Peckish
Peckish is an AI-powered DoorDash ordering agent that integrates with Claude (terminal, web app, or MCP). It enables you to:
Discover: Search restaurants and non-restaurant stores (grocery, alcohol, etc.), fetch menus, look up store details, and find specific items or build grocery lists from a shopping list.
Manage Carts: Create and manage carts with customizations, add/remove items, and support group orders with shareable links and per-person spend limits.
Preview Orders: Get real-time authoritative totals including fees, tips, promos, credits, ETA, and payment method. Control options like priority/express delivery, scheduling, and opting out of DoorDash credits.
Place Orders: Submit after explicit human confirmation, specifying tip and card. Supports work benefits like budgets and expense codes. A browser checkout URL is available as fallback.
Handle Payments & Promos: List saved payment methods, apply or remove promo codes, and discover eligible promos for a store.
Manage Account: List and set default delivery addresses, switch between delivery and pickup, load session context (address, preferences, time) at the start.
Track Orders: View order history and itemized receipts, reorder with automatic detection of unavailable items, and check order status.
Save Preferences: Persist dietary rules, allergies, tipping defaults, and other habits across sessions.
Ensure Transparency: All tool calls and confirmations are logged; explicit human approval is always required before any charge.
Enables an AI ordering agent for DoorDash, allowing users to search restaurants, browse menus, manage carts, compare fee-included totals, and place orders with explicit user approval.
Peckish π
Feeling peckish? Just ask. An AI ordering agent for DoorDash β it searches,
compares real totals (fees included), builds the cart, and you approve every
order. Built on Claude and DoorDash's official
dd-cli.
One tool layer, three surfaces:
Surface | Start | Best for |
Terminal chat |
| Living in the terminal |
Local web app |
| Consumer-friendly UI: store cards, live quote, Stop button, order modal |
MCP server |
| Claude Desktop / Claude Code users β no API key needed; your Claude subscription powers the model |
Which one is for me?
Comfortable with a terminal? β Terminal chat. Fastest, most informative.
Want something that feels like an app? β Local web app. Cards, live quote, a proper Place-order button.
Already use Claude Desktop or Claude Code? β MCP server. No API key, no separate chat window β Claude itself becomes your ordering agent, and order confirmation appears as a native dialog.
Updates: every release ships with full notes, all artifacts, and a
SHA256SUMS.txt on Releases β
see CHANGELOG.md for the history. Watch the repo (Releases
only) to get notified.
Install in one line β no git clone:
npm install -g peckishPrefer an app? Download the Mac app (.dmg) β guided setup, no terminal at any step. See Mac app below. Everything runs on your own Mac either way, because DoorDash sign-in lives in your keychain.
you βΊ Find me a high-protein dinner under $25 that can arrive within 45
minutes. Avoid mushrooms and excessive fees.
β search_restaurants {"query":"grilled chicken bowls","limit":8} β 2.1s
β get_menu {"store_id":"35406455","filter":"chicken"} β 1.8s
β list_carts {"store_id":"35406455"} β 1.2s
β add_items_to_cart {β¦} β 2.4s
β preview_order {"cart_uuid":"β¦"} β 3.9s
Best fit: Sharon Korean Kitchen (4.8β
, ~24 min) β Grilled Chicken Bulgogi
Bowl, $16.95. No mushrooms listed. Total with fees: $21.40 on your Visa
ending 1234. Suggested Dasher tip is $3.50 β that, another amount, or none?
~$0.04 turn Β· $0.04 sessionGet started (user guide)
1. Prerequisites
A Mac with Apple Silicon (M1βM4). Peckish is local-first: your Mac is the backend on every surface, because dd-cli authenticates against your keychain.
Node.js 20+ β
node --versionto check; install from nodejs.org or brew.DoorDash CLI access (currently waitlist-gated by DoorDash). Peckish 0.4.0 requires dd-cli β₯ 0.2.1. Download the release from doordash-oss/doordash-cli, verify the SHA256 checksum against the published value, then:
tar -xzf dd-cli-v*-darwin-arm64.tar.gz && cd dd-cli-v*-darwin-arm64 bash install.sh # installs to ~/.local/bin/dd-cli dd-cli login # sign in to DoorDash in your browser (stored in keychain)An Anthropic API key for the terminal/web surfaces (console.anthropic.com) β or skip the key entirely and use the MCP surface with your Claude subscription (step 4).
