EnCarAPI - Korean & Chinese used cars

io.github.ThatMojov1.0.1Updated Oct 4, 2026

Live used car listings from South Korea (Encar, KB Chachacha, K Car) and China (Dongchedi, Che168).

VerifiedStreamable HTTPWeb executableWeb Search & ScrapingBusiness & Commerce

Overview

AI-generated overview

Lets an assistant search live used-car listings from South Korea and China and pull details, inspection reports and accident records.

What it does
Provides read-only tools over live used-car marketplaces: search_korean_cars and search_chinese_cars filter listings by brand, model, year, price, mileage, fuel, city or export-ready status, while get_korean_car and get_chinese_car return full records such as specs, options, photos, price history and seller. Inspection reports and accident or ownership history come from get_korean_inspection, get_korean_accident_record and get_chinese_inspection. Helper tools cover model autocomplete and valid filter values.
When to use it
Useful when someone wants an assistant to browse, compare or research second-hand vehicles in Korea or China, for example finding accident-free models under a price cap or checking inspection and accident records for a specific listing. Not intended for buying, bidding or any transaction.
Requirements
An EnCarAPI key is required, obtained from encarapi.com (5-day trial). Chinese data needs a ChinaCarAPI key or an EnCarAPI key with the China add-on. Hosted use is a remote MCP endpoint at either through OAuth in the browser or by sending the key in the Authorization header (x-api-key also works); local use runs the npm package encarapi-mcp via npx with ENCARAPI_KEY, and optionally CHINACARAPI_KEY, set as environment variables. Network access is needed.
Before you install
The EnCarAPI key is a paid-service credential: ENCARAPI_KEY, CHINACARAPI_KEY, the Authorization header and the x-china-key header are secrets, and a key passed in the URL query string can end up in logs, so a header is preferred. The hosted server does not store the key but encrypts it into the client token, and a single token cannot be revoked server-side; rotating the key cuts off all access. Self-hosting OAuth requires MCP_OAUTH_SECRET, and changing it signs out all clients. Tools are…

Installation

In SourceWeft

  1. Open EnCarAPI - Korean & Chinese used cars in the dashboard and add it to a workspace.
  2. Enable the server for the chats that should use its tools.

Web executable via Streamable HTTP. Remote servers run from the web runtime once configured in a workspace.

Other MCP clients

Add this to your client's mcpServers config.

{
  "mcpServers": {
    "encarapi-mcp": {
      "type": "http",
      "url": "https://mcp.encarapi.com/mcp"
    }
  }
}

README

EnCarAPI MCP server: Korean and Chinese used car data for AI assistants

Model Context Protocol server for EnCarAPI. Lets Claude, Cursor, ChatGPT and other MCP clients search live used car listings from South Korea (Encar, KB Chachacha, K Car) and China (Dongchedi, Che168), and pull full details, inspection reports and accident records.

An API key is required. Get one (5-day trial) at encarapi.com. Chinese data works with a ChinaCarAPI key or an EnCarAPI key with the China add-on.

Tools

ToolWhat it does
search_korean_carsSearch Korean listings (brand, model, year, price in 10,000 KRW, mileage, fuel, accident-free, source: encar / kbc / kcar / all)
get_korean_carFull detail for one listing (specs, options, photos, price history, seller)
get_korean_inspectionOfficial Korean inspection report
get_korean_accident_recordInsurance accident history and ownership changes
find_korean_modelsModel name autocomplete across brands
korean_filter_valuesValid filter values
search_chinese_carsSearch Chinese listings (brand, model, year, price in CNY, mileage, city, export-ready)
get_chinese_carFull record for one Chinese listing
get_chinese_inspectionChinese inspection report (accident, flood, fire, EV battery)
chinese_modelsModels of a brand with listing counts

All tools are read-only.

