🎩 You're Invited:Meet the Socket team at Black Hat in Las Vegas, August 3-6.RSVP
Sign In

@theyahia/hh-mcp

Package Overview
Dependencies
Maintainers
1
Versions
7
Alerts
File Explorer

Advanced tools

Socket logo

Install Socket

Detect and block malicious and high-risk dependencies

Install

@theyahia/hh-mcp

MCP server for HeadHunter — vacancy search, resumes, salary stats (Russia)

latest
Source
npmnpm
Version
2.1.0
Version published
Weekly downloads
67
71.79%
Maintainers
1
Weekly downloads
 
Created
Source

@theyahia/hh-mcp

MCP server for the hh.ru API — Russia and CIS job market. 19 tools covering vacancies, resumes, employers, salary statistics, dictionaries, autocomplete, and token diagnostics.

Responses are returned as compact, LLM-friendly summaries by default — pass raw: true to any search/detail tool to get the full hh.ru JSON.

npm CI License: MIT

Part of the Russian API MCP series by @theYahia.

Two Modes

ModeWhat's availableToken needed?
No tokenVacancy search, vacancy by ID, similar vacancies, employers, salary stats, areas, roles, industries, metro, dictionaries, suggests, token checkNo
With tokenEverything above + resume search, resume by IDYes (HH_ACCESS_TOKEN)

Get a token at dev.hh.ru/admin. Note: resume search additionally requires an employer account with a paid resume-database subscription — applicant/anonymous tokens get a 403. Use validate_token to check what your token can do.

Installation

Claude Desktop

{
  "mcpServers": {
    "hh": {
      "command": "npx",
      "args": ["-y", "@theyahia/hh-mcp"],
      "env": {
        "HH_ACCESS_TOKEN": "optional-oauth-token"
      }
    }
  }
}

Claude Code

claude mcp add hh -- npx -y @theyahia/hh-mcp
# With token:
claude mcp add hh -e HH_ACCESS_TOKEN=your-token -- npx -y @theyahia/hh-mcp

VS Code / Cursor

{
  "servers": {
    "hh": {
      "command": "npx",
      "args": ["-y", "@theyahia/hh-mcp"]
    }
  }
}

Windsurf

{
  "mcpServers": {
    "hh": {
      "command": "npx",
      "args": ["-y", "@theyahia/hh-mcp"]
    }
  }
}

HTTP Mode (Streamable HTTP)

npx @theyahia/hh-mcp --http
# or
HTTP_PORT=8080 npx @theyahia/hh-mcp --http

Endpoint: http://localhost:3000/mcp (POST) · Health check: http://localhost:3000/health (GET)

HTTP mode is stateless and binds to 127.0.0.1 by default with DNS-rebinding protection on. To expose it, set HOST=0.0.0.0 and add your host/origin to HH_ALLOWED_HOSTS / HH_ALLOWED_ORIGINS, and put it behind your own auth.

Environment Variables

VariableRequiredDescription
HH_ACCESS_TOKENNoOAuth 2.0 Bearer token. Required for resume endpoints (employer + paid resume DB).
HH_USER_AGENTNoCustom HH-User-Agent (hh.ru requires it). Recommend your-app/1.0 (you@example.com).
HTTP_PORT / PORTNoPort for HTTP mode (default: 3000).
HOSTNoInterface to bind in HTTP mode (default: 127.0.0.1).
HH_ALLOWED_HOSTSNoComma-separated Host allow-list for HTTP mode (default: loopback).
HH_ALLOWED_ORIGINSNoComma-separated Origin allow-list for HTTP mode.

See .env.example.

Tools (19)

Every search/detail tool accepts raw: true to return the full hh.ru JSON instead of the compact summary.

Vacancies

ToolDescriptionToken?
search_vacanciesSearch by keywords, region, professional role, industry, metro, employer, salary, experience, work format / employment form, date range (period or date_from/date_to), labels, search field, with sorting and paginationNo
get_vacancyFull vacancy details: description, requirements, key skills, contactsNo
get_similar_vacanciesFind vacancies similar to a given oneNo

Resumes (employer token + paid resume DB)

ToolDescriptionToken?
search_resumesSearch candidate resumes by keywords, region, role, salary, experienceYes
get_resumeFull resume: experience, education, skills, contactsYes

Employers

ToolDescriptionToken?
search_employersSearch companies by name and regionNo
get_employerEmployer profile: description, industries, website, vacancy countNo
get_employer_vacanciesList active vacancies for a specific employerNo

Dictionaries & Suggests

ToolDescriptionToken?
get_areasTree of regions and cities (id — name)No
get_areas_subtreeRegions/cities under one area id — lighter than the full treeNo
get_professional_rolesTree of professional roles with IDsNo
get_industriesTree of company industries with IDsNo
get_metroMetro stations/lines with IDs for a cityNo
get_dictionariesAll reference data: currencies, employment types, schedules, experience, labelsNo
suggest_positionsAutocomplete job titlesNo
suggest_companiesAutocomplete company namesNo
suggest_areasAutocomplete region/city namesNo

Salary & Account

ToolDescriptionToken?
get_salary_statisticsEstimated salary distribution (median, P25/P75, min/max) for a role in a region, computed from posted vacancy salaries. Biased sample, not official market data.No
validate_tokenCheck whether HH_ACCESS_TOKEN is valid (via /me) and report the account roleNo

Rate Limiting

Built-in rate limiter respects the hh.ru API limit of 5 requests per second. Automatic retry with exponential backoff on 429 and 5xx errors (up to 3 attempts). Note: the limiter is process-global, so in shared HTTP mode all clients share one 5 req/s budget.

Demo Prompts

Find remote Python developer jobs in Moscow paying over 300,000 RUB
Show me all open vacancies at Yandex and give me salary statistics for their top roles
Compare Senior Backend salaries in Moscow vs Saint Petersburg, and suggest similar vacancies to the best-paying one

Development

git clone https://github.com/theYahia/hh-mcp.git
cd hh-mcp
npm install
npm run build
npm test

API Reference

License

MIT

Keywords

mcp

FAQs

Package last updated on 23 Jun 2026

Did you know?

Socket

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Install

Related posts