Form DP-D · Field manual

Documentation

Everything here reflects the actual package behavior — no aspirational docs.

Quickstart

Prerequisites: Python 3.11+ and a DoorDash Developer Portal access key (developer ID, key ID, signing secret). See the security model.

Not on PyPI — this runs straight from the source tree. No install step, no stale copy to update.

shell — uvx runs it from a local path
uvx --from /absolute/path/to/dashpilot-mcp dashpilot-mcp
shell
cd dashpilot-mcp
uv sync
uv run dashpilot-mcp

Then register it with your MCP client. Claude Desktop / Cursor example:

Waybill · MCP client configNo. 001042
claude_desktop_config.json
{
  "mcpServers": {
    "dashpilot": {
      "command": "uvx",
      "args": ["--from", "/absolute/path/to/dashpilot-mcp", "dashpilot-mcp"],
      "env": {
        "DASHPILOT_API_URL": "https://your-namespace.functions.fnc.fr-par.scw.cloud",
        "DASHPILOT_API_KEY": "dp_your_install_key"
      }
    }
  }
}

Drive credentials live in a .env file in your project directory — the package reads it at startup, so the key isn't duplicated into every client profile you sync:

.env
DASHPILOT_DRIVE_DEVELOPER_ID=dd_dev_...
DASHPILOT_DRIVE_KEY_ID=dd_key_...
DASHPILOT_DRIVE_KEY=your-base64-key

First prompt to try:

your agent
Check my Drive connection, then quote a delivery from my restaurant
to 350 5th Ave, New York, NY 10118. Don't dispatch yet — just the quote.

Configuration

All configuration is environment variables; any of them can also live in a project .env file (real environment variables win). HTTPS is enforced for every URL — http:// is accepted only for loopback development.

VariableDefaultWhat it does
DASHPILOT_API_KEYdp_… (issued at registration)Your install key for DashPilot Cloud — shown once when you register; save it.
DASHPILOT_API_URLhttp://localhost:8790DashPilot Cloud endpoint. Self-hosted — there is no shared public instance, so this must point at wherever you deployed the backend/ service (e.g. https://your-namespace.functions.fnc.fr-par.scw.cloud).
DASHPILOT_DRIVE_DEVELOPER_ID—From the DoorDash Developer Portal. Local only.
DASHPILOT_DRIVE_KEY_ID—Access key ID. Local only.
DASHPILOT_DRIVE_KEY—Base64 Drive access key. Used to sign JWTs on this machine.
DASHPILOT_DRIVE_BASE_URLhttps://openapi.doordash.com/drive/v2Drive API bootstrap endpoint (see managed routing).
DASHPILOT_DRIVE_ROUTINGmanagedmanaged follows the cloud's routing block (sandbox → production cutover, no env edits). manual pins the env value.
DASHPILOT_CONFIG_TTL_SECONDS300How stale the cached client config may get before a lazy refresh. Failed refreshes never fail a tool call.
DASHPILOT_STATE_FILE~/.dashpilot/state.jsonLocal state: which diagnostics check-ins this install has already reported.
DASHPILOT_TIMEOUT_S15HTTP timeout for cloud calls.

Tool reference

All sixteen tools, exactly as shipped in v0.1.0. Read-only tools never change state; makes changes tools can dispatch, spend, or modify — the package annotates them so your agent's permission policy can gate them.

No tools match that search.

Managed routing

By default (DASHPILOT_DRIVE_ROUTING=managed) the package follows the drive block in DashPilot Cloud's client config: sandbox while you test, production at go-live, endpoint migrations pushed fleet-wide — no env edits on your side. The selection is pinned to DoorDash's own hosts (or the bundled loopback simulator): a config block naming any other destination is ignored. This is endpoint selection only: signed requests always travel directly from your machine to DoorDash over TLS. DashPilot never proxies, logs, or even sees those requests. Set DASHPILOT_DRIVE_ROUTING=manual to pin your env value and opt out.

How scheduling works

  • schedule_delivery sends the unsigned delivery payload to DashPilot Cloud with a dispatch_at time.
  • Your local server polls the due queue (dispatch_due_deliveries) — on a cron, or whenever your agent decides.
  • When work is due, the package mints a fresh 60-second JWT on your machine and dispatches directly to DoorDash.
  • The cloud backend holds no credential at any point — it cannot dispatch, early or late, ever. If DashPilot Cloud is down, your past-due work simply waits for the next poll; nothing can fire without your key.

FAQ

No. DashPilot is an independent, unofficial project. DoorDash and Drive are trademarks of DoorDash, Inc. We use the public Drive API exactly as documented.
In your MCP client's env config on your machine. The local server reads it to sign JWTs. See Security.
Crash reports only, and redacted structurally: when a tool call fails, the record keeps the tool name, error code, and argument shapes (strings and numbers are replaced by their types — no address, phone, key, or free text can ride along). Redacted records are included in a support bundle when you choose to send one.
Unsigned scheduled-delivery payloads (addresses and order values you chose to schedule), your delivery reports for the ops board, and your client config. No credentials, no tokens, no payment instruments.
DoorDash, directly, through your Drive account. DashPilot runs no billing and never touches money.
Quoting, dispatch, tracking, updates, and cancellation are unaffected — those go straight to DoorDash. Scheduling pauses: due work waits for the next successful poll. Your agent can always dispatch directly with dispatch_delivery.
Any client that speaks MCP over stdio: Cursor, Claude Desktop, and others. The server is a plain Python process — no sidecars, no daemons beyond what you configure.