shopify-operations MCP Server
by jpkaio.github.jpka/shopify-operations-mcpv0.1.2
Safe-write Shopify operations: plan-before-execute writes with out-of-band approval and audit.
context tax
queued
security
queued
cold start
queued
freshness
Maintained35d ago
Install shopify-operations MCP server
Install in Claude Code
claude mcp add shopify-operations -e SHOPIFY_STORE_DOMAIN='<shopify-store-domain>' -e SHOPIFY_ADMIN_TOKEN='<shopify-admin-token>' -- npx -y shopify-operations-mcpInstall in Cursor
{
"mcpServers": {
"shopify-operations": {
"command": "npx",
"args": [
"-y",
"shopify-operations-mcp"
],
"env": {
"SHOPIFY_STORE_DOMAIN": "<shopify-store-domain>",
"SHOPIFY_ADMIN_TOKEN": "<shopify-admin-token>"
}
}
}
}Add to ~/.cursor/mcp.json (global) or .cursor/mcp.json (project).
Install in Claude Desktop
{
"mcpServers": {
"shopify-operations": {
"command": "npx",
"args": [
"-y",
"shopify-operations-mcp"
],
"env": {
"SHOPIFY_STORE_DOMAIN": "<shopify-store-domain>",
"SHOPIFY_ADMIN_TOKEN": "<shopify-admin-token>"
}
}
}
}Settings → Developer → Edit Config (claude_desktop_config.json), then restart.
Install in VS Code
{
"servers": {
"shopify-operations": {
"type": "stdio",
"command": "npx",
"args": [
"-y",
"shopify-operations-mcp"
],
"env": {
"SHOPIFY_STORE_DOMAIN": "<shopify-store-domain>",
"SHOPIFY_ADMIN_TOKEN": "<shopify-admin-token>"
}
}
}
}Add to .vscode/mcp.json in your workspace.
Install in Windsurf
{
"mcpServers": {
"shopify-operations": {
"command": "npx",
"args": [
"-y",
"shopify-operations-mcp"
],
"env": {
"SHOPIFY_STORE_DOMAIN": "<shopify-store-domain>",
"SHOPIFY_ADMIN_TOKEN": "<shopify-admin-token>"
}
}
}
}Add to ~/.codeium/windsurf/mcp_config.json.
Configuration
| Variable | Required | Secret | Description |
|---|---|---|---|
| SHOPIFY_STORE_DOMAIN | yes | — | The myshopify.com store domain, e.g. my-store.myshopify.com. Overrides shopify.storeDomain from the config file. |
| SHOPIFY_ADMIN_TOKEN | yes | yes | Shopify Admin API access token. Required and only ever read from the environment — never from the config file. |
| SHOPIFY_CONFIG | — | — | Path to a config.json with shopify/plans/approvalServer/protectedTags settings. Defaults to ./config.json in the working directory. |
| SHOPIFY_PLAN_TTL_MS | — | — | How long a plan token stays valid before it must be executed or expires, in milliseconds. Default 60000. |
| SHOPIFY_APPROVAL_SERVER_PORT | — | — | Port the localhost human-approval HTTP server binds to (127.0.0.1 only). Default 4319. |
| SHOPIFY_PROTECTED_TAGS | — | — | Comma-separated tags that plans may never modify; any plan touching an item carrying one is refused. Default do-not-touch. |
| SHOPIFY_CALLER_ID | — | — | Identity recorded as the caller on every audit log row. Default unknown. |
| SHOPIFY_AUDIT_PATH | — | — | File path for the tamper-evident JSONL audit log. Default shopify-operations-audit.jsonl in the working directory. |
Freshness
Maintained — last maintenance signal 35d ago. The newest of the signals below sets the band.
Last commit (default branch)
2026-09-04 · 35d ago · GitHub
Latest release
no data · GitHub
Package published
no data · npm/PyPI
Registry entry updated
2026-08-17 · 54d ago · official registry · v0.1.2
FAQ
›How do I install the shopify-operations MCP server in Claude Code?
Run: claude mcp add shopify-operations -e SHOPIFY_STORE_DOMAIN='<shopify-store-domain>' -e SHOPIFY_ADMIN_TOKEN='<shopify-admin-token>' -- npx -y shopify-operations-mcp. For Cursor, VS Code, Claude Desktop and Windsurf, use the install tabs above.
›Does shopify-operations require an API key?
Yes. It expects SHOPIFY_STORE_DOMAIN, SHOPIFY_ADMIN_TOKEN, of which 1 is a secret.
›Can I use shopify-operations as a remote (hosted) MCP server?
No hosted endpoint is published; it runs locally over stdio.
›Is shopify-operations in the official MCP registry?
Yes, as io.github.jpka/shopify-operations-mcp.
Alternatives to shopify-operations
Other e-commerce MCP servers.