Option 1: hosted (no install)

Add this URL as a remote MCP server:

https://mcp.encarapi.com/mcp

In clients with OAuth support the URL is all you need. On first use a browser window opens, you paste your EnCarAPI key once, and the client is connected:

  • Claude (claude.ai, desktop, mobile): Settings - Connectors - Add custom connector, paste the URL
  • ChatGPT (developer mode): Settings - Connectors - create a connector with the URL
  • Cursor: {"mcpServers": {"encarapi": {"url": "https://mcp.encarapi.com/mcp"}}} in .cursor/mcp.json
  • VS Code: "MCP: Add Server" - HTTP - paste the URL
  • Claude Code:
bash
claude mcp add --transport http encarapi https://mcp.encarapi.com/mcp

The key is checked once and is not stored on the server: it is encrypted into the token your client receives. To disconnect, remove the server in your client; to cut off access everywhere, rotate your key at encarapi.com.

Alternative: send the key yourself

Clients without OAuth support, scripts and gateways can send the key directly:

https://mcp.encarapi.com/mcpAuthorization: Bearer YOUR_ENCARAPI_KEY

Claude Code:

bash
claude mcp add --transport http encarapi https://mcp.encarapi.com/mcp \  --header "Authorization: Bearer YOUR_ENCARAPI_KEY"

The x-api-key: YOUR_ENCARAPI_KEY header works as well. Clients that only accept a URL and have no OAuth support can use https://mcp.encarapi.com/mcp?key=YOUR_ENCARAPI_KEY (a header is preferred, since URLs can end up in logs). A separate ChinaCarAPI key goes into the x-china-key header, or into the second field of the browser form.

Option 2: local (npx)

Claude Desktop (claude_desktop_config.json), Cursor (.cursor/mcp.json) and most other clients:

json
{  "mcpServers": {    "encarapi": {      "command": "npx",      "args": ["-y", "encarapi-mcp"],      "env": {        "ENCARAPI_KEY": "YOUR_ENCARAPI_KEY"      }    }  }}

Claude Code:

bash
claude mcp add encarapi -e ENCARAPI_KEY=YOUR_ENCARAPI_KEY -- npx -y encarapi-mcp

Optional: CHINACARAPI_KEY for a separate ChinaCarAPI key.

Example prompts

  • "Find accident-free Genesis GV80 from 2022 or newer under 50 million KRW and compare the mileage."
  • "Show the inspection report and accident record for Encar listing 41000001."
  • "What are the cheapest export-ready BYD Seal listings in China right now?"

Self-hosting the HTTP endpoint

bash
docker build -t encarapi-mcp .docker run -p 3000:3000 encarapi-mcp     # POST /mcp, GET /health

Stateless: every request carries its own key, nothing is stored.

To enable the OAuth flow ("connect by URL only"), set two environment variables:

VariableMeaning
MCP_OAUTH_SECRETAt least 32 random characters, e.g. openssl rand -base64 48. Enables OAuth; without it the server only accepts keys sent by the client.
MCP_PUBLIC_URLPublic origin of the server, e.g. https://mcp.example.com (default https://mcp.encarapi.com). Tokens are bound to <MCP_PUBLIC_URL>/mcp.
bash
docker run -p 3000:3000 -e MCP_OAUTH_SECRET="$(openssl rand -base64 48)" \  -e MCP_PUBLIC_URL=https://mcp.example.com encarapi-mcp

This adds /.well-known/oauth-protected-resource, /.well-known/oauth-authorization-server, /register, /authorize and /token (OAuth 2.1 with PKCE, dynamic client registration). There is still no database: client ids, authorization codes and tokens are encrypted, self-contained values (AES-256-GCM) that carry the key. Consequences:

  • Changing MCP_OAUTH_SECRET signs out all OAuth clients (they reconnect through the browser).
  • Access tokens last 1 hour, refresh tokens 90 days and are replaced on every use.
  • Single use of authorization codes and of replaced refresh tokens is tracked in memory, so it is best-effort: it does not survive a restart and is not shared between instances.
  • A single token cannot be revoked on the server. Rotating the EnCarAPI key cuts off all access.

Links

EnCarAPI is an independent service and not affiliated with Encar, KB Chachacha, K Car, Dongchedi or Che168.

License

MIT

Source: README.md at commit e1d8c9f

Tools

0
Tool metadata has not been indexed yet.

Version history

1
  1. v1.0.1LatestOct 4, 2026