Atlas / MCP servers / geli2001 / Shopify

ShopifySAFE

mcp/geli2001/shopify-8

MCP server for Shopify api, usable on mcp hosts such as Claude and Cursor

Verdict
SAFE
Grade
B
Trust score
89 /100
Exposed tools
44 16r · 21w · 7d
Transport
stdio
License
MIT
Stars
238
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

(please leave a star if you like!)

MCP Server for Shopify API, enabling interaction with store data through GraphQL API. This server provides tools for managing products, customers, orders, and more.

📦 Package Name: `shopify-mcp` 🚀 Command: `shopify-mcp` (NOT `shopify-mcp-server`)

Features

  • Product Management: Full CRUD for products, variants, and options (8 tools)
  • Customer Management: Full CRUD, merge, and address management (8 tools)
  • Order Management: Smart lookup, cancel, close/open, mark as paid, fulfillment, refunds (10 tools)
  • Metafield Management: Get, set, and delete metafields on any resource (3 tools)
  • Inventory Management: Set absolute inventory quantities at locations (1 tool)
  • Tag Management: Add/remove tags on any taggable resource (1 tool)
  • Pagination & Sorting: Cursor-based pagination and sort keys on all list queries
  • Advanced Filtering: Pass-through Shopify query syntax for all list endpoints
  • GraphQL Integration: Direct integration with Shopify's GraphQL Admin API (2026-01)
  • Comprehensive Error Handling: Clear error messages for API and authentication issues

Prerequisites

  1. Node.js (version 18 or higher)
  2. A Shopify store with a custom app (see setup instructions below)

Setup

Authentication

This server supports two authentication methods:

Option 1: Client Credentials (Dev Dashboard apps, January 2026+)

As of January 1, 2026, new Shopify apps are created in the Dev Dashboard and use OAuth client credentials instead of static access tokens.

  1. From your Shopify admin, go to Settings > Apps and sales channels
  2. Click Develop apps > Build app in dev dashboard
  3. Create a new app and configure Admin API scopes:
  4. `read_produc
Read from source at commit 6dcd55b2a876OBSERVED · 2026-10-06
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add shopify-mcp --env SHOPIFY_ACCESS_TOKEN=${SHOPIFY_ACCESS_TOKEN} --env SHOPIFY_CLIENT_SECRET=${SHOPIFY_CLIENT_SECRET} -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "shopify-mcp": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ],
      "env": {
        "SHOPIFY_ACCESS_TOKEN": "${SHOPIFY_ACCESS_TOKEN}",
        "SHOPIFY_CLIENT_SECRET": "${SHOPIFY_CLIENT_SECRET}"
      }
    }
  }
}
03

Exposed tools (44)

