations, the description carries the burden. It discloses that reserved listings are filtered out and that results are limited to maxResults (default 40, cap 200). It does not state whether the operation is read-only or mention authentication/rate limits, but for a search tool this is largely implicit. Slight deduction for missing explicit read-only declaration.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is concise, consisting of two sentences that efficiently list filters, pagination, reserved-listings behavior, and result limits. No redundancy or unnecessary detail; well-structured for quick understanding.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
Despite having 10 parameters, the description, combined with the schema, covers all essential aspects: how to search (filters), pagination (nextPage cursor), data handling (reserved listings filtered out), and result limits. It does not mention error handling or authentication, but for a search tool these are typically standard and not required for completeness. The description is sufficient for a developer to use the tool effectively.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
The schema already provides clear descriptions for each parameter (e.g., latitude defaults to Barcelona center, maxPrice in EUR). The tool description adds context by grouping them as 'optional filters' and noting pagination via nextPage, but does not significantly expand on individual parameter meanings. Since schema coverage is 100% and descriptions are self-explanatory, the added value is moderate.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states the tool searches Wallapop for products with optional filters, using the specific verb 'Search' and resource 'Wallapop products'. It distinguishes from sibling tools like get_listing (single item) and scan_products (likely broader scan) by focusing on filtered search.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description provides concrete usage guidance: mentions optional filters, pagination via nextPage cursor, reserved listings being filtered out, and maxResults default/cap. It does not explicitly differentiate from alternatives like scan_products, but the filter and pagination details give clear context for when to use this tool.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
server_statusGet MCP server health and auth statusA
Returns whether the server is configured for public or authenticated use, whether a session is loaded, and whether browser fallback is available.
| Name | Required | Description | Default |
|---|---|---|---|
No parameters | |||
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
No annotations are provided, so the description carries the full burden. It discloses what information is returned (config, session, browser fallback) but does not disclose any side effects, read-only nature, or operational details. As a status check, it is likely read-only, but this is not stated. There is no mention of whether it performs network calls, requires auth, or has any side effects.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is a single, concise sentence that efficiently lists the three key pieces of information returned. No waste; every clause adds value.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
While the description is adequate for a zero-parameter status tool, it does not provide any context about the response structure or how the status should be interpreted. For a health/auth status tool, an agent might benefit from knowing what 'browser fallback' means or how to act on the status, but the description meets the minimum viable level.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
The tool has zero parameters, which is fully disclosed by the empty schema. Since there are no parameters to describe, the description does not need to add parameter semantics. The baseline for 0 params is 4, and there is no missing information.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states what the tool does: returns server configuration status (public/authenticated), session load state, and browser fallback availability. It is specific about the resource (server status) and the information returned, distinguishing it from sibling tools which operate on products, listings, sellers, and categories.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
No guidance is provided on when to use this tool versus the sibling tools. It is implied that this is a diagnostic/utility tool, but the description does not explicitly state when an agent should check server status (e.g., before auth-dependent operations, to verify availability). The sibling tools are all product/catalog-related, so differentiation is clear, but the description lacks usage context.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
Tool Schema Changelog
Recent tool additions, removals, and schema changes observed during successful MCP inspections.
6 tool updates
v0.1.0- First observed
get_listing - First observed
get_seller - First observed
list_categories - First observed
scan_products - First observed
search_products - First observed
server_status
TDQS
Scored across 6 tools
Most tools are clearly distinct: search_products, get_listing, get_seller, list_categories, and server_status each target a different resource or action. The main ambiguity is between search_products and scan_products, though scan_products is clearly positioned as a specialized multi-keyword search with deduplication.
The naming pattern is largely consistent: search_products, get_listing, get_seller, list_categories, and scan_products all follow verb_noun naming. server_status breaks the pattern slightly by using a noun phrase instead of a get_ or status_ verb, but it is still readable and predictable.
Six tools is well-scoped for a marketplace browsing/searching MCP server. Each tool covers a meaningful capability without bloat, and the count feels appropriate for the server's purpose.
The core browsing flow is covered: search listings, get listing details, get seller profiles, and list categories. Minor gaps exist such as not being able to list a seller's active listings or perform authenticated actions, but those are not necessarily core to this server's stated scope.
Maintenance
Related MCP Connectors
Your own WhatsApp as an MCP server: read, search and send from any MCP client.
Official SerpApi MCP server for Google, Bing, and other search engines.
MCP server for Muovi, Argentina's trust-first local services marketplace: find pros, draft tasks.
Related MCP Servers
- AlicenseBqualityAmaintenanceMCP server for automating Xianyu (Goofish) marketplace operations: publish, manage items, handle IM messages, and more via CLI or AI agents.17259 PyPI297Apache 2.0
- AlicenseAqualityBmaintenanceMCP server for interacting with Bazos.cz, Bazos.sk, Bazos.at, and Bazos.pl. Supports searching ads, retrieving ad details, and fetching user ratings.3240 npm4AGPL 3.0
- AlicenseNot gradedqualityCmaintenanceAn MCP server for Vinted search and analysis that provides tools to search listings, fetch item details, inspect seller profiles, compare prices across countries, and surface trending items.116 npm17AGPL 3.0
- FlicenseBqualityDmaintenanceRead-only MCP server for WhatsApp Web allowing listing chats and reading recent messages, without sending or mutating WhatsApp state.312 npm-