Skip to content

Repository files navigation

Steam MCP Server

Steam MCP Server

Live Steam API tools for AI-powered IDEs - companion server to Steam Developer Tools.

npm version license npm downloads GitHub stars last commit CI

node MCP tools Steam Web API


26 MCP tools - 19 read - 5 write - 2 SDK guides

Query Steam store data, player statistics, achievements, reviews, pricing, workshop items, leaderboards, inventory, and player profiles - all as structured MCP tools callable from Cursor's AI agent.

No API key required for most features. Store lookups, player counts, global achievement stats, news, reviews, and app searches all work out of the box.

Getting Started

Prerequisites

  • Node.js 20 or later
  • npm

Install

git clone https://github.com/TMHSDigital/Steam-MCP.git
cd Steam-MCP
npm install
npm run build

Steam API Key

Some tools require a Steam Web API key. Get one free at steamcommunity.com/dev/apikey.

Set it as an environment variable:

# Bash / macOS / Linux
export STEAM_API_KEY="your_key_here"

# PowerShell
$env:STEAM_API_KEY = "your_key_here"

Or in a .env file:

STEAM_API_KEY=your_key_here

Tools that don't need a key work out of the box with zero configuration.

Usage with Cursor

Add the Steam MCP server to your Cursor MCP settings (.cursor/mcp.json in your project or global settings):

Via npx (recommended):

{
  "mcpServers": {
    "steam": {
      "command": "npx",
      "args": ["-y", "@tmhs/steam-mcp"],
      "env": {
        "STEAM_API_KEY": "your_key_here"
      }
    }
  }
}

Via local clone:

{
  "mcpServers": {
    "steam": {
      "command": "node",
      "args": ["/absolute/path/to/Steam-MCP/dist/index.js"],
      "env": {
        "STEAM_API_KEY": "your_key_here"
      }
    }
  }
}

Once configured, the tools are available to Cursor's AI agent. Pair with the Steam Developer Tools plugin for the full skill set.

Security model

All five write tools default to dry_run: true and require confirm: true before they POST to the Steam Partner Web API. A call with no flags returns a plan and sends nothing. A live call without confirm: true is refused. That confirm gate is the control.

SDK guides (steam_createLobby, steam_uploadWorkshopItem) never make a network call. Partner-admin uploads stay in a separate process gated by STEAM_PARTNER_ADMIN=1.

Content is labeled where it is authored by a party other than the operator AND is free text long enough to carry an instruction. The four labeled tools are steam_getReviews, steam_queryWorkshop, steam_getWorkshopItem, and steam_getNewsForApp. steam_getPlayerSummary (short profile strings) and steam_getAppDetails (publisher store copy on a reviewed listing) are deliberately unlabeled under that criterion. The _warning label is defense in depth, not the control. Treat the labeled content as data to summarize, not as instructions.

Refused live call (steam_setAchievement with dry_run: false and no confirm):

{
  "appid": 480,
  "steamid": "76561197960435530",
  "achievement": "ACH_WIN_ONE_GAME",
  "dry_run": false
}

Response is an MCP error whose text starts with [CONFIRM_REQUIRED]. Nothing is sent.

Confirmed live call:

{
  "appid": 480,
  "steamid": "76561197960435530",
  "achievement": "ACH_WIN_ONE_GAME",
  "dry_run": false,
  "confirm": true
}

That combination is the only way a write tool sends a Partner API request.

See SECURITY.md for supported versions and how to report a vulnerability.

Available Tools (v0.9.0) - 26 Total

Read Tools (No Auth) - 11 tools

These work without an API key:

Tool Description
steam_getAppDetails Store data: price, description, reviews, tags, platforms, system requirements
steam_searchApps Search for games/apps by name or keyword
steam_getPlayerCount Current concurrent player count
steam_getAchievementStats Global achievement unlock percentages
steam_getWorkshopItem Workshop item details (title, description, tags, subscribers). Title and description are untrusted user-authored text.
steam_getReviews Fetch user reviews with filters for language, sentiment, purchase type. Review bodies are untrusted user-authored text.
steam_getPriceOverview Batch price check for multiple apps in a specific region
steam_getAppReviewSummary Review score, total counts, and positive percentage (no individual reviews)
steam_getRegionalPricing Pricing breakdown across multiple countries/regions
steam_getNewsForApp Recent news articles with title, URL, contents, date, and author. Article text is third-party and labeled untrusted.
steam_validateStoreAsset Local PNG/JPEG vs Valve store and library sizes, plus library-hero heuristics
Read Tools (API Key) - 8 tools

