A shopping list management system built with FastAPI that exposes REST endpoints as MCP tools via fastapi-mcp, integrated with LangGraph for AI agent capabilities
This FastAPI-MCP server demonstrates solid foundational tool design with consistent naming conventions, complete parameter schemas, and comprehensive descriptions. All 11 tools follow verb-noun naming patterns (create_*, get_*, update_*, delete_*, toggle_*) that clearly signal intent. Every tool has a meaningful description (100-250 chars) explaining what it does. Input parameters are properly typed with JSON Schema, including constraints like minLength, maxLength, minimum, and defaults. The server properly models pagination (skip/limit), distinguishes between read-only and destructive operations via risk classification, and includes appropriate HTTP status error handling (404s for not-found, validation errors). However, there are notable gaps: output schemas are not explicitly documented in the tool definitions themselves (they exist as FastAPI response_model annotations but are not exposed to MCP clients as structured descriptions), error messages lack recovery guidance (e.g., 'Shopping list not found' could suggest 'Try get_shopping_lists() to see available lists'), and there is no explicit parameter dependency documentation (e.g., shopping_list_id is required in create_shopping_item but this relationship is not documented). Tool composition is well-designed, each tool has exactly one responsibility, IDs are consistently named, and response objects should chain well (though we cannot verify return field names from the code snippet). Security-wise, the server uses FastAPI dependency injection for database access and HTTP status codes, but there is no visible audit logging, rate limiting, or explicit permission checking beyond what the database layer provides.
Add a new item to a shopping list.
Create a new shopping list with the given name and description.
Delete a shopping item from its list.
Delete a shopping list and all its items.
Retrieve a specific shopping item by ID.
Retrieve all shopping items with optional filtering by shopping list.
Retrieve a specific shopping list by ID along with all its items.
Output schemas not documented in MCP tool definitions. Response models (ShoppingListResponse, ShoppingItemResponse, ShoppingListWithItems) exist in FastAPI but are not exposed as structured JSON Schema in the MCP tool schema. LLM cannot plan downstream field access without inspecting undocumented response types.
Error messages lack recovery guidance. When a shopping list is not found (404), the response is a bare 'Shopping list not found' with no suggestion of next steps. Should say 'Shopping list not found. Try get_shopping_lists() to see available lists or create one with create_shopping_list().'
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | C | 63 | 2026-07-28+ | v2 |
| 2026-03-09 | C | 62 | - | v1 |
Retrieve all shopping lists with optional pagination.
Toggle the completion status of a shopping item (mark as completed/uncompleted).
Update an existing shopping item's details.
Update an existing shopping list's name and/or description.
Parameter dependencies not documented. create_shopping_item requires shopping_list_id but does not document that the shopping list must exist first or how to obtain a valid ID. Agents may pass invalid IDs without understanding the constraint.
No audit logging visible. Tool calls (especially destructive operations like delete_shopping_list, delete_shopping_item) should log who called what, when, and what happened. No logging decorator or explicit audit trail code is visible in the provided source.
No rate limiting. An agent in a retry loop could generate thousands of create_shopping_item calls without throttling, overwhelming the service. Rate limits should guard all write/destructive operations.
Destructive operations lack confirmation step. delete_shopping_list and delete_shopping_item should support a dry-run or require explicit confirmation before executing, preventing accidental cascading deletes.