# NorthCinder: a local MCP server that asks before it buys

> NorthCinder compares offers from stores you connect, reruns the ranking on your machine, and requires a fresh signed approval for every checkout. It is for buyers who want an agent to research without letting it spend.

**cinderline/northcinder** — Open-source MCP server for comparing products and asking the buyer before purchase.

- Repository: https://github.com/cinderline/northcinder
- Stars: 1,215 · Forks: 10
- Language: JavaScript
- License: MIT
- Published: 2026-09-10 · Updated: 2026-09-10 · Language: en
- Canonical page: https://hysenlabs.com/projects/cinderline-northcinder

## The marketplace agent problem NorthCinder answers

A shopping agent that searches one catalog and routes you to that catalog's checkout is not giving independent advice. The README states the case plainly: the marketplace decides what can be seen and makes money when the sale closes. NorthCinder is built for the opposite arrangement. It compares products from sources you choose, shows where its facts came from, and asks for approval before anything is bought.

The audience is narrow and specific. You need an MCP-capable AI app, Node.js 20 or later, and a willingness to run software locally. The repository owner operates no NorthCinder service, there is no account, and there is no cloud endpoint. That is a deliberate constraint rather than a missing feature: the audit log, the approvals, and the purchase records live on your computer, and the README says searches, settings, and local history are not sent to the repository owner.

## How the MCP server, local engine and audit log fit together

Your AI app talks to NorthCinder over MCP. In the default local mode, the MCP server and the search engine run together in one process on a temporary loopback port, which is why local mode needs no keys. The engine performs the search, then NorthCinder reruns the ranking locally before returning it, so the ordering that reaches your agent is checked rather than accepted.

Recommendations, approvals, and checkout attempts are written to a local audit log. The README points to four places where the rules are spelled out: docs/RANKING.md, docs/TRUST.md, docs/NEUTRALITY-AUDIT.md, and the packages/checkout directory. The stated neutrality rules are concrete: seller payment never improves ranking, sponsored offers stay labeled and below organic results, missing store coverage stays visible, and unknown seller history stays unknown rather than being guessed safe.

Buying is a separate path from recommending. Every checkout needs a fresh approval for one exact offer and one unit, and the signed approval carries the merchant, variant, price, known total, and spending cap. It can be used once. NorthCinder rejects raw card details; a supported automated checkout can use an opaque payment token, or the buyer can be handed a cart link to finish in their own browser.

## Install NorthCinder and run a first shopping brief

The quickest path is the published package, which the README gives as a single command. It saves configuration on your computer and prints the MCP entry to paste into your AI app.

```bash
npx northcinder init
```

If you prefer to build from source, the repository is a pnpm workspace. Product packages need Node.js 20 or later, while the private site workspace needs Node.js 22.12 or later. The README gives these three commands.

```bash
corepack pnpm install --frozen-lockfile
corepack pnpm build
node northcinder/bin/northcinder.js init
```

Once the MCP entry is connected, the README suggests starting with a brief that names the constraints rather than the product. A black wool running shoe under $130, compared on price, delivery, fit, and merchant trust, will produce at most three useful choices: the strongest fit, a lower-risk option, and a cheaper or meaningfully different option when one exists. Each result explains its position, and the other finalists, rejected offers, and unverifiable facts remain inspectable.

For a separate engine process, the README describes setting NORTHCINDER_API_KEYS on the service and configuring the client with NORTHCINDER_SERVICE_URL plus the matching NORTHCINDER_CLIENT_KEY bearer credential. Non-loopback bearer connections must use HTTPS, and the example environment file notes that keys need at least 16 characters.

## Store coverage is the real limit, and it is stated up front

Built-in adapters cover Shopify, WooCommerce, eBay, Etsy, and read-only Amazon comparison. That list is useful but partial, and NorthCinder says when a store was unavailable or not configured rather than presenting a partial search as market-wide. The distinction matters: the neutrality checks cover the offers NorthCinder received, not the completeness or truth of any store's catalog.

Several adapters need credentials you supply yourself. eBay takes EBAY_CLIENT_ID, EBAY_CLIENT_SECRET, and an EBAY_ENV of sandbox or production. Etsy takes ETSY_API_KEY. WooCommerce takes WOOCOMMERCE_STORE_HOSTS. Shopify is the awkward one: the environment inventory says any Shopify UCP call requires SHOPIFY_UCP_AGENT_PROFILE_URL, an HTTPS URL to agent-profile JSON you control, and notes that current Shopify catalog docs require a profile rather than an API key. The Amazon adapter is read-only and uses AMAZON_SESSION_PROFILE, your own local browser profile.

