Shopify MCP: Storefront, Dev and Admin Servers Explained
Shopify’s MCP servers changed in 2026. What each one is today: the Dev MCP server for building, Customer Accounts MCP for signed-in shoppers, the UCP catalog, cart, checkout and order servers that replaced Storefront MCP, and how admin work reaches a store without an Admin MCP server. Setup, sign-in and safe use for each.
8 min read
Shopify MCP is not one server. Shopify documents several, for different people. The Shopify Dev MCP server runs on a developer’s machine with no sign-in and gives a coding agent Shopify’s docs, API schemas and code validation. The Customer Accounts MCP server lets an app act for a signed-in shopper on orders and account details, with OAuth. For shopping agents, the old Storefront MCP server’s catalog and cart tools have been removed and replaced by MCP servers built on the Universal Commerce Protocol (UCP): Storefront Catalog, Cart, Checkout and Order. Shopify documents no Admin MCP server; store management from an agent goes through Shopify CLI, which runs Admin API queries and blocks changes unless you allow them.
What changed: Storefront MCP is gone
If you read about Shopify MCP before mid-2026, most of it now points somewhere else. Shopify’s Storefront MCP migration page (opens in a new tab) says the catalog and cart tools on https://{shop}/api/mcp were removed in favor of UCP at https://{shop}/api/ucp/mcp. Shopify’s developer changelog announced the cart deprecation on June 24, 2026 and said the old tools would be maintained until August 31, 2026. The map:
search_catalogandget_product_detailsbecame Storefront Catalog MCP:search_catalog,lookup_catalogandget_product.get_cartandupdate_cartbecame Cart MCP:create_cart,get_cart,update_cartandcancel_cart.update_cartnow replaces the whole cart, so send every line item you want to keep.- The checkout URL from the cart became Checkout MCP.
search_shop_policies_and_faqsis unchanged and still lives at/api/mcp, with no authentication.- The Customer Accounts MCP server is unchanged; only its documentation moved.
- The
shop-chat-agentsample app and its tutorial are deprecated.
The Shopify Dev MCP server also has a new home: its setup page now redirects to the Shopify AI Toolkit, which bundles it with Shopify’s agent skills.
The Shopify Dev MCP server and the AI Toolkit
This is the one most developers want. The Shopify AI Toolkit (opens in a new tab) connects a coding agent to Shopify’s developer docs and API schemas, validates GraphQL, Liquid and extension code against Shopify’s schemas, and runs store-management tasks through Shopify CLI. Shopify recommends installing it as a plugin, which updates itself. If you prefer plain MCP, the Dev MCP server is the @shopify/dev-mcp package; it runs locally over stdio and needs no authentication.
claude plugin install shopify-ai-toolkit@claude-plugins-official claude mcp add --transport stdio shopify-dev-mcp -- npx -y @shopify/dev-mcp@latest
{
"mcpServers": {
"shopify-dev-mcp": {
"command": "npx",
"args": ["-y", "@shopify/dev-mcp@latest"]
}
}
}VS Code takes the same command under servers in its mcp.json, and Codex takes it in ~/.codex/config.toml under [mcp_servers.shopify-dev-mcp]. Restart the client after adding it. The general shape of these files is in MCP config files.
One thing to know before you install: telemetry is on by default. The package’s README says release builds send usage events to Shopify that can include tool inputs and results, and the toolkit’s README says its hooks can attach your most recent prompt in Claude Code when a Shopify skill runs. To opt out everywhere, create an empty file at ~/.config/shopify-ai-toolkit/opt-out (on Windows, %APPDATA%\shopify-ai-toolkit\opt-out), or set OPT_OUT_INSTRUMENTATION=true in the environment that launches the client.
The Customer Accounts MCP server
The Customer Accounts MCP server (opens in a new tab) handles requests for a signed-in customer, such as checking order status, retrieving order details and managing account preferences. It is for apps you build, not for connecting your own assistant to your store. The requirements:
- The store has a custom domain.
- Your app meets Shopify’s protected customer data requirements, with access requested for each field it needs, such as name, email, phone and address.
- Your app is set up for customer accounts authentication, with scopes and redirect URIs in
shopify.app.toml.
