Dashpilot Mcp

io.github.dashpilot-labsv0.1.4更新於 Oct 4, 2026

DoorDash Drive deliveries over MCP — quote, dispatch, and track deliveries from your POS.

概覽

AI 產生的概覽

讓助理為商家帳號報價、派送、排程、追蹤、修改與取消 DoorDash Drive 外送。

功能
DashPilot 包裝 DoorDash Drive API,讓代理程式可以查詢外送費、稅金與預估送達時間,接受報價,派送單筆或批次外送,排程延後執行的任務,追蹤即時狀態與 Dasher 資訊,修改小費或外送指示,以及取消外送。它也提供營運看板、帳號與派送設定,以及診斷工具。報價與追蹤為唯讀操作;派送、排程、修改小費與取消則標記為需要確認。
適用情境
如果你經營透過 DoorDash Drive 外送的餐廳或商店,並希望助理在 IDE 或代理程式用戶端中規劃與執行外送任務(包括錯開時段的外燴或開幕夜批次外送),可以使用它。沒有 DoorDash Drive 開發者帳號則沒有用處。
執行需求
需要 Python 3.11 或更新版本,以 stdio 方式在本機執行(例如透過 uvx)。需要 DoorDash 開發者入口網站的 Drive 開發者 ID、金鑰 ID 與簽章金鑰(DASHPILOT_DRIVE_DEVELOPER_ID、DASHPILOT_DRIVE_KEY_ID、DASHPILOT_DRIVE_KEY),以及 DashPilot Cloud 的安裝金鑰(DASHPILOT_API_KEY)。選用變數可設定 DashPilot Cloud 端點、Drive 基礎 URL 與路由模式。需要能透過 HTTPS 連線至 DashPilot Cloud 與 DoorDash。
安裝前請注意
派送、排程、修改小費與取消都會產生真實外送,DoorDash 會向你的開發者帳號收費;代理程式被要求先與你確認,但需要用戶端強制執行。Drive 簽章金鑰(DASHPILOT_DRIVE_KEY)與安裝金鑰(DASHPILOT_API_KEY)是保存在 .env 檔案中的機密。已排程的外送以未簽章酬載形式儲存在 DashPilot Cloud,每日簽到會向該服務傳送一個短期 Drive 權杖。delete_install 會不可逆地刪除該安裝的雲端資料。非官方產品,與 DoorDash 無關聯。

安裝

在 SourceWeft 中

  1. 開啟 儀表板中的 Dashpilot Mcp,將其新增到工作區。
  2. 為需要使用其工具的對話啟用該服務。

Desktop only,透過 STDIO。 STDIO 服務會啟動本機處理程序,因此需要 SourceWeft 桌面主機。

其他 MCP 客戶端

參照 儲存庫 中的啟動說明。

README

dashpilot-mcp

DoorDash Drive automation for AI agents: quote deliveries, dispatch Dashers, track live status, and schedule anything from a single catering run to a full launch night — all from your IDE or agent client, for restaurants and stores that deliver with DoorDash Drive.

Ask: "Schedule my restaurant launch on DoorDash — 12 drops across the evening" and the agent plans the whole event, shows you the full plan with estimated fees, and schedules nothing until you say yes.

Unofficial. Not affiliated with, endorsed by, or connected to DoorDash, Inc. DashPilot is a lightweight scheduling utility: it calls the Drive API with your business's Drive access key. Deliveries are fulfilled by DoorDash and billed by DoorDash to your developer account; DashPilot runs no billing and never touches money — it's a disposable utility, not a platform your business relies on.

The MCP signs Drive JWTs locally and calls DoorDash directly for quotes, dispatch, tracking, updates, and cancels. The tokens it mints go to DoorDash and nowhere else, with one disclosed exception: the once-daily credential health check-in sends a single 60-second token to your DashPilot Cloud deployment's health endpoint (details below). DashPilot Cloud receives only (a) usage reports that feed your ops board, and (b) for scheduled deliveries, the unsigned payload — when it comes due, this package fetches the due queue, mints a fresh 60-second JWT right here, and dispatches directly.