If a native connection is missing, the AI app can keep researching with its own browser or search tools. NorthCinder accepts product facts, not cookies, raw pages, passwords, or page instructions. That is a sensible boundary, and it also means a native connection must confirm the exact offer before checkout or an unattended watch.

## Research results are provisional by design

This is the part that will frustrate anyone expecting a clean answer. NorthCinder ships separate research guides for products and sellers, exposed as northcinder://research/product and northcinder://research/seller. The host is expected to read one of those, call create_research_plan with the actual request and exact subject, then follow the returned checklist using research tools it already controls.

When sources disagree or fail to identify the exact product or seller, the result stays provisional. Research can decide whether an offer is ready to compare, but it cannot add ranking points. The README is blunt about the current state: no host and model combination is currently qualified for routine research use, and every research result should be treated as provisional until the buyer checks its identity, sources, conflicts, and unknowns.

That admission is unusual and worth weighing. It means the human is not a rubber stamp at the end of the flow; the human is a required participant in the middle of it. If you want an agent that resolves ambiguous listings on its own, NorthCinder is the wrong tool today, and the project says so.

## Where NorthCinder differs from an agent using generic web search

The obvious alternative is an MCP-capable agent with a general web search or browser tool and no shopping layer at all. That setup is more flexible and covers any storefront immediately, including ones with no adapter. It also has no shared ranking specification, no neutrality audit, no local audit log of checkout attempts, and no single-use signed approval tied to one offer and one unit.

The difference is not the search itself. It is what happens between a plausible listing and a purchase. With a generic browser tool, the agent's own reasoning is the only thing standing between a page and a checkout, and the constraints live in the prompt. With NorthCinder, the ranking is rerun locally, the approval is scoped to the merchant, variant, price, known total, and spending cap, and the rules about sponsored placement and seller payment are written into the repository rather than into a system prompt.

The cost is coverage and setup. You configure adapters and credentials, you accept that unconfigured stores are reported as gaps, and you give up the ability to buy without a fresh approval.

## Maintenance, releases and the MIT licence

The last push to the main branch was on 2026-08-22, the same day v0.2.1 was released, with v0.2.0 earlier that day and v0.1.2 on 2026-08-17. The repository is not archived. The version numbering suggests a project that is still settling: three releases inside a week, and a 0.2 line rather than anything declared stable.

Upgrade cost is mostly configuration drift. The example environment file keeps THENAGAIN_* and EMPTOR_* aliases as temporary migration compatibility paths, with canonical NORTHCINDER_* variables taking precedence, which tells you the environment surface has already been renamed once. If you script against those prefixed variables, expect to move to the NORTHCINDER_* names.

NorthCinder is MIT licensed, so you can use, modify, and redistribute it under those terms. The licence is silent on the stores you connect: eBay, Etsy, WooCommerce, Shopify, and Amazon each have their own API terms, and the repository does not speak for them. That is a question for your own review, not a legal opinion this article can give.

## Conclusion

Adopt NorthCinder if you already run an MCP-capable AI app and want comparison and checkout approval to stay on your own machine. Skip it if you need one adapter to cover the whole market, or if you want unattended purchasing, since every checkout needs a fresh single-use approval and no host and model combination is currently qualified for routine research. Before trusting a result, read docs/RANKING.md and docs/TRUST.md in the repository and confirm which store adapters you can actually configure.

## FAQ

### Does NorthCinder need my AI provider key or a NorthCinder account?

No. The README states NorthCinder never needs your AI provider key, which stays in your AI app, and that there is no NorthCinder account or cloud service because the repository owner operates no NorthCinder service.

### Which stores can NorthCinder compare?

Built-in adapters cover Shopify, WooCommerce, eBay, Etsy, and read-only Amazon comparison. When a store was unavailable or not configured, NorthCinder says so instead of presenting a partial search as market-wide.

### Can NorthCinder buy something without asking me first?

No. Every checkout needs a fresh approval for one exact offer and one unit, and the signed approval, which includes the merchant, variant, price, known total, and spending cap, can be used once.

## Sources

- [cinderline/northcinder on GitHub](https://github.com/cinderline/northcinder)
- [Issues](https://github.com/cinderline/northcinder/issues)
- [License: MIT](https://github.com/cinderline/northcinder/blob/main/LICENSE)
- [README](https://github.com/cinderline/northcinder/blob/main/README.md)
- [Releases](https://github.com/cinderline/northcinder/releases)

---

Hysen Labs editorial analysis, written from the project's own repository and release notes. Cite the canonical page: https://hysenlabs.com/projects/cinderline-northcinder
