EnCarAPI - Korean & Chinese used cars

io.github.ThatMojov1.0.1更新于 Oct 4, 2026

Live used car listings from South Korea (Encar, KB Chachacha, K Car) and China (Dongchedi, Che168).

已验证Streamable HTTP可网页运行Web Search & ScrapingBusiness & Commerce

概览

AI 生成的概览

让助手搜索韩国和中国的实时二手车车源,并获取详情、检测报告和事故记录。

功能
提供针对实时二手车市场的只读工具:search_korean_cars 和 search_chinese_cars 可按品牌、车型、年份、价格、里程、燃料、城市或是否可出口筛选车源,get_korean_car 和 get_chinese_car 返回完整记录,如规格、配置、照片、价格历史和卖家信息。检测报告与事故、过户历史由 get_korean_inspection、get_korean_accident_record 和 get_chinese_inspection 提供。辅助工具用于车型自动补全和有效筛选值查询。
适用场景
适合让助手浏览、比较或调研韩国和中国的二手车,例如查找某价格以内无事故的车型,或查看某条车源的检测与事故记录。不用于购车、出价或任何交易。
运行要求
需要 EnCarAPI 密钥,可在 encarapi.com 获取(5 天试用)。中国数据需要 ChinaCarAPI 密钥,或带中国附加组件的 EnCarAPI 密钥。托管方式为远程 MCP 端点 OAuth 连接,或在 Authorization 请求头中发送密钥(x-api-key 也可);本地方式通过 npx 运行 npm 包 encarapi-mcp,并以环境变量设置 ENCARAPI_KEY,可选 CHINACARAPI_KEY。需要网络访问。
安装前请注意
EnCarAPI 密钥是付费服务凭据:ENCARAPI_KEY、CHINACARAPI_KEY、Authorization 请求头和 x-china-key 请求头都是机密,把密钥放在 URL 查询参数中可能进入日志,因此优先使用请求头。托管服务器不存储密钥,而是将其加密进客户端令牌,且单个令牌无法在服务端撤销;轮换密钥会切断所有访问。自托管 OAuth 需要 MCP_OAUTH_SECRET,更改它会使所有客户端退出登录。工具为只读,但车源数据来自第三方平台,本服务与这些平台无关联。

安装

在 SourceWeft 中

  1. 打开 控制台中的 EnCarAPI - Korean & Chinese used cars,将其添加到工作区。
  2. 为需要使用其工具的对话启用该服务。

Web executable,通过 Streamable HTTP。 远程服务在工作区中配置后即可从网页运行时运行。

其他 MCP 客户端

把它添加到你客户端的 mcpServers 配置中。

{
  "mcpServers": {
    "encarapi-mcp": {
      "type": "http",
      "url": "https://mcp.encarapi.com/mcp"
    }
  }
}

README

EnCarAPI MCP server: Korean and Chinese used car data for AI assistants

Model Context Protocol server for EnCarAPI. Lets Claude, Cursor, ChatGPT and other MCP clients search live used car listings from South Korea (Encar, KB Chachacha, K Car) and China (Dongchedi, Che168), and pull full details, inspection reports and accident records.

An API key is required. Get one (5-day trial) at encarapi.com. Chinese data works with a ChinaCarAPI key or an EnCarAPI key with the China add-on.

Tools

ToolWhat it does
search_korean_carsSearch Korean listings (brand, model, year, price in 10,000 KRW, mileage, fuel, accident-free, source: encar / kbc / kcar / all)
get_korean_carFull detail for one listing (specs, options, photos, price history, seller)
get_korean_inspectionOfficial Korean inspection report
get_korean_accident_recordInsurance accident history and ownership changes
find_korean_modelsModel name autocomplete across brands
korean_filter_valuesValid filter values
search_chinese_carsSearch Chinese listings (brand, model, year, price in CNY, mileage, city, export-ready)
get_chinese_carFull record for one Chinese listing
get_chinese_inspectionChinese inspection report (accident, flood, fire, EV battery)
chinese_modelsModels of a brand with listing counts

All tools are read-only.

