ShopifySAFE
MCP server for Shopify api, usable on mcp hosts such as Claude and Cursor
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
(please leave a star if you like!)
MCP Server for Shopify API, enabling interaction with store data through GraphQL API. This server provides tools for managing products, customers, orders, and more.
📦 Package Name: `shopify-mcp` 🚀 Command: `shopify-mcp` (NOT `shopify-mcp-server`)
Features
- Product Management: Full CRUD for products, variants, and options (8 tools)
- Customer Management: Full CRUD, merge, and address management (8 tools)
- Order Management: Smart lookup, cancel, close/open, mark as paid, fulfillment, refunds (10 tools)
- Metafield Management: Get, set, and delete metafields on any resource (3 tools)
- Inventory Management: Set absolute inventory quantities at locations (1 tool)
- Tag Management: Add/remove tags on any taggable resource (1 tool)
- Pagination & Sorting: Cursor-based pagination and sort keys on all list queries
- Advanced Filtering: Pass-through Shopify query syntax for all list endpoints
- GraphQL Integration: Direct integration with Shopify's GraphQL Admin API (2026-01)
- Comprehensive Error Handling: Clear error messages for API and authentication issues
Prerequisites
- Node.js (version 18 or higher)
- A Shopify store with a custom app (see setup instructions below)
Setup
Authentication
This server supports two authentication methods:
Option 1: Client Credentials (Dev Dashboard apps, January 2026+)
As of January 1, 2026, new Shopify apps are created in the Dev Dashboard and use OAuth client credentials instead of static access tokens.
- From your Shopify admin, go to Settings > Apps and sales channels
- Click Develop apps > Build app in dev dashboard
- Create a new app and configure Admin API scopes:
- `read_produc
6dcd55b2a876OBSERVED · 2026-10-06Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.
claude mcp add shopify-mcp --env SHOPIFY_ACCESS_TOKEN=${SHOPIFY_ACCESS_TOKEN} --env SHOPIFY_CLIENT_SECRET=${SHOPIFY_CLIENT_SECRET} -- npx -y [email protected]{
"mcpServers": {
"shopify-mcp": {
"command": "npx",
"args": [
"-y",
"[email protected]"
],
"env": {
"SHOPIFY_ACCESS_TOKEN": "${SHOPIFY_ACCESS_TOKEN}",
"SHOPIFY_CLIENT_SECRET": "${SHOPIFY_CLIENT_SECRET}"
}
}
}
}Exposed tools (44)
16 read · 21 write · 7 destructive. Blast radius: 7 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
complete-draft-order | write | Complete a draft order, converting it into a real order. Optionally specify a payment gateway. |
create-customer | write | Create a new customer |
create-draft-order | write | Create a draft order for phone/chat sales, invoicing, or wholesale. Supports custom line items, discounts, and customer association. |
create-fulfillment | write | Create a fulfillment (mark items as shipped) with optional tracking info and customer notification. |
create-product | write | Create a new product. When using productOptions, Shopify registers all option values but only creates one default variant (first value of each option, price $0). Use manage-product-variants with strategy=REMOVE_STANDALONE_VARIANT afterward to create all real variants with prices. |
customer-merge | write | Merge two customer records into one. Optionally override which fields to keep from which customer. |
delete-customer | destructive | Delete a customer |
delete-metafields | destructive | Delete metafields from any Shopify resource by specifying owner ID, namespace, and key. |
delete-product | destructive | Delete a product |
delete-product-variants | destructive | Delete one or more variants from a product |
get-collection-by-id | read | Get a single collection with full details including products (paginated), rules for smart collections, SEO, and image |
get-collections | read | Query collections (manual & smart) with optional filtering. Returns title, handle, products count, sort order, and rules for smart collections. |
get-customer-by-id | read | Get a single customer by ID |
get-customer-orders | read | Get orders for a specific customer |
get-customers | read | Get customers or search by name/email |
get-fulfillment-orders | write | Get fulfillment orders for an order including status, assigned location, delivery method, holds, and line items |
get-inventory-items | read | Get inventory item details for all variants of a product including SKU, cost, tracked status, country of origin, and HS codes |
get-inventory-levels | read | Get inventory quantities per location for an inventory item (available, on_hand, committed, reserved, incoming, damaged, etc.) |
get-locations | read | Get all inventory/fulfillment locations with addresses, capabilities, and active status |