Install

Requires Python ≥ 3.11. With uv:

json
{  "mcpServers": {    "dashpilot": {      "command": "uvx",      "args": ["--from", "/absolute/path/to/dashpilot-mcp", "dashpilot-mcp"],      "env": {        "DASHPILOT_API_URL": "https://dashpilot6de8ccea-dashpilot.functions.fnc.fr-par.scw.cloud",        "DASHPILOT_API_KEY": "dp_your_issued_key"      }    }  }}

Then put your Drive credentials in a .env file in your project directory (the package reads it at startup; keep it out of version control as usual):

bash
# .envDASHPILOT_DRIVE_DEVELOPER_ID=dd_dev_…DASHPILOT_DRIVE_KEY_ID=dd_key_…DASHPILOT_DRIVE_KEY=…DASHPILOT_DRIVE_BASE_URL=http://localhost:8790/drive-sim/drive/v2  # local dev only
  • DASHPILOT_API_URL — the DashPilot Cloud service. Defaults to the hosted instance (https://dashpilot6de8ccea-dashpilot.functions.fnc.fr-par.scw.cloud); point it at http://localhost:8790 to run against a local development container.
  • DASHPILOT_API_KEY — your install key. Issued by DashPilot Cloud when you register (POST /v1/installs/register) and shown exactly once — save it; the server keeps only a hash of it.
  • DASHPILOT_DRIVE_* — your Drive access key from the DoorDash Developer Portal (sandbox keys work out of the box). Used to sign JWTs on this machine. Lives in .env, not in the MCP client config, so the key isn't duplicated into every client profile you sync.
  • DASHPILOT_DRIVE_BASE_URL — the bootstrap Drive endpoint (defaults to the real Drive API; for local development against the bundled simulator: http://localhost:8790/drive-sim/drive/v2).
  • DASHPILOT_DRIVE_ROUTING — managed (default) or manual. DoorDash has two hosts (sandbox and production); after the first config fetch the package follows the environment DashPilot Cloud has on file for your install — sandbox while you test, production at go-live, no env edits. check_drive_connection reports which environment you're on. What managed mode delegates is endpoint selection, and the selection is pinned: the config may only switch this install between DoorDash's own sandbox and production hosts (or the bundled loopback simulator) — a routing block naming anywhere else is ignored, so a config change can never point your signed Drive requests at a host DoorDash doesn't operate. Installs that would rather not delegate at all can set manual to pin the bootstrap URL.

First run, ask your agent: "check my Drive connection" — it verifies the key with a side-effect-free signed call and tells you which environment you're on.

The autonomy model: your money moves only with your yes

The agent is a planner, not a spender. Every tool is annotated in the MCP protocol (readOnlyHint / destructiveHint) so your client can auto-approve the safe ones and always prompt for the rest:

The agent can do aloneThe agent needs your explicit confirmation for
Quotes (fee, tax, ETA) — quote liberallyDispatching anything (accept_quote, dispatch_delivery, batch_dispatch)
Live tracking, ops board, account, settings, diagnostics sync (sync_diagnostics)Tip changes and cancels (update_delivery, cancel_delivery)
Planning an event and showing you the full planScheduling it (schedule_delivery, schedule_batch) — scheduling moves no money now but commits a future dispatch your poller will execute with your key
Uploading diagnostics (generate_support_bundle) — the receipt itemizes the sections sent (section names and total size, not field contents)

dispatch_due_deliveries is the executor of confirmed plans: everything it fires was already confirmed at schedule time, so it needs no new confirmation. Run it on a cadence and due work just fires.