2. Install Peckish
npm install -g peckishThat's it β you now have three commands: peckish (terminal chat),
peckish-web (web app), and peckish-mcp (MCP server).
git clone https://github.com/CydVilla/peckish.git
cd peckish
npm install
npm test # optional: 13 unit tests, no network needed
npm run dev # terminal chat (or: npm run web / npm run mcp)3. Run it β terminal or web
export ANTHROPIC_API_KEY=sk-ant-β¦ # from console.anthropic.com
peckish # terminal chat
peckish-web # web app β open http://localhost:4747On boot Peckish verifies your DoorDash sign-in, shows your default delivery
address, and flags any open carts you forgot about. If sign-in is missing or
expired, Peckish offers to fix it for you: the terminal asks before launching
dd-cli login (which opens your browser), the web app shows a sign-in card,
and mid-conversation the agent can offer the same assist on any surface β you
approve, sign in in the browser, and it picks up where it left off.
4. Or run it inside Claude β no API key
Claude itself becomes the ordering agent, and your Claude subscription pays for the model. Pick whichever fits your client:
Claude Code β one line:
claude mcp add peckish -- npx -y peckish-mcpClaude Desktop β download peckish-0.2.2.mcpb from
Releases and
double-click it. Claude Desktop installs it like a browser extension: no
terminal, no Node install, no JSON editing.
Add to ~/Library/Application Support/Claude/claude_desktop_config.json:
{
"mcpServers": {
"peckish": {
"command": "npx",
"args": ["-y", "peckish-mcp"]
}
}
}If dd-cli isn't at ~/.local/bin/dd-cli, add
"env": { "DD_CLI_PATH": "/your/path/to/dd-cli" } β desktop apps don't
inherit your shell PATH.
Peckish is also listed in the MCP Registry
as io.github.CydVilla/peckish, so clients that browse the registry can find
it directly.
Restart Claude Desktop and ask it to find you dinner. Order confirmation appears as a native dialog; clients that can't render dialogs can browse and build carts but cannot place orders (fail closed).
5. Everyday use
Things to say:
"Find me a high-protein dinner under $25 that can arrive within 45 minutes. Avoid mushrooms and excessive fees."
"Compare the real totals at the top two β fees included."
"Reorder my usual from Sharon Korean."
"What did I spend on delivery last month?"
"Is this place actually good?" (checks web reviews)
"Never mushrooms, ever." β saved permanently; applied automatically next time
"Get me milk, eggs, and a pound of ground beef from Whole Foods."
Placing an order always ends with an explicit confirmation you perform β
typing yes in the terminal, clicking Place order in the web modal, or
approving the dialog in Claude Desktop. Before that, Peckish must show you the
itemized quote, confirm the tip, and name the card being charged. Decline
anything and it backs off.
Controls & housekeeping
Where | What |
Terminal |
|
Web | Stop button cancels a turn Β· New chat resets Β· header chip shows session cost Β· click the address chip to switch your delivery address (editing an address's text happens on doordash.com β Peckish picks it up automatically) |
Both | Preferences live in |
Cost: defaults are tuned for low spend at decent quality β claude-sonnet-5
at medium effort, prompt caching on the system prefix and conversation tail,
and server-side context editing that prunes stale menu payloads in long
sessions. The cost meter shows the approximate spend per turn and per session.
Max quality: DD_AGENT_MODEL=claude-opus-4-8 DD_AGENT_EFFORT=high. (On MCP,
the client chooses and pays for the model.)
Troubleshooting
Symptom | Fix |
| Accept the built-in sign-in assist (it runs |
Auth errors right after upgrading dd-cli | New CLI versions can need fresh scopes β sign in again (assist or |
|
|
| Install dd-cli (step 1) or set |
Web app port in use |
|
A turn ran away | Ctrl+C (terminal) / Stop (web) β history rolls back cleanly |
Env vars: DD_AGENT_MODEL (default claude-sonnet-5), DD_AGENT_EFFORT
(lowβmax, default medium), DD_CLI_PATH, PECKISH_PORT (default 4747).
Related MCP server: DoorDash MCP Server
Mac app
A double-clickable app for people who never want to see a terminal:
download Peckish-x.y.z-arm64.dmg from
Releases, drag
Peckish to Applications, and open it.
First launch (Gatekeeper): the app is ad-hoc signed but not notarized (no paid Apple Developer ID), so macOS won't open it on a plain double-click the first time. Right-click the app β "Open" β "Open" (or approve it under System Settings β Privacy & Security). Only needed once.
