MCP server guide · checked September 27, 2026

Shopify MCP server

Yes, Shopify has official MCP servers, each for a different job. As of September 2026, Shopify’s own connector at https://setup.shopify.com/mcp lets store owners use Claude, ChatGPT or Perplexity to edit products, collections, inventory and discount codes, run analytics, and read orders and customers; the local Dev MCP server gives developers Shopify docs and API schemas; and Shopify’s Universal Commerce Protocol (UCP) servers let shopping agents search catalogs, build carts and start checkouts. For store operations the gap is changing orders: Shopify blocks refunds, cancellations, captures, returns and gift cards through its AI integrations even with write access, lists no Copilot Studio integration, and works only on Shopify data, not your ERP or 3PL.

Official server: Yes, generally available
Shopify's own connectors for Claude, ChatGPT and Perplexity edit products, inventory and discounts and read orders and customers in a store you own, but block refunds, cancellations and other order changes; its Dev MCP server serves app developers.

Shopify API facts that shape an MCP server

Shopify API facts that shape an MCP server
FactDetailSource
Official connectorClaude’s directory lists an Anthropic-verified Shopify connector, made by Shopify and added in April 2026, with 25 tools at the connector URL https://setup.shopify.com/mcp.Claude directory: Shopify connector
What it coversConnected to a store you own, the connector creates and updates products and collections, sets inventory at a location with a reason such as received or damaged, creates percentage-off discount codes and runs ShopifyQL analytics. It lists up to 50 orders at a time and reads orders and customers but doesn’t change them. Shopify charges no extra fee for it.Shopify Help Center: Shopify connector for Claude
What it can’t doA connected AI tool can’t issue refunds, cancel or capture orders, mark orders as paid, process returns, or create and adjust gift cards; Shopify says these are blocked even when you approve write access. It also can’t change the plan, payments, taxes or domains, or edit, publish or delete the live theme.Shopify Help Center: Considerations for third-party AI tools
Access and setupYou install the Shopify plugin for ChatGPT, the Shopify connector for Claude or the Shopify connector for Perplexity from that tool, then approve the requested data access in the Shopify admin. The tool is limited by that access and by the user’s permissions and connects to one store at a time. Shopify tells merchants not to create an API access token or build their own integration to connect an AI tool.Shopify Help Center: Authorizing AI tool access
Generic Admin API toolsFor areas without a named action, such as pages, blogs, menus, metafields, markets and translations, the connector uses graphql_query and graphql_mutation against the Admin API and asks you to confirm before a change. Shopify notes that results vary more for these than for named actions.Shopify Help Center: Shopify connector for Claude
Dev MCP serverThe Dev MCP server (npx -y @shopify/dev-mcp@latest) runs locally without authentication and gives coding agents Shopify docs, API schemas and validation for GraphQL, Liquid and extensions. It is one install option of the Shopify AI Toolkit, which can also run store tasks through Shopify CLI’s authenticated store context when you choose to.Shopify developer docs: Shopify AI Toolkit
Storefront MCP replacedThe catalog and cart tools on the per-store endpoint https://{shop}/api/mcp were removed. Shopify now serves them through UCP at https://{shop}/api/ucp/mcp as Storefront Catalog, Cart and Checkout MCP; only search_shop_policies_and_faqs stays on /api/mcp.Shopify developer docs: Migrate from Storefront MCP
UCP access tiersUCP sorts agents into Token (a Dev Dashboard credential), Signed (RFC 9421 message signatures) and Anonymous tiers. Only Token-tier agents can complete checkouts, when granted permission, or call get_order, and get_order returns only orders placed through that agent.Shopify developer docs: UCP auth and rate limiting
Customer Accounts MCPFor signed-in shoppers, the Customer Accounts MCP server handles order status, order details and account preferences. Its endpoint is discovered from /.well-known/customer-account-api, and it needs a custom domain, Shopify’s protected customer data approval and an OAuth 2.0 authorization code flow with PKCE.Shopify developer docs: Customer Accounts MCP server
Admin API rate limitsEach app and store pair gets 100 cost points per second on Standard plans, 200 on Advanced, 1,000 on Plus and 2,000 on Shopify for enterprise (Commerce Components). A single query can’t exceed 1,000 points, a mutation costs 10 by default, and bulk operations don’t have these limits.Shopify developer docs: GraphQL Admin API rate limits
Custom apps in 2026Custom apps are now created in the Dev Dashboard, install only on stores in the same organization, and get access tokens through the client credentials grant. Legacy custom apps created in the Shopify admin before January 1, 2026 still show their Admin API token there.Shopify Help Center: Installing and setting up apps
Order history windowThe read_orders and write_orders scopes cover orders created within the last 60 days. Older orders need read_all_orders, which an app must request access to.Shopify developer docs: Access scopes

