Your developer says the store needs Shopify MCP. A vendor says its agent already has it. You own the store, and nobody has told you what either of them could change in it. Approve the wrong setup and an agent can edit 300 product prices before anyone looks.
The short answer. Shopify MCP is a standard plug that lets an assistant read your store and, if you allow it, change it. Of three kinds, only one suits a store owner. It installs in about five minutes with no code. Start read-only, and never let an agent apply changes to prices, stock or discounts.
Who this is for. The founder or operator who has to approve or refuse an agent’s access to a live store. Developers are better served by Shopify’s own docs. It is not for anyone who only wants a chat assistant with no store access.
| Kind | What it can do for a store owner | What it cannot do | Your job |
|---|---|---|---|
| Dev MCP | Nothing for the live store. It helps your developer write code | Touch store data | None. Skip it |
| Storefront MCP | Lets a shopper's agent search your catalogue and fill a cart | Change prices, stock or your theme | Keep product data complete |
| Admin or community MCP | Lets your own agent read and change products, orders and stock | Nothing, unless a rule stops it | Approve scopes, read every list |
The rule. An agent may propose any change to money, stock or routing. It may not apply one. Ask for the list first, every time. Reading 40 rows costs a minute. Not reading them costs a weekend.
Five terms to know before the detail
An agent is an assistant that can take actions, not only answer questions. MCP, short for Model Context Protocol, is a common plug shape that lets an agent talk to a tool. A connector is a packaged, no-code way to attach that plug to one app. An API (application programming interface) is the set of requests that apps use to read and change your store. An MCP server is the side of the plug that sits next to your store.
Shopify ships three of these plugs. One helps developers write code. One lets shoppers’ agents buy from you. One lets your own agent run the store. We cover the whole set in our Shopify AI agent hub.
Why a store owner should care
Three reasons, in order of how soon they hit revenue.
Your store already answers agents. In August 2026 Shopify enabled WebMCP tools on every Liquid storefront. A browser agent can search your catalogue, change a cart and head to checkout without guessing at your buttons.
This already happened, on 5 August 2026. Shopify’s changelog says the WebMCP tools are “live today on every Liquid storefront and on the Hydrogen developer preview”, with “nothing to install or configure”. Support is “limited to Chromium-based browsers through an origin trial” (Shopify changelog). Early, but not theoretical.
Your own work can move into a chat window. An assistant can pull last week’s numbers or find slow products.
Product data is now a distribution problem. An agent that cannot tell two variants apart, or find a returns policy, cannot recommend you. Thin descriptions used to cost search traffic. Now they cost a shelf in a channel you cannot see.
The three kinds of Shopify MCP
Most of the confusion comes from one name covering three different things.
Dev MCP builds apps and themes
Shopify’s AI Toolkit includes a Dev MCP server. It gives a coding assistant Shopify’s developer docs and API schemas, and checks GraphQL, Liquid and extensions against them. Shopify says the server runs locally and needs no login.
It does not touch your store data. You do not install it.
Storefront and Catalog MCP let shoppers’ agents buy from you
This is the customer-facing side. Shopify documents a Storefront MCP server on your store’s own domain. One endpoint covers catalogue search and product detail. Another covers the cart, plus your policies and FAQ. Shopify says these servers need no login, and notes some stores may restrict access.
A related Storefront Catalog MCP lets an agent search one merchant’s catalogue and read full product detail. Shopify points cross-merchant discovery to a separate Global Catalog MCP. A Customer Accounts MCP server lets a signed-in shopper’s assistant check order status. That one needs a token.
You do not build any of this. It comes with being on Shopify. What you control is whether your data wins the recommendation.
Admin MCP servers let your agent run the store
This is what people mean by “run my store with AI”. It connects an assistant to the GraphQL Admin API, the same interface your apps use. The assistant can then read and change products, orders, customers, inventory and metafields.
There is no single official Admin MCP product. There are two official paths, the chat connector and the Shopify CLI connector, both covered below. Beyond those sits a field of community servers. One widely used open source example, GeLi2001/shopify-mcp, is MIT licensed and exposes 31 Admin API tools. They cover create, update and delete for products and customers, order cancellation, refunds and inventory writes. Ecommerceguide’s directory lists 32 servers. That is a reference list, not a recommendation.
| Kind | Tools or endpoints | Writes it can make | Login |
|---|---|---|---|
| Dev MCP | Docs, schemas, validation | 0 to your store | None. Runs locally |
| Storefront MCP | 6 tools, 2 endpoints | 1, the shopper's cart | None |
| Community Admin server | 31 tools | Create, update, delete, most of the store | Your Admin API token |
| Official connector for Claude | 25 tools | Products, stock, percentage discounts, content | Shopify's approval screen |
What is safe to let an agent write, and what never is
The useful line is not “reads are safe, writes are dangerous”. It is reversibility. An agent may do anything you could undo in under a minute, with no customer seeing it. Everything else gets a human approval step.