If macOS instead says "Peckish is damaged and can't be opened", you have a build from before this was fixed, or the download quarantine got confused. Clear it once and it opens normally:
xattr -cr /Applications/Peckish.app
First-run setup happens in the app β three buttons, no terminal:
DoorDash CLI β one-click guided install (downloads the official release, verifies its SHA256 checksum before running anything). If you don't have dd-cli access yet, there's a waitlist link.
Sign in to DoorDash β opens your browser; the app detects when you're done. Your sign-in lives in the macOS keychain.
Anthropic API key β paste it once; it's stored encrypted with Electron
safeStorage(keychain-backed), never in plain text.
Then Open Peckish β same web app, same order-confirmation modal, same safety gates; the app is just a shell that runs the local server for you on a random localhost-only port. Requires Apple Silicon; Node.js is not required (the app bundles its own runtime).
Building it yourself: cd desktop && npm install && npm run dist β
desktop/dist/Peckish-*.dmg.
What it does
Search β menus β cart β preview β confirm β submit, with the real fee/ETA quote (
order preview) driving every recommendation.Comparison shopping: builds carts at up to 3 finalists, compares true totals + fee share + ETA, recommends one, deletes the losers.
Fee tactics: promo scanning with consent, pickup-vs-delivery comparison, DoorDash credits surfaced, DashPass status shown.
Memory: dietary rules and habits persist across sessions and surfaces.
History: "my usual" from order frequency, honest spend breakdowns from receipts, reorders with silent-drop detection.
Web reviews via Claude's server-side web search (never used for prices β dd-cli is the only source of truth for ordering data).
Group carts (new in 0.4.0): "start a group order for the team, $25 each" β creates a shareable cart link, optional per-person spend limit, host reviews and submits when everyone's in.
Express delivery (new): asks for Priority when you want it fastest β offered per-cart, priced into the quote before you approve.
Credits control (new): DoorDash credits apply by default; say "don't use my credits" to opt out for an order.
Enterprise chains (new): Domino's, Sweetgreen, Dave's Hot Chicken and other big chains are now orderable (dd-cli β₯ 0.2.1).
Work benefits (company budgets + expense codes), scheduled delivery, pickup, groceries/retail/pets/alcohol.
Architecture
terminal REPL local web app MCP client (Claude Desktopβ¦)
src/index.ts src/web.ts + public/ src/mcp.ts
ββββββββββββββ¬ββββββββββ β (client's model reasons;
β β server instructions guide it)
Claude agent loop, streaming β
src/agent.ts Β· claude-sonnet-5 Β· strict tools β
Β· adaptive thinking Β· context editing β
Β· prompt caching Β· web_search Β· cost meter β
βββββββββββββββββ¬ββββββββββββββββββ
β
28 typed tools β src/tools.ts (strict: true)
β
sanitizing wrapper β src/ddcli.ts
β
dd-cli --json-output β DoorDashSafety model
Placing an order always requires an explicit human approval rendered by the surface, not by the model:
Surface | The gate |
Terminal | Type |
Web | "Place order" modal (declines automatically after 5 min) |
MCP | Client elicitation dialog; clients without elicitation cannot place orders (fail closed) |
Also on every surface:
Strict tool schemas β the API guarantees tool arguments validate before any handler runs (no malformed-argument class).
Abortable turns β Ctrl+C / Stop rolls history back to the turn start.
Audit log β every tool call, argument set, duration, confirmation outcome, and submit result in
~/.peckish/logs/*.jsonl.Tip confirmed + card named before any submit ask; submit never auto-retries (not idempotent); success reported only after
order statusconfirms.Merchant text treated as data (widget/assistant-instruction fields stripped); read-only CLI calls retry once on transient errors, mutations never do.
Web server is localhost-only (Host + Origin checks).
What Peckish shares with DoorDash
dd-cli β₯ 0.2.1 requires an --intent note on every command, which DoorDash
says it may review for research and product improvement. DoorDash's documented
format asks for your verbatim prompt β but food prompts routinely contain
dietary, health, and religious signals, which DoorDash's own guidance says to
avoid. So Peckish defaults to privacy:
What is sent: a one-line goal summary authored by the model at generic altitude (e.g.
Summary: Help the user order dinner), plus an explicituser prompt/purpose: "(not shared β Peckish privacy default)"marker.What is never sent by default: your verbatim words, dietary rules, budgets, names, saved preferences, or conversation content.
