buywhere-mcp
warningsapi.buywhere.ai
Agent-native product catalog: 300M+ products, 150,000+ stores, deliver_to ranking.
https://api.buywhere.ai/mcpWebsiteOAuthMCP 2024-11-05v1.0.0last checked 3 Sep 2026spoke MCP on 3 of 3 checks (30 days)initialize in 319 msWill my client connect?
Decided from what the probe found at the endpoint, and from what each client's own documentation says it can complete. Every row carries the day that documentation was read.
✕Claude CodeNot supported
The authorization server advertises no S256 challenge method, which MCP's authorization spec requires — no compliant client has a method in common with it.
Claude Code docs · read on 2026-08-30
✕Claude (claude.ai & Desktop)Not supported
The authorization server advertises no S256 challenge method, which MCP's authorization spec requires — no compliant client has a method in common with it.
Claude (claude.ai & Desktop) docs · read on 2026-08-30
✕ChatGPTNot supported
The authorization server advertises no S256 challenge method, which MCP's authorization spec requires — no compliant client has a method in common with it.
ChatGPT docs · read on 2026-08-30
✕CursorNot supported
The authorization server advertises no S256 challenge method, which MCP's authorization spec requires — no compliant client has a method in common with it.
Cursor docs · read on 2026-08-30
✕VS Code (Copilot)Not supported
The authorization server advertises no S256 challenge method, which MCP's authorization spec requires — no compliant client has a method in common with it.
VS Code (Copilot) docs · read on 2026-08-30
How to authenticate
Checked against the endpoint by our probe on 3 Sep 2026. These are the capabilities the server advertises, not a prediction about any particular client.
| Scheme | OAuth |
|---|---|
| Issuer | https://api.buywhere.ai |
| Dynamic client registration | ✓Advertised (RFC 7591) |
| Client ID Metadata Document | ✕Not advertised |
| PKCE | ✕None advertised MCP requires S256; a client that implements only that has no method in common with this server. |
| Grant types | client_credentials |
| Scopes | catalog.read, offers.read |
| Protected-resource metadata | ✓Published (RFC 9728) |
| Anonymous access | Handshake succeeds; 13 tools listable |
| Credentials demanded in prose | ✕ingest_products These tools are listed anonymously and their own descriptions ask for an account or key, but no challenge is issued — so a client has nothing to act on and the refusal arrives as a tool error. |
| Documentation | https://buywhere.ai/agent-dx |
What the probe found
1 of the 13 tools listed anonymously say in their own descriptions that they need an account or a key (ingest_products), but the endpoint issued no WWW-Authenticate challenge. The requirement is stated only in prose, so a call reaches the tool and comes back as a tool error instead of an authorization step.
A cross-origin preflight came back without Access-Control-Allow-Origin, so the endpoint is reachable from native clients only — code running in a web page is stopped by the browser before a request is ever sent.
The server exposes a public surface before authorization: search_products, get_product, compare_products, get_deals, list_categories, find_best_price, find_similar, ingest_products, search_products_v2, get_product_v2, compare_products_v2, get_deals_v2, find_best_price_v2.
Tools
Contract history
Get alerted when this contract changes
Depend on this server? Leave an email and get a message when a probe records a change — a tool removed, an argument newly required, an enum narrowed. Alerts are being built; signing up is what tells us to hurry.
Prefer a feed reader? This page's contract changes are also an Atom feed.
Own this server?
Sign in to claim this listing by proving control of its host.
Status badge
Status for a README, from the last probe — cached an hour, so up to seven hours behind the endpoint. Links back to this page.
[](https://mcpi.app/servers/buywhere-mcp)