Every way to connect Shopify to AI

Every way to connect Shopify to AI
OptionTypeFits whenLimits
Shopify’s own AI integrations (Claude, ChatGPT, Perplexity)OfficialOwners and staff who want to ask about sales, check stock, edit the catalog, set inventory and create discount codes from a chat, under their own staff permissions, at no extra Shopify cost.Orders and customers are read-only, and refunds, cancellations, captures, returns and gift cards are blocked. Shopify’s action list has no fulfillment, draft order or B2B tools, it serves one store at a time, and Copilot isn’t supported.
Sidekick in the Shopify adminOfficialStaff who work in the Shopify admin and want an assistant that analyzes data, manages orders and edits products, and that presents changes for review before applying them.It lives inside the Shopify admin, not in Claude, ChatGPT or Copilot. Shopify says its chat integrations don’t replace Sidekick or the admin.
Developer and shopping-agent servers (Dev MCP, UCP, Customer Accounts MCP)OfficialDevelopers building apps, themes or a custom server (Dev MCP), and shopping agents or storefront assistants that search products, build carts, hand buyers to checkout and answer signed-in customers’ order questions (UCP and Customer Accounts MCP).None runs store operations. Dev MCP reads docs and schemas, UCP’s get_order sees only orders placed through your agent, and Checkout MCP needs authentication or signed requests.
Zapier MCP or ComposioHostedTeams that need actions Shopify’s connector lacks, next to other apps. Zapier lists 25 Shopify write actions, including Create Fulfillment, Create Draft Order, Create Company, Capture Order and Mark Order as Paid; Composio offers a similar hosted toolkit with managed OAuth.Some of these actions move money or change paid orders, which Shopify blocks in its own connector, so approval rules are yours to add. Calls run through the vendor’s Shopify connection, and each Zapier MCP tool call uses two tasks from your plan.
Community Admin API serversCommunityDevelopers testing locally: GeLi2001/shopify-mcp (MIT) wraps the GraphQL Admin API with tools for products, customers, orders, draft orders, metafields, inventory and tags, and signs in with Dev Dashboard client credentials or a legacy token.Unofficial and run on your machine. Tools such as refund-create, order-cancel and order-mark-as-paid run under one app token, so approvals and per-user limits are yours to add, and Shopify advises merchants against home-built AI integrations.
Custom operations MCP serverCustomOperations teams that need what Shopify’s connector doesn’t do: order changes behind approval by the right staff role, fulfillment exceptions, B2B terms, ERP or 3PL context, or Copilot Studio.You build, host and secure it as a Shopify app with its own scopes and token. Build only for what the official integrations don’t cover.

Tools a Shopify MCP server should expose

Start with read-only tools and add write actions once the team trusts the answers. Every write action below runs with a confirmation or approval step.

Tools a Shopify MCP server should expose
ToolAccessRiskPurposeGuard
get_order_statusReadLowPayment, fulfillment and return status, tracking and line items for one order, found by order number or customer email.Read-only; one order per call; orders older than 60 days need the read_all_orders scope; contact details masked unless the user’s role allows them.
get_stock_by_locationReadLowAvailable, committed and incoming quantity for a SKU at each location.Read-only; a SKU or product is required; no free-form GraphQL.
list_low_stockReadLowVariants below their reorder point at each location, for a daily alert or a buyer’s question.Read-only; reorder points come from a reviewed configuration, not the prompt; results capped and paged.
list_fulfillment_exceptionsReadMediumPaid orders still unfulfilled after the promised window, fulfillment orders on hold, and shipments without tracking.Read-only; a date window is required; queries sized to stay under Shopify’s 1,000-point query limit.
get_b2b_company_termsReadMediumA B2B company location’s catalogs, price list, payment terms and recent orders.Read-only; needs the read_companies scope and a user role with B2B access; one company per call.
create_draft_orderWriteMediumBuild a draft order for a customer or B2B location and show totals, tax and shipping before saving.Saves only after the user confirms the preview; prices come from Shopify catalogs; an idempotency key blocks duplicates; the tool never completes the draft or sends an invoice.
adjust_inventoryWriteMediumChange the available quantity of one item at one location with a reason such as received, damaged or correction.Shows current and new quantity and saves only after the user confirms; compare-and-set against the quantity just read, so a stale update fails; per-call and daily change limits; logged with user and reason.
issue_refundWriteHighRefund chosen line items or shipping on an order, after a calculated preview.Calculates the refund first; runs only after approval by a staff member whose Shopify role can issue refunds; per-refund cap; idempotency key; logged with order, amount, requester and approver.

