MCP server for Karrito — digital catalog builder for WhatsApp sellers in LATAM
Karrito MCP provides 15 tools with consistent naming (verb_noun pattern) and reasonable descriptions (avg ~120 chars). All tools have input schemas with type definitions and parameter descriptions. However, output schemas are not documented in the source code provided, and several tools lack depth in error handling guidance. Parameter constraints are present (enums, min/max) but some descriptions could be more actionable. No tool annotations (readOnlyHint/destructiveHint) despite clear risk classifications in the spec. Security is handled server-side (API key injection), which is correct.
Create a new category in your Karrito store. Requires KARRITO_API_KEY environment variable.
Create a new discount code for your Karrito store. Requires KARRITO_API_KEY environment variable.
Delete a category from your Karrito store. Products in this category will become uncategorized. Requires KARRITO_API_KEY environment variable.
Delete a discount code from your Karrito store. Requires KARRITO_API_KEY environment variable.
Get detailed information about a specific customer including their order history. Requires KARRITO_API_KEY environment variable.
Get information about a specific Karrito niche by slug or name. Returns niche details from the 50 available niches. No authentication required.
Output schemas not documented. Tool descriptions state what is returned (e.g., 'Returns niche details') but the actual response structure (fields, types, nested objects) is not visible in source. LLMs cannot plan downstream tool calls or extract specific fields without knowing the response schema.
Tool annotations missing. Tools are classified with Risk levels (READ_ONLY, WRITE, DESTRUCTIVE) in the spec but not exposed as MCP tool annotations (readOnlyHint, destructiveHint, idempotentHint). This prevents clients from applying appropriate safety guards or confirmation flows.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-23 | B | 72 | 2026-07-28+ | v2 |
Get detailed information about a specific order including items, customer info, and status. Requires KARRITO_API_KEY environment variable.
List categories in your Karrito store. Requires KARRITO_API_KEY environment variable.
List customers who have placed orders in your Karrito store. Requires KARRITO_API_KEY environment variable.
List discount codes in your Karrito store. Requires KARRITO_API_KEY environment variable.
List orders from your Karrito store. Requires KARRITO_API_KEY environment variable.
Search public Karrito catalogs by keyword. No authentication required.
Update an existing category in your Karrito store. Requires KARRITO_API_KEY environment variable.
Update an existing discount code in your Karrito store. Requires KARRITO_API_KEY environment variable.
Update the status of an order (e.g., confirm, ship, deliver, or cancel). Requires KARRITO_API_KEY environment variable.
Error handling lacks recovery guidance. Descriptions do not explain what to do if a call fails (e.g., 'If category not found, try list_categories() first'). Error responses are not shown in source, so it is unclear whether they include actionable next steps or just error codes.
Destructive operations lack confirmation pattern. delete_category and delete_discount have no dry-run or confirmation step. Agents can permanently delete resources without a safety gate, risking data loss.
Parameter descriptions could be more actionable. Several parameters lack format hints or constraint details. E.g., 'Niche slug (e.g., "reposteria")' includes an example value, which LLMs may reuse literally. Use enum constraints or format patterns instead.