alza-mcp
Server Configuration
Describes the environment variables required to run the server.
| Name | Required | Description | Default |
|---|---|---|---|
| ALZA_DEBUG | No | Verbose stderr logging | false |
| ALZA_CDP_URL | No | Connect to your already-running Chrome via CDP instead of launching a managed Chromium. Reuses the existing browser session; set ALZA_MCP_SKIP_INSTALL=1 separately to skip the installation-time download. Launch Chrome with --remote-debugging-port=9222 and set ALZA_CDP_URL=http://localhost:9222 | |
| ALZA_BASE_URL | No | Switch locale: https://www.alza.cz, .sk, .hu, .at, .de, .co.uk | https://www.alza.cz |
| ALZA_HEADLESS | No | Set false to show the browser used for scraping and API fallback; OAuth/MFA/payment interactions remain user-controlled | true |
| ALZA_HTTP_HOST | No | Bind address for HTTP transport | 127.0.0.1 |
| ALZA_HTTP_PORT | No | Listen port for HTTP transport (0 picks a free one); PORT is also honored | 3000 |
| ALZA_TRANSPORT | No | Set to `http` to serve over Streamable HTTP instead of stdio | stdio |
| ALZA_TOKEN_FILE | No | JSON token store written by scripts/alza-auth-login* / scripts/alza_auth_login.py (set `none` to disable auto-load) | ~/.alza-mcp/tokens.json |
| ALZA_VISITOR_ID | No | Optional anonymous visitor UUID; otherwise generated per process | |
| ALZA_IDLE_TTL_MS | No | Close the headless Chromium after this many ms with no tool calls. Lower it on memory-constrained machines; raise it (or disable by setting absurdly high) if you make many calls in quick succession and don't want the relaunch latency | 180000 |
| ALZA_API_BASE_URL | No | Mobile API base URL | https://www.alza.cz |
| ALZA_CLIENT_SECRET | No | Same secret for the PKCE exchange scripts (scripts/e2e-order-payment.browser.mjs exchange, scripts/alza-auth-exchange.mjs) | |
| ALZA_OAUTH_AUTHORITY | No | OAuth authority | https://identity.alza.cz |
| ALZA_MCP_SKIP_INSTALL | No | Skip the installation-time Chromium download | |
| ALZA_HTTP_MAX_SESSIONS | No | Concurrent session cap (HTTP 503 beyond it) | 50 |
| ALZA_HTTP_ALLOWED_HOSTS | No | Comma-separated hostnames accepted in Host/Origin (defaults to loopback names when bound to loopback, otherwise no check) | |
| ALZA_HTTP_ENABLE_ACCOUNT | No | Unlock the auth/account/checkout/order/payment toolsets (per-session logins) | |
| ALZA_OAUTH_CLIENT_SECRET | No | The alza_Android OAuth client is confidential — token requests need its APK-embedded secret (default: the source-verified value; set "" to omit it for public clients). Used by auth_exchange and token refresh | |
| ALZA_HTTP_SESSION_IDLE_MS | No | Close a session after this long without a request (a session holding an open GET/SSE stream is not closed) | 1800000 |
| ALZA_HTTP_ALLOW_TOKEN_FILE | No | Also load ALZA_TOKEN_FILE into every session (single-user only; needs ALZA_HTTP_ENABLE_ACCOUNT) |
Instructions
Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.
This server publishes no instructions, or was last inspected before Glama recorded them.
