Everything here reflects the actual package behavior — no aspirational docs.
Prerequisites: Python 3.11+ and a DoorDash Developer Portal access key (developer ID, key ID, signing secret). See the security model.
Not on PyPI — this runs straight from the source tree. No install step, no stale copy to update.
uvx --from /absolute/path/to/dashpilot-mcp dashpilot-mcp
cd dashpilot-mcp uv sync uv run dashpilot-mcp
Then register it with your MCP client. Claude Desktop / Cursor example:
{
"mcpServers": {
"dashpilot": {
"command": "uvx",
"args": ["--from", "/absolute/path/to/dashpilot-mcp", "dashpilot-mcp"],
"env": {
"DASHPILOT_API_URL": "https://dashpilot6de8ccea-dashpilot.functions.fnc.fr-par.scw.cloud",
"DASHPILOT_API_KEY": "dp_your_install_key"
}
}
}
}Drive credentials live in a .env file in your project directory —
the package reads it at startup, so the key isn't duplicated into every client
profile you sync:
DASHPILOT_DRIVE_DEVELOPER_ID=dd_dev_... DASHPILOT_DRIVE_KEY_ID=dd_key_... DASHPILOT_DRIVE_KEY=your-base64-key
First prompt to try:
Check my Drive connection, then quote a delivery from my restaurant to 350 5th Ave, New York, NY 10118. Don't dispatch yet — just the quote.
All configuration is environment variables; any of them can also live in a
project .env file (real environment variables win). HTTPS is enforced
for every URL — http:// is accepted only for loopback development.
| Variable | Default | What it does |
|---|---|---|
DASHPILOT_API_KEY | dp_… (issued at registration) | Your install key for DashPilot Cloud — shown once when you register; save it. |
DASHPILOT_API_URL | https://dashpilot6de8ccea-dashpilot.functions.fnc.fr-par.scw.cloud | DashPilot Cloud endpoint — defaults to the hosted service; set http://localhost:8790 to run against a local development container. |
DASHPILOT_DRIVE_DEVELOPER_ID | — | From the DoorDash Developer Portal. Local only. |
DASHPILOT_DRIVE_KEY_ID | — | Access key ID. Local only. |
DASHPILOT_DRIVE_KEY | — | Base64 Drive access key. Used to sign JWTs on this machine. |
DASHPILOT_DRIVE_BASE_URL | https://openapi.doordash.com/drive/v2 | Drive API bootstrap endpoint (see managed routing). |
DASHPILOT_DRIVE_ROUTING | managed | managed follows the cloud's routing block (sandbox → production cutover, no env edits). manual pins the env value. |
DASHPILOT_CONFIG_TTL_SECONDS | 300 | How stale the cached client config may get before a lazy refresh. Failed refreshes never fail a tool call. |
DASHPILOT_STATE_FILE | ~/.dashpilot/state.json | Local state: which diagnostics check-ins this install has already reported. |
DASHPILOT_TIMEOUT_S | 15 | HTTP timeout for cloud calls. |
All sixteen tools, exactly as shipped in v0.1.0. Read-only tools never change state; makes changes tools can dispatch, spend, or modify — the package annotates them so your agent's permission policy can gate them.
By default (DASHPILOT_DRIVE_ROUTING=managed) the package follows the
drive block in DashPilot Cloud's client config: sandbox while you test,
production at go-live, endpoint migrations pushed fleet-wide — no env edits on your side.
The selection is pinned to DoorDash's own hosts (or the bundled loopback simulator):
a config block naming any other destination is ignored. This is endpoint selection only:
signed requests always travel directly from your machine to DoorDash over TLS. DashPilot
never proxies, logs, or even sees those requests. Set DASHPILOT_DRIVE_ROUTING=manual
to pin your env value and opt out.
schedule_delivery sends the unsigned delivery payload to DashPilot Cloud with a dispatch_at time.dispatch_due_deliveries) — on a cron, or whenever your agent decides.env config on your machine. The local server reads it to sign JWTs. See Security.dispatch_delivery.