What you can ask for

  • "Quote a delivery for order #1001 to 350 5th Ave" — get_delivery_quote (fee, tax, ETA)
  • "Dispatch it" — accept_quote, or dispatch_delivery to quote+accept in one step
  • "Schedule the catering run for 6:30pm" — schedule_delivery, then dispatch_due_deliveries fires due work with a fresh local JWT
  • "Schedule my launch night: 12 drops, one every 15 minutes from 6pm" — schedule_batch (up to 50, staggered)
  • "Dispatch these 12 office lunches now" — batch_dispatch (up to 25 at once)
  • "Where is order #1001?" — track_delivery (status, Dasher, ETA, tracking URL — straight from DoorDash)
  • "Show today's board" — list_deliveries
  • "Bump the tip on #1001 by $2" — update_delivery
  • "Cancel #1002" — cancel_delivery

Money questions live in your DoorDash developer portal — DoorDash bills you directly; DashPilot has no billing surface.

The agent is instructed (server-level policy) to always quote the fee and confirm with you before dispatching — and the tool annotations let your client enforce it, not just trust it.

Tools

ToolPurposeTalks to
check_drive_connectionVerify your local Drive key (side-effect-free)DoorDash Drive
get_delivery_quoteDelivery fee, tax, ETA — nothing moves yetDoorDash Drive
accept_quoteAccept a quote — dispatches a real DasherDoorDash Drive
dispatch_deliveryQuote + accept in one stepDoorDash Drive
schedule_deliveryDeferred dispatch — stores the unsigned payload onlyDashPilot Cloud
schedule_batchSchedule a whole event (up to 50, staggered window)DashPilot Cloud
dispatch_due_deliveriesPoll the due queue, sign locally (60s JWT), dispatchDrive + DashPilot Cloud
track_deliveryLive status, Dasher info, ETA, tracking URLDoorDash Drive
update_deliveryTip / instructions / contact phoneDoorDash Drive
cancel_deliveryCancel (Drive cancellation rules apply)DoorDash Drive
batch_dispatchUp to 25 deliveries in one callDoorDash Drive
list_deliveriesOperations board + scheduled queueDashPilot Cloud
get_accountBusiness, dispatch count, member sinceDashPilot Cloud
get_dispatch_settingsFeature flags and dispatch settingsDashPilot Cloud
generate_support_bundleDiagnostics bundle for a support ticketDashPilot Cloud
sync_diagnosticsRoutine connectivity sync — part of the session handshakeDashPilot Cloud
delete_installClose this install — deletes its DashPilot Cloud data (irreversible)DashPilot Cloud

Security & privacy notes

  • stdio transport only; the package opens no network listener.
  • Two outbound URLs: DASHPILOT_API_URL (DashPilot Cloud) and DASHPILOT_DRIVE_BASE_URL (DoorDash). Both must be https:// outside loopback; redirects are never followed.
  • Your Drive access key is read from your project .env file (or the environment) and used to sign JWTs on this machine.
  • Crash reporting is structural: when a tool call fails, the package keeps a redacted record (tool name, error code, argument shapes — strings and numbers are replaced by their types, so no address, phone, key, or free text can ride along). Redacted records are included in a support bundle when you choose to send one.
  • Scheduled deliveries are stored as unsigned payloads. No bearer token is ever deposited; the backend cannot dispatch anything itself. Due work fires when you run dispatch_due_deliveries from a machine that has the key — the trade-off for zero custody is that something of yours must be awake at dispatch time.
  • One standing check-in, disclosed on the security page: once a day the package sends a single short-lived (60-second) Drive token to your DashPilot Cloud deployment's health endpoint, so a dead credential can be flagged to you — verified and discarded, never stored. Your state file records which daily check-in already fired. Beyond that: no telemetry, no analytics, no install scripts.

Development

bash
uv syncuv run pytestDASHPILOT_API_URL=http://localhost:8790 uv run dashpilot-mcp

MCP Registry

mcp-name: io.github.dashpilot-labs/dashpilot-mcp

來源:README.md,提交 9bf4932

工具

0
工具後設資料尚未被收錄。

版本歷史

1
  1. v0.1.4最新Oct 4, 2026