
Dashpilot Mcp
io.github.dashpilot-labsv0.1.4更新于 Oct 4, 2026
DoorDash Drive deliveries over MCP — quote, dispatch, and track deliveries from your POS.
概览
让助手为商家账户报价、派单、安排、跟踪、修改和取消 DoorDash Drive 配送。
- 功能
- DashPilot 封装 DoorDash Drive API,让智能体可以查询配送费、税费和预计送达时间,接受报价,派发单笔或批量配送,安排延迟执行的任务,跟踪实时状态和 Dasher 信息,修改小费或配送说明,以及取消配送。它还提供运营看板、账户与派单设置,以及诊断工具。报价和跟踪为只读操作;派单、排期、修改小费和取消被标记为需要确认。
- 适用场景
- 如果你经营通过 DoorDash Drive 配送的餐厅或商店,并希望助手在 IDE 或智能体客户端中规划和执行配送任务(包括错峰的企业餐饮或开业夜批量配送),可以使用它。没有 DoorDash Drive 开发者账户则没有用处。
- 运行要求
- 需要 Python 3.11 或更高版本,以 stdio 方式在本地运行(例如通过 uvx)。需要 DoorDash 开发者门户的 Drive 开发者 ID、密钥 ID 和签名密钥(DASHPILOT_DRIVE_DEVELOPER_ID、DASHPILOT_DRIVE_KEY_ID、DASHPILOT_DRIVE_KEY),以及 DashPilot Cloud 的安装密钥(DASHPILOT_API_KEY)。可选变量用于设置 DashPilot Cloud 端点、Drive 基础 URL 和路由模式。需要能通过 HTTPS 访问 DashPilot Cloud 和 DoorDash。
安装
在 SourceWeft 中
- 打开 控制台中的 Dashpilot Mcp,将其添加到工作区。
- 为需要使用其工具的对话启用该服务。
Desktop only,通过 STDIO。 STDIO 服务会启动本地进程,因此需要 SourceWeft 桌面宿主。
其他 MCP 客户端
参照 仓库 中的启动说明。
README
dashpilot-mcp
DoorDash Drive automation for AI agents: quote deliveries, dispatch Dashers, track live status, and schedule anything from a single catering run to a full launch night — all from your IDE or agent client, for restaurants and stores that deliver with DoorDash Drive.
Ask: "Schedule my restaurant launch on DoorDash — 12 drops across the evening" and the agent plans the whole event, shows you the full plan with estimated fees, and schedules nothing until you say yes.
Unofficial. Not affiliated with, endorsed by, or connected to DoorDash, Inc. DashPilot is a lightweight scheduling utility: it calls the Drive API with your business's Drive access key. Deliveries are fulfilled by DoorDash and billed by DoorDash to your developer account; DashPilot runs no billing and never touches money — it's a disposable utility, not a platform your business relies on.
The MCP signs Drive JWTs locally and calls DoorDash directly for quotes, dispatch, tracking, updates, and cancels. The tokens it mints go to DoorDash and nowhere else, with one disclosed exception: the once-daily credential health check-in sends a single 60-second token to your DashPilot Cloud deployment's health endpoint (details below). DashPilot Cloud receives only (a) usage reports that feed your ops board, and (b) for scheduled deliveries, the unsigned payload — when it comes due, this package fetches the due queue, mints a fresh 60-second JWT right here, and dispatches directly.