16 read · 21 write · 7 destructive. Blast radius: 7 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
complete-draft-orderwriteComplete a draft order, converting it into a real order. Optionally specify a payment gateway.
create-customerwriteCreate a new customer
create-draft-orderwriteCreate a draft order for phone/chat sales, invoicing, or wholesale. Supports custom line items, discounts, and customer association.
create-fulfillmentwriteCreate a fulfillment (mark items as shipped) with optional tracking info and customer notification.
create-productwriteCreate a new product. When using productOptions, Shopify registers all option values but only creates one default variant (first value of each option, price $0). Use manage-product-variants with strategy=REMOVE_STANDALONE_VARIANT afterward to create all real variants with prices.
customer-mergewriteMerge two customer records into one. Optionally override which fields to keep from which customer.
delete-customerdestructiveDelete a customer
delete-metafieldsdestructiveDelete metafields from any Shopify resource by specifying owner ID, namespace, and key.
delete-productdestructiveDelete a product
delete-product-variantsdestructiveDelete one or more variants from a product
get-collection-by-idreadGet a single collection with full details including products (paginated), rules for smart collections, SEO, and image
get-collectionsreadQuery collections (manual & smart) with optional filtering. Returns title, handle, products count, sort order, and rules for smart collections.
get-customer-by-idreadGet a single customer by ID
get-customer-ordersreadGet orders for a specific customer
get-customersreadGet customers or search by name/email
get-fulfillment-orderswriteGet fulfillment orders for an order including status, assigned location, delivery method, holds, and line items
get-inventory-itemsreadGet inventory item details for all variants of a product including SKU, cost, tracked status, country of origin, and HS codes
get-inventory-levelsreadGet inventory quantities per location for an inventory item (available, on_hand, committed, reserved, incoming, damaged, etc.)
get-locationsreadGet all inventory/fulfillment locations with addresses, capabilities, and active status
get-marketsreadGet all markets with their regions, currencies, status, and web presence configuration
get-metafield-definitionswriteDiscover custom metafield definitions for any resource type (PRODUCT, ORDER, CUSTOMER, etc.). Returns namespace, key, name, type, and validations.
get-metafieldsreadGet metafields for any Shopify resource (products, orders, customers, variants, collections, etc.). Uses the node query with HasMetafields interface.
get-order-by-idwriteGet a specific order by ID
get-order-refund-detailswriteGet detailed refund info for an order including refunded items, amounts, restock status, and associated transactions
get-order-transactionswriteGet all payment transactions for an order including authorizations, captures, refunds, and voids with gateway, status, and amounts
get-ordersreadGet orders with optional filtering by status
get-price-listsreadGet all price lists with their currency, fixed/relative adjustments, and associated catalog context
get-product-by-idreadGet a specific product by ID
get-product-variants-detailedreadGet all variant fields for a product: pricing, inventory, barcode, weight, tax code, selected options, metafields, and image
get-productsreadGet all products or search by title
get-shop-inforeadGet shop configuration including name, plan, currencies, features, payment settings, tax config, and contact info
inventory-set-quantitieswriteSet absolute inventory quantities for items at specific locations. Use for inventory corrections, cycle counts, etc.
manage-customer-addressdestructiveCreate, update, or delete a customer
manage-product-optionsdestructiveCreate, update, or delete product options (e.g. Size, Color). Use action=
manage-product-variantswriteCreate or update product variants. Omit variant id to create new, include id to update existing.
manage-tagsdestructiveAdd or remove tags on any taggable resource (orders, products, customers, draft orders, articles).
order-cancelwriteCancel an order with options for refunding, restocking inventory, and customer notification. Cancellation is irreversible.
order-close-openwriteClose or reopen an order. Closing marks all items fulfilled and finances complete. Opening reopens a closed order.
order-mark-as-paidwriteMark an order as paid. Useful for manual/offline payments (cash, bank deposit, etc.).
refund-createwriteCreate a full or partial refund for an order with optional restocking and shipping refund.
set-metafieldswriteSet metafields on any Shopify resource (products, orders, customers, variants, collections, etc.). Creates or updates up to 25 metafields atomically.
update-customerwriteUpdate a customer
update-orderwriteUpdate an existing order with new information
update-productwriteUpdate an existing product
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codePASS
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
declared (1 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (3)

MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
delete-customer, delete-metafields, delete-product, delete-product-variants, manage-customer-address, manage-product-options, manage-tags
Why it matters. 7 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWInventory / provenance · inv.hidden_file · CWE-1104
.graphqlrc.ts
.graphqlrc.ts
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/sdk, dotenv, graphql, graphql-request, minimist, zod, @types/jest, @types/minimist
Why it matters. 18 dependency range(s) float
Fix. pin exact versions or ship a lockfile

Gates applied: no_behavioural_pass.

Audited 2026-10-06 · audit v0.4.1 · source sha 6dcd55b2a876full audit observations/trust-audit/mcp-server/geli2001__shopify-8.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-066dcd55b2a876SAFEB89first audit
06

Questions

What is the Shopify MCP server?

MCP server for Shopify api, usable on mcp hosts such as Claude and Cursor

What tools does Shopify expose?

44 in total: 16 read-only, 21 that write, and 7 that can delete or overwrite (delete-customer, delete-metafields, delete-product, delete-product-variants, manage-customer-address). Every one is listed on this page with its risk.

Is Shopify safe to connect to an agent?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean server reads B. Separately from the audit: 7 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does Shopify need?

It reads SHOPIFY_ACCESS_TOKEN and SHOPIFY_CLIENT_SECRET from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Shopify run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as shopify-mcp at 1.0.8.

How current is this page?

The grade is for one exact copy of the source (6dcd55b2a876), read on 2026-10-06. The repository is watched and re-audited when it changes.

Advertisement