get-markets | read | Get all markets with their regions, currencies, status, and web presence configuration |
get-metafield-definitions | write | Discover custom metafield definitions for any resource type (PRODUCT, ORDER, CUSTOMER, etc.). Returns namespace, key, name, type, and validations. |
get-metafields | read | Get metafields for any Shopify resource (products, orders, customers, variants, collections, etc.). Uses the node query with HasMetafields interface. |
get-order-by-id | write | Get a specific order by ID |
get-order-refund-details | write | Get detailed refund info for an order including refunded items, amounts, restock status, and associated transactions |
get-order-transactions | write | Get all payment transactions for an order including authorizations, captures, refunds, and voids with gateway, status, and amounts |
get-orders | read | Get orders with optional filtering by status |
get-price-lists | read | Get all price lists with their currency, fixed/relative adjustments, and associated catalog context |
get-product-by-id | read | Get a specific product by ID |
get-product-variants-detailed | read | Get all variant fields for a product: pricing, inventory, barcode, weight, tax code, selected options, metafields, and image |
get-products | read | Get all products or search by title |
get-shop-info | read | Get shop configuration including name, plan, currencies, features, payment settings, tax config, and contact info |
inventory-set-quantities | write | Set absolute inventory quantities for items at specific locations. Use for inventory corrections, cycle counts, etc. |
manage-customer-address | destructive | Create, update, or delete a customer |
manage-product-options | destructive | Create, update, or delete product options (e.g. Size, Color). Use action= |
manage-product-variants | write | Create or update product variants. Omit variant id to create new, include id to update existing. |
manage-tags | destructive | Add or remove tags on any taggable resource (orders, products, customers, draft orders, articles). |
order-cancel | write | Cancel an order with options for refunding, restocking inventory, and customer notification. Cancellation is irreversible. |
order-close-open | write | Close or reopen an order. Closing marks all items fulfilled and finances complete. Opening reopens a closed order. |
order-mark-as-paid | write | Mark an order as paid. Useful for manual/offline payments (cash, bank deposit, etc.). |
refund-create | write | Create a full or partial refund for an order with optional restocking and shipping refund. |
set-metafields | write | Set metafields on any Shopify resource (products, orders, customers, variants, collections, etc.). Creates or updates up to 25 metafields atomically. |
update-customer | write | Update a customer |
update-order | write | Update an existing order with new information |
update-product | write | Update an existing product |
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | PASS |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (1 observation(s))
- Network
- declared (1 observation(s))
- Shell
- none-observed
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (3)
delete-customer, delete-metafields, delete-product, delete-product-variants, manage-customer-address, manage-product-options, manage-tags
.graphqlrc.ts
@modelcontextprotocol/sdk, dotenv, graphql, graphql-request, minimist, zod, @types/jest, @types/minimist
Gates applied: no_behavioural_pass.
6dcd55b2a876full audit observations/trust-audit/mcp-server/geli2001__shopify-8.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-06 | 6dcd55b2a876 | SAFE | B | 89 | first audit |
Questions
What is the Shopify MCP server?
MCP server for Shopify api, usable on mcp hosts such as Claude and Cursor
What tools does Shopify expose?
44 in total: 16 read-only, 21 that write, and 7 that can delete or overwrite (delete-customer, delete-metafields, delete-product, delete-product-variants, manage-customer-address). Every one is listed on this page with its risk.
Is Shopify safe to connect to an agent?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 7 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Shopify need?
It reads SHOPIFY_ACCESS_TOKEN and SHOPIFY_CLIENT_SECRET from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.
How does Shopify run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as shopify-mcp at 1.0.8.
How current is this page?
The grade is for one exact copy of the source (6dcd55b2a876), read on 2026-10-06. The repository is watched and re-audited when it changes.