Connect it to Claude, ChatGPT or Copilot Studio

Claude

Add Shopify’s own connector from Claude’s directory (Anthropic-verified, made by Shopify), then approve its data access in the Shopify admin from a desktop browser. It serves one store at a time, and a Claude workspace owner can restrict it. A custom operations server is added as a custom connector with its remote URL and OAuth client details; on Team and Enterprise plans an Owner adds it first. Calls come from Anthropic’s cloud, so a private server must allowlist Anthropic’s IP ranges.

ChatGPT

Shopify documents the Shopify plugin for ChatGPT with the same kinds of store actions as the Claude connector: install it from ChatGPT, approve access in the Shopify admin, and type @Shopify so ChatGPT uses it. A custom server connects in developer mode under ChatGPT Plugins with OAuth; on Enterprise and Edu an admin must grant developer-mode access, and ChatGPT asks for confirmation on tools not marked read-only. For a server that must stay private, OpenAI’s Secure MCP Tunnel makes only outbound HTTPS calls.

Microsoft Copilot Studio

Shopify’s chat integrations cover ChatGPT, Claude and Perplexity, not Copilot Studio; VS Code is supported only as a developer tool through the Shopify CLI connector. Add a custom or hosted MCP server through the MCP onboarding wizard (Streamable HTTP only) with OAuth 2.0 or an API key, turn on generative orchestration, and expect Power Platform data policies to govern it. Power Platform also lists a premium Shopify (Independent Publisher) connector in preview that calls Shopify’s REST API with an access token; Shopify has treated that API as legacy since October 1, 2024.

Claude implementation · Copilot implementation · ChatGPT implementation

Permissions, identity and audit

  • Shopify’s connectors act through the staff account that signs in and the data access you approve. Give AI users staff accounts with only the permissions their job needs; a user who can’t edit products can’t give the tool that power.
  • Approve the smallest data access that works. You can’t lower an approved level later: you uninstall and reinstall, and uninstalling cuts access at once.
  • A custom server is a Shopify app with its own access scopes. Request only what its tools use, such as read_orders, read_inventory, write_inventory and read_companies; add read_all_orders only if agents must see orders older than 60 days; and treat write_orders, which covers orders and their transactions, as high risk.
  • Dev Dashboard apps get tokens through the client credentials grant. Tokens last 24 hours and work only on stores in the same Shopify organization, so keep the client secret on the server in a secrets manager, never in the AI client.
  • That token belongs to the app, not the person. The server must sign each user in through your identity provider, map them to a role such as support, warehouse or finance, apply that role’s tools and limits, and log user, approver and Shopify object IDs on every write.

Hosting and network

  • Shopify hosts its own connector, so there is nothing to deploy: setup is an install from the AI tool and an approval in the Shopify admin.
  • A custom server runs in your cloud as a remote Streamable HTTP endpoint that Claude, ChatGPT and Copilot Studio can reach. It keeps the Shopify token server-side and calls the GraphQL Admin API, since the REST Admin API has been legacy since October 2024.
  • Budget query cost, not request count. Cap how many calls one prompt can trigger, read the throttle status Shopify returns with each response, back off when throttled (Shopify recommends one second), and move large exports to bulk operations, where from API version 2026-01 each app can run up to five bulk queries per shop at once.
  • Use webhooks for new, paid and cancelled orders and inventory changes, but reconcile on a schedule: Shopify documents that webhooks can arrive out of order, more than once or not at all.
  • Pin an API version and review it each quarter. Shopify releases a new version every three months and supports each stable version for at least 12 months.