Opt in to the full format: set
PECKISH_INTENT_VERBATIM=1and the intent will include your opening request verbatim, as DoorDash's docs ask.
Independent of intent, DoorDash necessarily sees the API traffic itself (searches, carts, orders) β that's inherent to ordering.
Repo map
File | What it is |
| Terminal REPL surface (abort, cost lines, /cost) |
| Web surface: SSE streaming, cards, Stop, confirm modal, Origin guard |
| MCP stdio server: 28 tools + session context, instructions, elicitation gates |
| System prompt + streaming tool loop (beta: context editing; web_search; usage) |
| Tool schemas (strictified) + handlers; menu trimming/filtering |
|
|
| Pluggable confirmation gates (fail closed) |
| Cost accounting Β· JSONL audit log |
| Preference persistence ( |
| 13 unit tests ( |
| Electron shell for the Mac app (.dmg): onboarding + server launcher, no agent logic |
| The |
| Claude Desktop extension ( |
| MCP Registry metadata ( |
Releasing
Everything ships from one tag. .github/workflows/release.yml publishes both
npm packages, registers the MCP Registry entry, builds the .mcpb and the
.dmg, and attaches both to the GitHub release:
npm version patch # or edit the versions by hand
git push && git push --tagsEvery publish step is skip-if-already-published, so re-running a tag after a
failure is safe. .github/workflows/ci.yml runs typecheck, tests, a metadata
consistency check, and a real MCP handshake on every push.
scripts/check-consistency.mjs guards the metadata that spans files and drifts
silently β the registry namespace casing, matching server.json name and
mcpName, the 100-character registry description cap, and the extension's
advertised tool list. Run it locally before tagging.
npm β either configure
trusted publishing on npmjs.com for
both peckish and peckish-mcp (provider: GitHub Actions, repo
CydVilla/peckish, workflow release.yml) so no secret is needed, or add an
NPM_TOKEN repository secret using a granular access token with "bypass 2FA"
enabled.
MCP Registry β nothing to configure. The workflow authenticates with
mcp-publisher login github-oidc, and GitHub's OIDC token proves the repo owner
is CydVilla, which grants the io.github.CydVilla/* namespace.
Mac app signing β the .dmg is built unsigned. Notarized builds would need
an Apple Developer ID plus CSC_LINK/CSC_KEY_PASSWORD and notarization
secrets.
Notes & limitations
Local-first by design: hosted delivery (SMS bots, voice) would require DoorDash's partner API β your Mac is the backend here.
One open cart per store (DoorDash rule) β Peckish collision-checks and asks.
payment-method listsees cards only; wallet defaults (Apple Pay etc.) are confirmed generically or via the browser checkout URL.Age-restricted items can't be submitted by an agent β checkout URL fallback.
Popularity data is deliberately unused (per dd-cli guidance); web reviews fill that gap with attribution.
Cost figures are close estimates from token usage at list prices.
Maintenance
Related MCP Servers
- Alicense-qualityDmaintenanceEnables AI agents to discover and order food from multiple delivery services (DoorDash, UberEats, Grubhub) using A2A protocol and process payments via Stripe with AP2 protocol mandates for cryptographically signed user authorization.Last updated1MIT
- FlicenseBqualityDmaintenanceEnables AI agents to search restaurants, browse menus, and manage DoorDash carts through structured JSON data. It leverages a background browser to handle authentication and direct GraphQL API calls for efficient interaction.Last updated71
- FlicenseBqualityDmaintenanceEnables AI agents to search restaurants, browse menus, manage carts, and place orders on DoorDash programmatically. It utilizes a headless browser to interact with DoorDash's GraphQL API and bypass anti-bot protections for the full delivery lifecycle.Last updated222
- Flicense-qualityDmaintenanceEnables AI agents to search restaurants, place delivery orders, and track real-time delivery status using the DoorDash Drive API. It includes a built-in mock data mode that allows for testing and demonstrating delivery lifecycles without requiring live API credentials.Last updated
Related MCP Connectors
Let ChatGPT, Claude & Cursor use your Mac: email, calendar, iMessage, Teams, files. Local, free.
A paid remote MCP for ShipSwift, built to return verdicts, receipts, usage logs, and audit-ready JSO
Routes natural-language shopping queries to merchant storefronts, returns normalized results.
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/CydVilla/peckish'
If you have feedback or need assistance with the MCP directory API, please join our Discord server