Dev MCP writes nothing to your store. Storefront MCP’s only write is the shopper’s cart, then a handoff to checkout. Admin-style MCP is the wide one. Read covers orders, customers, inventory, products, collections and analytics. Write can cover price and inventory changes, discount codes, cancellations, refunds, metafields, pages and menus. How much is exposed depends on the server and the scopes you grant.
| Let an agent write it | Never without a human reading the list | Why |
|---|---|---|
| Draft products, unpublished pages, draft orders | Prices | A percentage on the wrong collection is public revenue, at once |
| Alt text, metafields, internal tags | Inventory quantities | A wrong number oversells you, or hides sellable stock |
| Descriptions on draft products | Discount codes | Wrong percentage or no cap leaks until somebody notices |
| A CSV of proposed changes | URL redirects | They move traffic and rankings, and look fine on the store |
| Nothing else | Theme publishing | Duplicate, preview, publish by hand. Never by agent |
The official path enforces some of this. Shopify’s docs for the connector for Claude say it cannot edit or publish live themes. It cannot issue refunds, cancel orders or process returns. It cannot change payments, taxes, domains or plans. It asks you to confirm changes to pages, menus, metafields and translations, and caps product status updates at 50 per batch. A community server holding a full-access token enforces none of that. You are the only guardrail.
Do you need Shopify MCP at all?
For most store owners, no. Not yet. If you are still choosing an assistant rather than a protocol, Sidekick vs Claude vs ChatGPT is the better comparison.
Shopify publishes an official connector that hooks your store to a consumer assistant with no code and no tokens. Per its docs it reads products, orders, customers, inventory, collections and analytics. It writes products, collections, inventory, percentage discounts and content, with confirmation prompts on several. Access is bounded by what you approve and by your own admin permissions.
You need MCP proper when the assistant must see something Shopify does not own. Your email platform’s flow performance. Analytics sessions joined to search rankings. Ad spend checked against orders that exist in Shopify. None of that lives in the Admin API. That is the real merchant case: not a second way into Shopify, but a way into everything beside it. Ten of those cross-system jobs, each with its prompt, sit in 30 things a Shopify AI agent can do.
Five steps to set up the connector path
This is the order we use.
- Decide what you want answered, not what you want connected. Write down 3 questions you ask your admin every week. That list is your test.
- Install the official connector from the assistant’s directory on a desktop browser, then authorize it in your admin.
- Stay read-only for a week. Ask your 3 questions and check every answer against the admin. Assistants state numbers confidently whether or not they queried anything.
- Turn on writes for drafts only. Draft products, unpublished pages. Confirm the output is good before it touches anything live.
- Write your approval rule and keep it. Money, stock and routing get a list you read. Everything else proceeds.
| Step | Official connector | Self-hosted Admin server |
|---|---|---|
| 1. Get access | Approval screen in your admin | Custom app plus a token |
| 2. Time to working | About 5 minutes | Half a day, if done before |
| 3. Guardrails | Shopify's limits applied | 0 by default |
| 4. Ownership | Uninstall when done | 1 token owner, 1 rotation date |
For a local tool such as Claude Code, Shopify’s official route is the Shopify CLI connector. It authorizes API access from a machine you control, limited by what you grant. The alternative is a custom app in your admin with its own token.
Grant only the scopes the job needs. Scopes are the exact permissions attached to a token. Read Shopify’s access scope list first. Keep write scopes off until a read-only version proves itself. Treat the token like a password.
Common mistakes
Six we keep meeting on real stores.
Installing an Admin MCP server when the connector would do. Extra tokens, fewer rails, the same answers.
Granting full scopes on day one. Start with read scopes, then add the one write scope needed.
Believing a number the agent never queried. The failure is not a refusal. It is a plausible figure. Ask which tool call produced it. If the answer is vague, it was generated, not retrieved.
Running a bulk write with no preview. “Update the 300 products” is a gamble. “Show me the 300 products and the exact change, then wait” is a prompt.
Assuming Storefront MCP is something you configure. It is not a switch. The lever is your product data: complete variants, real descriptions, published policies, accurate stock.
Treating an agent’s opinion as an audit. An assistant reading your admin sees only the admin. It cannot see how checkout behaves on a slow phone.
What to do this week
Install the official connector, keep it read-only, and ask your 3 weekly questions. Thirty minutes tells you more than any article. Then pick one cross-system job from the 30 Shopify AI agent prompts and ask whether it needs MCP at all.
If agents are going to read your store, fix the input, not the plug. An agent recommends only what your catalogue and policies say. Our Shopify operations work starts there, and the free scan below ranks the gaps first.
Questions owners ask before they approve access
What is the difference between Shopify MCP and the Shopify connector for Claude?
MCP is the open protocol. The connector is a packaged, no-code path built on it, with Shopify’s own permission prompts and hard limits applied. Most owners want the connector. You add MCP servers when you need tools Shopify does not own.
What is Shopify Catalog MCP?
Storefront Catalog MCP lets a shopper’s agent search one store’s catalogue, look up products by ID and read full product detail. Global Catalog MCP does the same across many merchants. You do not install either. What you control is the product data they read.
Can an agent break my store?
Not through Storefront MCP, which only reads your catalogue and writes a shopper’s cart. It can through an Admin API server with broad write scopes, because that server can do anything an app can do. Scope narrowly, and approve every change to money, stock and routing.
Facts checked October 2026, re-check by 5 April 2027. Sources: Shopify changelog, AI Toolkit, Storefront MCP, connector for Claude.