Cost and timeline

  • Shopify’s own connector costs nothing extra in Shopify; you pay the AI provider for Claude, ChatGPT or Perplexity. The work is staff permissions, the access approval and training.
  • A focused read-only operations server, for example order status, stock by location, low-stock alerts and fulfillment exceptions, typically takes two to four weeks including security and evaluation.
  • Write tools with approvals (refunds, draft orders, inventory changes), B2B terms and ERP or 3PL context take longer and are scoped after a short discovery. Hosted platforms bill on their own terms; Zapier, for example, counts each MCP tool call as two tasks.

Shopify MCP questions

Does Shopify have an MCP server?

Yes, several. Shopify’s own connector (https://setup.shopify.com/mcp) connects Claude, ChatGPT and Perplexity to a store you own. The Dev MCP server serves developers, and the UCP servers (Catalog, Cart, Checkout and Order MCP) plus the Customer Accounts MCP server serve shopping agents. None is a full operations server: order changes stay in the Shopify admin.

What is Shopify Storefront MCP?

It was a per-store endpoint at https://{shop}/api/mcp that let shopping agents search a catalog and manage carts. Shopify deprecated its catalog tools in April 2026 and its cart tools in June 2026, kept them running until June 15 and August 31, 2026, and has since removed them. Use UCP at https://{shop}/api/ucp/mcp instead; only the policies and FAQs tool stays on /api/mcp.

Is there a Shopify Admin MCP server?

Not under that name. Shopify’s connector for Claude, ChatGPT and Perplexity is Shopify’s own route to Admin API data, with named tools plus generic graphql_query and graphql_mutation tools. Community Admin API servers exist, such as GeLi2001/shopify-mcp, but they are unofficial, and Shopify advises merchants not to create API tokens or build their own integration to connect an AI tool. As of September 2026, the official MCP Registry lists community Shopify servers but none published by Shopify.

Can Claude manage my Shopify orders?

It can find and read them. Shopify’s connector lists recent orders, up to 50 at a time, and opens one order’s items, fulfillment status, address and tracking, but it doesn’t edit orders, and Shopify blocks refunds, cancellations, captures, returns and marking orders as paid even with write access. Sidekick in the Shopify admin can manage orders and shows changes for review first. Order changes from Claude need a hosted platform or a custom server, with approval rules you set.

Does it work with ChatGPT and Copilot?

ChatGPT, yes: Shopify offers the Shopify plugin for ChatGPT with the same kinds of actions as the Claude connector. Microsoft Copilot Studio isn’t among Shopify’s AI integrations, so Copilot needs a custom or hosted MCP server, or Power Platform’s independent-publisher Shopify connector, which is in preview.

Is my store data safe with these connectors?

The connector acts through the signed-in staff account and the data access you approved, and it asks before changes made through the generic Admin API tools. Shared data leaves Shopify and falls under the AI provider’s terms, and Shopify doesn’t review actions the tool takes, so monitor changes and give AI users staff accounts with only the permissions they need.

How do Shopify rate limits affect an AI agent?

Each app and store pair gets a cost budget: 100 points per second on Standard plans, 200 on Advanced, 1,000 on Plus and 2,000 on Commerce Components, and no single query may cost more than 1,000 points. An agent that loops can exhaust it, so a server should cap calls per prompt, page results and use bulk operations for exports.

Official or custom?

Start with Shopify’s own connector: it’s free in Shopify, runs under each person’s staff permissions, and Shopify recommends it over home-built integrations. Build custom only for what it can’t do: order changes behind approvals, fulfillment exceptions, B2B terms, ERP or 3PL context, or Copilot Studio. AIONDATA is an independent provider, not a Shopify partner, so we’ll tell you when the official connector is enough.

Connect Shopify to your AI assistants.

Tell us which Shopify questions and actions matter. We’ll say whether the official route is enough and scope a custom server where it isn’t.

Please share the workflow and the systems involved—not credentials or employee or customer records.

NVIDIA Inception

NVIDIA Inception member

Part of NVIDIA’s program for startups building with AI and accelerated computing.

About the program
Pravin BansalSravan Modugula

Bay Area roots. Enterprise experience.

Pravin’s experience includes Google and SmartBear. Sravan previously held leadership roles at JPMorgan Chase and First Republic Bank.

Meet the founders

San Francisco Bay Area, California

9110 Alcosta Blvd Ste H345, San Ramon, CA 94583

US-led delivery, with engineering in India. Supporting US and international organizations.
Prefer email? info@aiondata.io

Scope your Shopify MCP server.

Just your name and email to get started. Your details are handled under our Privacy Policy.