Option 1: hosted (no install)

Add this URL as a remote MCP server:

https://mcp.encarapi.com/mcp

In clients with OAuth support the URL is all you need. On first use a browser window opens, you paste your EnCarAPI key once, and the client is connected:

  • Claude (claude.ai, desktop, mobile): Settings - Connectors - Add custom connector, paste the URL
  • ChatGPT (developer mode): Settings - Connectors - create a connector with the URL
  • Cursor: {"mcpServers": {"encarapi": {"url": "https://mcp.encarapi.com/mcp"}}} in .cursor/mcp.json
  • VS Code: "MCP: Add Server" - HTTP - paste the URL
  • Claude Code:
bash
claude mcp add --transport http encarapi https://mcp.encarapi.com/mcp

The key is checked once and is not stored on the server: it is encrypted into the token your client receives. To disconnect, remove the server in your client; to cut off access everywhere, rotate your key at encarapi.com.

Alternative: send the key yourself

Clients without OAuth support, scripts and gateways can send the key directly:

https://mcp.encarapi.com/mcpAuthorization: Bearer YOUR_ENCARAPI_KEY

Claude Code:

bash
claude mcp add --transport http encarapi https://mcp.encarapi.com/mcp \  --header "Authorization: Bearer YOUR_ENCARAPI_KEY"

The x-api-key: YOUR_ENCARAPI_KEY header works as well. Clients that only accept a URL and have no OAuth support can use https://mcp.encarapi.com/mcp?key=YOUR_ENCARAPI_KEY (a header is preferred, since URLs can end up in logs). A separate ChinaCarAPI key goes into the x-china-key header, or into the second field of the browser form.

Option 2: local (npx)

Claude Desktop (claude_desktop_config.json), Cursor (.cursor/mcp.json) and most other clients:

json
{  "mcpServers": {    "encarapi": {      "command": "npx",      "args": ["-y", "encarapi-mcp"],      "env": {        "ENCARAPI_KEY": "YOUR_ENCARAPI_KEY"      }    }  }}

Claude Code:

bash
claude mcp add encarapi -e ENCARAPI_KEY=YOUR_ENCARAPI_KEY -- npx -y encarapi-mcp

Optional: CHINACARAPI_KEY for a separate ChinaCarAPI key.

Example prompts

  • "Find accident-free Genesis GV80 from 2022 or newer under 50 million KRW and compare the mileage."
  • "Show the inspection report and accident record for Encar listing 41000001."
  • "What are the cheapest export-ready BYD Seal listings in China right now?"

Self-hosting the HTTP endpoint

bash
docker build -t encarapi-mcp .docker run -p 3000:3000 encarapi-mcp     # POST /mcp, GET /health

Stateless: every request carries its own key, nothing is stored.

To enable the OAuth flow ("connect by URL only"), set two environment variables:

VariableMeaning
MCP_OAUTH_SECRETAt least 32 random characters, e.g. openssl rand -base64 48. Enables OAuth; without it the server only accepts keys sent by the client.
MCP_PUBLIC_URLPublic origin of the server, e.g. https://mcp.example.com (default https://mcp.encarapi.com). Tokens are bound to <MCP_PUBLIC_URL>/mcp.
bash
docker run -p 3000:3000 -e MCP_OAUTH_SECRET="$(openssl rand -base64 48)" \  -e MCP_PUBLIC_URL=https://mcp.example.com encarapi-mcp

This adds /.well-known/oauth-protected-resource, /.well-known/oauth-authorization-server, /register, /authorize and /token (OAuth 2.1 with PKCE, dynamic client registration). There is still no database: client ids, authorization codes and tokens are encrypted, self-contained values (AES-256-GCM) that carry the key. Consequences:

  • Changing MCP_OAUTH_SECRET signs out all OAuth clients (they reconnect through the browser).
  • Access tokens last 1 hour, refresh tokens 90 days and are replaced on every use.
  • Single use of authorization codes and of replaced refresh tokens is tracked in memory, so it is best-effort: it does not survive a restart and is not shared between instances.
  • A single token cannot be revoked on the server. Rotating the EnCarAPI key cuts off all access.

Links

EnCarAPI is an independent service and not affiliated with Encar, KB Chachacha, K Car, Dongchedi or Che168.

License

MIT

来源:README.md,提交 e1d8c9f

工具

0
工具元数据尚未被收录。

版本历史

1
  1. v1.0.1最新Oct 4, 2026