Install
Requires Python ≥ 3.11. With uv:
Then put your Drive credentials in a .env file in your project directory (the
package reads it at startup; keep it out of version control as usual):
DASHPILOT_API_URL— the DashPilot Cloud service. Defaults to the hosted instance (https://dashpilot6de8ccea-dashpilot.functions.fnc.fr-par.scw.cloud); point it athttp://localhost:8790to run against a local development container.DASHPILOT_API_KEY— your install key. Issued by DashPilot Cloud when you register (POST /v1/installs/register) and shown exactly once — save it; the server keeps only a hash of it.DASHPILOT_DRIVE_*— your Drive access key from the DoorDash Developer Portal (sandbox keys work out of the box). Used to sign JWTs on this machine. Lives in.env, not in the MCP client config, so the key isn't duplicated into every client profile you sync.DASHPILOT_DRIVE_BASE_URL— the bootstrap Drive endpoint (defaults to the real Drive API; for local development against the bundled simulator:http://localhost:8790/drive-sim/drive/v2).DASHPILOT_DRIVE_ROUTING—managed(default) ormanual. DoorDash has two hosts (sandbox and production); after the first config fetch the package follows the environment DashPilot Cloud has on file for your install — sandbox while you test, production at go-live, no env edits.check_drive_connectionreports which environment you're on. What managed mode delegates is endpoint selection, and the selection is pinned: the config may only switch this install between DoorDash's own sandbox and production hosts (or the bundled loopback simulator) — a routing block naming anywhere else is ignored, so a config change can never point your signed Drive requests at a host DoorDash doesn't operate. Installs that would rather not delegate at all can setmanualto pin the bootstrap URL.
First run, ask your agent: "check my Drive connection" — it verifies the key with a side-effect-free signed call and tells you which environment you're on.
The autonomy model: your money moves only with your yes
The agent is a planner, not a spender. Every tool is annotated in the MCP protocol
(readOnlyHint / destructiveHint) so your client can auto-approve the safe ones and
always prompt for the rest:
dispatch_due_deliveries is the executor of confirmed plans: everything it fires was
already confirmed at schedule time, so it needs no new confirmation. Run it on a cadence
and due work just fires.
What you can ask for
- "Quote a delivery for order #1001 to 350 5th Ave" —
get_delivery_quote(fee, tax, ETA) - "Dispatch it" —
accept_quote, ordispatch_deliveryto quote+accept in one step - "Schedule the catering run for 6:30pm" —
schedule_delivery, thendispatch_due_deliveriesfires due work with a fresh local JWT - "Schedule my launch night: 12 drops, one every 15 minutes from 6pm" —
schedule_batch(up to 50, staggered) - "Dispatch these 12 office lunches now" —
batch_dispatch(up to 25 at once) - "Where is order #1001?" —
track_delivery(status, Dasher, ETA, tracking URL — straight from DoorDash) - "Show today's board" —
list_deliveries - "Bump the tip on #1001 by $2" —
update_delivery - "Cancel #1002" —
cancel_delivery
Money questions live in your DoorDash developer portal — DoorDash bills you directly; DashPilot has no billing surface.
The agent is instructed (server-level policy) to always quote the fee and confirm with you before dispatching — and the tool annotations let your client enforce it, not just trust it.
Tools
Security & privacy notes
- stdio transport only; the package opens no network listener.
- Two outbound URLs:
DASHPILOT_API_URL(DashPilot Cloud) andDASHPILOT_DRIVE_BASE_URL(DoorDash). Both must behttps://outside loopback; redirects are never followed. - Your Drive access key is read from your project
.envfile (or the environment) and used to sign JWTs on this machine. - Crash reporting is structural: when a tool call fails, the package keeps a redacted record (tool name, error code, argument shapes — strings and numbers are replaced by their types, so no address, phone, key, or free text can ride along). Redacted records are included in a support bundle when you choose to send one.
- Scheduled deliveries are stored as unsigned payloads. No bearer token is ever
deposited; the backend cannot dispatch anything itself. Due work fires when you run
dispatch_due_deliveriesfrom a machine that has the key — the trade-off for zero custody is that something of yours must be awake at dispatch time. - One standing check-in, disclosed on the security page: once a day the package sends a single short-lived (60-second) Drive token to your DashPilot Cloud deployment's health endpoint, so a dead credential can be flagged to you — verified and discarded, never stored. Your state file records which daily check-in already fired. Beyond that: no telemetry, no analytics, no install scripts.
Development
MCP Registry
mcp-name: io.github.dashpilot-labs/dashpilot-mcp
来源:README.md,提交 9bf4932
工具
0版本历史
1- v0.1.4最新Oct 4, 2026