Capabilities
Features and capabilities supported by this server
Protocol revision2025-11-25
| Capability | Details |
|---|---|
| tools | {
"listChanged": true
} |
| prompts | {
"listChanged": true
} |
| resources | {
"listChanged": true
} |
Tools
Functions exposed to the LLM to take actions
| Name | Description |
|---|---|
| search_productsA | Search the Alza.cz catalog by keyword. Use this for product discovery — finding what's available, comparing options, or starting research. Returns a list with product code, name, price, stock (from the card's purchase CTA), and rating. To get full details for one product, follow up with |
| get_productA | Fetch details for a single product by its Alza code (the |
| compare_productsA | Fetch 2–6 products by their Alza codes (the |
| get_product_reviewsA | Fetch reviews for a single product by its Alza code: the aggregate rating and review count plus up to |
| recommend_alternativesA | Find alternatives to one product ("something like this but cheaper / better / same brand"). Candidate pool = Alza's own alternatives list for the product (mobile API, keyed by the numeric commodity id taken from the product URL); if that list is empty, or nothing in it survives the mode filter, falls back to a same-category |
| find_pickup_pointsA | Find AlzaBox parcel lockers and AlzaShop showrooms near a Czech/Slovak postal code: name, address, GPS, distance and opening hours, sorted nearest first. Use when the user asks where the nearest AlzaBox or Alza store is, or where they could pick up an order. No cart or login needed. Lockers come from Alza's public locker map and are cached; each has a |
| list_category_filtersA | List the brands and attribute filters (facets) Alza defines for a category, with real ids and product counts. The attribute set differs per category (laptops have CPU/RAM facets, monitors have panel/resolution facets, …). Pass |
| list_categoriesA | Browse the Alza category tree one level at a time. Useful for narrowing a product search — find the right category id, then pass it to |
| get_dealsA | Find currently discounted products on Alza.cz, with current price, original price, savings and a discount % COMPUTED from the observed prices (never from marketing badges). Alza has no 'sale' facet or product-grid sale page, so this scans category listing pages (up to 3 pages ≈ 72 cards for a given |
| autocompleteA | Cheap search-box suggestions (plain HTTP, no page render): suggested query phrases plus matching categories, brands and products with ids/codes. Use it to refine a messy Czech query before a full |
| auth_discoveryA | Read the live OpenID Connect discovery document that the Alza mobile app uses (issuer, authorization endpoint, token endpoint). Use only when debugging the OAuth flow or verifying which identity endpoints Alza exposes before calling |
| auth_startA | Start an OAuth 2.0 PKCE sign-in for the Alza mobile API: returns an authorization URL plus a state value. Use when |
| auth_exchangeA | Complete the OAuth 2.0 PKCE sign-in: exchange the authorization code for mobile API tokens and load them into this server. Use immediately after the user finishes the |
| prepare_mutationA | Start a two-step mutation by returning a one-time confirmation token bound to exactly one action. This call itself sends nothing to Alza. Use it before the high-impact typed mutations — |
| account_statusA | Report whether a mobile API access token is loaded in this server process. Use as a first check before account-scoped tools ( |
| list_toolsetsA | List every toolset this server groups its tools into: id, title, description, member tool names, and whether it's currently enabled. Only |
| set_toolsetA | Enable or disable every tool in one toolset (or |
Prompts
Interactive templates invoked by user choice
| Name | Description |
|---|---|
| find-product | Guided shopping helper — describe what you're looking for and the agent will search, compare, and recommend. |
Resources
Contextual data attached and managed by the client
| Name | Description |
|---|---|
No resources | |
TDQS
Scored across 17 tools
Every tool targets a distinct purpose: search/discovery (search_products, autocomplete, list_categories, list_category_filters, get_deals), product detail (get_product, compare_products, get_product_reviews, recommend_alternatives), fulfillment (find_pickup_points), auth (auth_discovery, auth_start, auth_exchange, account_status), mutation gating (prepare_mutation), and meta toolset management (list_toolsets, set_toolset). The descriptions explicitly cross-reference each other (e.g. use compare_products instead of repeated get_product) so boundaries are clear.
Predominantly consistent verb_noun snake_case (search_products, get_product, list_categories, compare_products, prepare_mutation). Minor deviations: find_pickup_points vs list_* for exploration, and auth_* / account_status / list_toolsets shift the noun order slightly. Still highly predictable.
17 tools is borderline-heavy but defensible given the breadth (catalog, auth, cart/order, mutations, meta). The toolset-grouping mechanism exists precisely because the flat list is too large by default, which signals the count is on the high side.
Catalog-side coverage is strong (search, autocomplete, detail, compare, reviews, alternatives, deals, filters, categories, pickup). However the descriptions reference many tools that aren't visible in this set (cart, profile, order, add_to_cart, mutate_list, register, review_submit, watchdogs), so within the stated surface there are referenced-but-not-shown operations—a minor completeness gap for the catalog domain, largely mitigated by read-only coherent coverage.