The endpoint is discovered from the storefront: https://{shop}/.well-known/customer-account-api returns an mcp_api URL of the form https://{shop}/customer/api/mcp. Sign-in is OAuth 2.0 with the authorization code flow and PKCE, using endpoints from the shop’s /.well-known/openid-configuration; the documented scope is customer-account-mcp-api:full. The server answers 401 Unauthorized until the customer has signed in, and the tools are discovered with tools/list rather than listed in the docs.
Catalog, cart, checkout and orders over UCP
These servers are for agents that shop on a buyer’s behalf. Every request to /api/ucp/mcp carries an agent profile: a meta object with a ucp-agent.profile URL pointing at a UCP profile your agent hosts. Shopify’s auth and rate limiting page (opens in a new tab) sorts traffic into three tiers:
- Token: a credential issued through Shopify’s Dev Dashboard, sent as a Bearer token. The highest rate limits, and the only tier that can call
complete_checkout, when the token has been granted that permission, or read orders, with theread_global_api_ordersscope and only for orders placed through your agent. - Signed: requests signed with HTTP Message Signatures against a public key in your agent’s UCP profile. Cart and checkout, at lower limits.
- Anonymous: no credentials. Catalog, and building carts and checkouts, at the lowest limits.
Checkout is where the money is, and Shopify builds in a hand-off. Checkout MCP (opens in a new tab) returns a continue_url, and when a checkout needs buyer input or review it returns the status requires_escalation. For general access, sending the buyer to that URL is how checkout completes: the buyer finishes and pays on the merchant’s own checkout. Only a trusted, token-tier agent calls complete_checkout, which also needs an idempotency key. Shopify’s Universal Cart API, one cart across merchants, is early access with a waitlist.
Is there a Shopify Admin MCP server?
Not from Shopify. Its documentation has no Admin MCP server; third-party apps in the Shopify App Store offer MCP access to store data, and each should be judged like any app that asks for Admin API scopes. Shopify’s own route for an agent to manage a store is the AI Toolkit’s store management, which uses Shopify CLI. shopify store auth authenticates against one store with the Admin API scopes you list and stores the token, and `shopify store execute` (opens in a new tab) runs an Admin API GraphQL query against it. Mutations are disabled by default and run only with --allow-mutations.
shopify store auth --store your-dev-store.myshopify.com --scopes read_products
shopify store execute --store your-dev-store.myshopify.com --query '{ shop { name } }'Using them safely
- Start on a dev store. Point
shopify store authat a development store until the agent’s work is right, and request read scopes before any write scope. - Keep
--allow-mutationsbehind a person. The flag is the difference between reading your catalog and changing it, so an agent should ask every time it wants to runstore execute. - Treat product text, reviews and policies as untrusted. The catalog and policy tools return text other people wrote, and an agent that reads it and can also change the store is the pattern in indirect prompt injection.
- Keep shopper data where it belongs. Customer Accounts MCP returns protected customer data; do not copy it into chats, logs or task notes.
- Hand payment to the buyer. Use
continue_urlunless you have a real reason, and the token permission, to complete checkouts yourself.
{
"permissions": {
"allow": ["mcp__shopify-dev-mcp"],
"ask": ["Bash(shopify store execute *)"]
}
}An ask rule matches the command as written, so a command phrased another way can slip past it; keep the store token scoped narrowly as well. How allow and ask rules behave in each permission mode is in Claude Code auto-approve, and the same reasoning for every MCP server is in MCP security best practices.
Where the store work waits
The safe pattern is an agent that investigates and drafts, and a person who changes the store. With fenbs connected beside Shopify at https://fenbs.ai/api/mcp, an agent that finds 30 products with missing weights, or a Liquid error on the product page, files a task with the product IDs in the note and the proposed GraphQL change in the plan, and a person decides whether to run it. Record the line itself, such as “no agent runs store mutations”, on the Decisions and rules page, which every connected assistant reads before it starts. fenbs does not approve or block anything in Shopify; Shopify CLI’s mutation flag and your client’s prompts do that.
Related
The jobs around a store: AI agents for ecommerce. Payments beside Shopify: Stripe MCP. Sign-in in general: how MCP OAuth works. Setting up the board: Claude Code, Cursor and the MCP docs.