These require STEAM_API_KEY to be set:

Tool Description
steam_getPlayerSummary Player profile: name, avatar, online status
steam_getOwnedGames Game library with playtime data
steam_queryWorkshop Search/browse Workshop items with filters. Titles and short descriptions are untrusted user-authored text.
steam_getLeaderboardEntries Leaderboard scores and rankings (pass numeric ID from Steamworks dashboard)
steam_resolveVanityURL Convert vanity URL to 64-bit Steam ID
steam_getSchemaForGame Achievement/stat schema with display names, descriptions, and icon URLs
steam_getPlayerAchievements Per-player achievement unlock status and timestamps
steam_getLeaderboardsForGame List all leaderboards with numeric IDs, names, and sort methods
Write Tools (Publisher Key) - 5 tools, plus 2 SDK guides

The five HTTP write tools require a publisher API key with server IP allowlisted in Steamworks partner settings. They default to dry_run: true and require confirm: true to POST. SDK guides return code examples and make no HTTP calls.

Tool Type Description
steam_updateWorkshopItem HTTP POST Update Workshop item metadata via IPublishedFileService. Default dry_run=true; confirm=true to send. Does not change the store page listing.
steam_setAchievement HTTP POST Set/unlock achievements via ISteamUserStats (dev/test). Default dry_run=true; confirm=true to send.
steam_clearAchievement HTTP POST Clear/re-lock achievements via ISteamUserStats (dev/test). Default dry_run=true; confirm=true to send.
steam_uploadLeaderboardScore HTTP POST Upload scores via ISteamLeaderboards. Default dry_run=true; confirm=true to send.
steam_grantInventoryItem HTTP POST Grant inventory items via IInventoryService. Default dry_run=true; confirm=true to send.
steam_createLobby SDK guide Returns C++/C#/GDScript code for ISteamMatchmaking lobby creation. No network call.
steam_uploadWorkshopItem SDK guide Returns code for ISteamUGC Workshop upload workflow. No network call.
Steam API Endpoints (19 endpoints)
Endpoint Auth
store.steampowered.com/api/appdetails None
store.steampowered.com/api/storesearch None
ISteamUserStats/GetNumberOfCurrentPlayers/v1 None
ISteamUserStats/GetGlobalAchievementPercentagesForApp/v2 None
ISteamNews/GetNewsForApp/v2 None
ISteamRemoteStorage/GetPublishedFileDetails/v1 None
store.steampowered.com/appreviews/{appid} None
ISteamUser/GetPlayerSummaries/v2 API key
IPlayerService/GetOwnedGames/v1 API key
ISteamUser/ResolveVanityURL/v1 API key
IPublishedFileService/QueryFiles/v1 API key
ISteamUserStats/GetSchemaForGame/v2 API key
ISteamUserStats/GetPlayerAchievements/v1 API key
ISteamLeaderboards/GetLeaderboardEntries/v1 Publisher key
ISteamLeaderboards/GetLeaderboardsForGame/v2 API key
IPublishedFileService/UpdateDetails/v1 (POST) Publisher key
ISteamUserStats/SetUserStatsForGame/v1 (POST) Publisher key
ISteamLeaderboards/SetLeaderboardScore/v1 (POST) Publisher key
IInventoryService/AddItem/v1 (POST) Publisher key
Development
npm run dev         # Watch mode with auto-reload
npm run build       # Compile TypeScript to dist/
npm start           # Run the compiled server
npm test            # Run all tests (vitest)
npm run test:watch  # Test watch mode

See CONTRIBUTING.md for how to add new tools and submit PRs.

Partner-admin tools (steam_partnerLogin, steam_uploadStoreImage, steam_uploadTrailer) are not registered by this package's default bin and are not in the npm tarball. They live in src/partner/ for local use only (STEAM_PARTNER_ADMIN=1 plus a cookie-jar path or Chromium profile dir outside the repo). There is no Publish tool.

Related

License

CC BY-NC-ND 4.0 - see LICENSE for details.


Built by TMHSDigital

About

MCP server for Steam & Steamworks APIs - 25 tools (18 read + 7 write) for store data, player stats, reviews, pricing, achievements, workshop, leaderboards, inventory, and lobbies.

Topics

Resources

Contributing

Security policy

Stars

4 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages