Skip to main content

Announcing StackOne Defender: leading open-source prompt injection guard for your agent Read More

Shopify MCP Server
for AI Agents

Production-ready Shopify MCP server with 54 extensible actions — plus built-in authentication, security, and optimized execution.

Shopify logo
Shopify MCP Server
Built by StackOne StackOne

Coverage

54 Agent Actions

Create, read, update, and delete across Shopify — and extend your agent's capabilities with custom actions.

Authentication

Agent Tool Authentication

Per-user OAuth in one call. Your Shopify MCP server gets session-scoped tokens with zero credentials stored on your infra.

Agent Auth →

Security

Agent Protection

Every Shopify tool response scanned for prompt injection in milliseconds — 88.7% accuracy, all running on CPU.

Prompt Injection Defense →

Performance

Max Agent Context. Min Cost.

Free up to 96% of your agent's context window to enhance reasoning and reduce cost, on every Shopify call.

Tools Discovery →

What is the Shopify MCP Server?

A Shopify MCP server lets AI agents read and write Shopify data through the Model Context Protocol — Anthropic's open standard for connecting LLMs to external tools. StackOne's Shopify MCP server ships with 54 pre-built actions, fully extensible via the Connector Builder — plus managed authentication, prompt injection defense, and optimized agent context. Connect it from MCP clients like Claude Desktop, Cursor, and VS Code, or from agent frameworks like OpenAI Agents SDK, LangChain, and Vercel AI SDK.

All Shopify MCP Tools and Actions

Every action from Shopify's API, ready for your agent. Create, read, update, and delete — scoped to exactly what you need.

Products

  • Create Product

    Create a new product

  • List Products

    Retrieve a paginated list of products

  • Get Product

    Retrieve a single product by ID

  • Update Product

    Update an existing product

  • Delete Product

    Delete a product

Product Variants

  • Create Product Variant

    Add a new variant to a product

  • List Product Variants

    Retrieve all variants for a product

  • Get Product Variant

    Retrieve a specific product variant

  • Update Product Variant

    Update variant details

  • Delete Product Variant

    Remove a variant from a product

Orders

  • Create Order

    Create a new order

  • List Orders

    Retrieve a paginated list of orders

  • Get Order

    Retrieve a single order by ID

  • Update Order

    Update an existing order

Customers

  • Create Customer

    Create a new customer

  • List Customers

    Retrieve a paginated list of customers

  • Get Customer

    Retrieve a single customer by ID

  • Search Customers

    Search customers by criteria

  • Update Customer

    Update an existing customer

Customer Address

  • Create Customer Address

    Add a new address to customer

  • Get Customer Address

    Retrieve a specific customer address

  • Update Customer Address

    Update an existing address

  • Delete Customer Address

    Remove an address from customer (cannot delete default address)

Locations

  • List Locations

    Retrieve all store locations

  • Get Location

    Retrieve a specific location

Fulfillments

  • Create Fulfillment

    Create a fulfillment for fulfillment orders

  • List Fulfillments

    Retrieve fulfillments for an order

Custom Collections

  • Create Custom Collection

    Create a new custom collection

  • List Custom Collections

    Retrieve all custom collections

Collects

  • Create Collect

    Add a product to a collection

  • List Collects

    Retrieve product-collection associations

  • Delete Collect

    Remove a product from a collection

Webhooks

  • Create Webhook

    Register a new webhook subscription

  • List Webhooks

    Retrieve all registered webhooks

  • Delete Webhook

    Unregister a webhook subscription

Draft Orders

  • Create Draft Order

    Create a new draft order

  • List Draft Orders

    Retrieve all draft orders

Transactions

  • Create Transaction

    Create a payment transaction (requires existing authorization)

  • List Transactions

    Retrieve payment transactions for an order

Refunds

  • Create Refund

    Create a refund for order items (requires captured payment)

  • List Refunds

    Retrieve refunds for an order

Other (13)

  • List Customer Addresses

    Retrieve all addresses for a customer

  • List Inventory Items

    Retrieve inventory items by IDs

  • List Inventory Levels

    Retrieve inventory levels across locations

  • Count Products

    Get total count of products

  • Count Product Variants

    Get count of variants for a product

  • Cancel Order

    Cancel an order

  • Count Orders

    Get total count of orders

  • Close Order

    Close an order

  • Open Order

    Reopen a closed order

  • Count Customers

    Get total count of customers

  • Adjust Inventory Level

    Adjust inventory quantity at a location (requires inventory tracking enabled)

  • Complete Draft Order

    Convert draft order to regular order

  • Calculate Refund

    Calculate refund amounts before processing (requires captured payment)

Set Up Your Shopify MCP Server in Minutes

One endpoint. Any framework. Your agent is talking to Shopify in under 10 lines of code.

MCP Clients

Agent Frameworks

Claude Desktop
{
  "mcpServers": {
    "stackone": {
      "command": "npx",
      "args": [
        "-y",
        "mcp-remote@latest",
        "https://api.stackone.com/mcp?x-account-id=<account_id>",
        "--header",
        "Authorization: Basic <YOUR_BASE64_TOKEN>"
      ]
    }
  }
}

More Commerce MCP Servers

Klaviyo

162+ actions

Stripe

133+ actions

Magento

125+ actions

Square

125+ actions

BigCommerce

120+ actions

Eventbrite

73+ actions

Gorgias

69+ actions

Shopify MCP Server FAQ

Shopify MCP server vs direct API integration — what's the difference?
A Shopify MCP server and direct API integration serve different use cases. Direct API integration is for software-to-software — backend code calling Shopify. A Shopify MCP server is for AI agents — MCP clients like Claude and Cursor, plus framework agents built with OpenAI, LangChain, or Vercel AI — discovering and calling Shopify at runtime. StackOne provides both.
How does Shopify authentication work for AI agents?
Shopify authentication for AI agents works through a StackOne Connect Session. Create one via the dashboard or the SDK — you get an auth link and ready-to-paste config for Claude Desktop, Cursor, and other MCP clients. Your user authenticates their own Shopify account; StackOne handles token exchange, storage, and refresh. Credentials never reach the LLM, and each user is isolated via origin_owner_id.
Are Shopify MCP tools vulnerable to prompt injection?
Yes — Shopify MCP tools can be vulnerable to indirect prompt injection. Any tool that reads user-written content — documents, messages, tickets, records, or free-text fields — is a potential vector. StackOne Defender scans every tool response before it enters the agent's context — regex patterns in ~1ms, then a MiniLM classifier in ~4ms. 88.7% accuracy, CPU-only.
What is the context bloat of a Shopify agent and how do I avoid it?
Context bloat happens when Shopify tool schemas and API responses eat your Shopify agent's memory, preventing it from reasoning effectively. A single Shopify query can return a massive JSON response, and connecting multiple tools compounds the problem. Tools Discovery and Code Mode reduce context bloat — loading only relevant tools per query and keeping raw responses out of the agent's context.
Can I limit which actions my Shopify agent can access?
Yes — you can limit which actions your Shopify agent can access directly from the StackOne dashboard. Toggle actions on or off, or restrict them to specific accounts, with no code changes to your agent. Session tokens can be scoped to exact actions so if one leaks, exposure stays contained.
Can I create custom agent actions for my Shopify MCP server?
Yes — you can create custom agent actions for your Shopify MCP server using Connector Builder. It's an integration agent your coding assistant (Claude Code, Cursor, or Copilot) can invoke to research Shopify's API, generate production-ready connector YAML, test against the live API, and validate before you ship.
When should I NOT use a Shopify MCP server?
Skip a Shopify MCP server if your integration is purely software-to-software — direct Shopify API integration is simpler when no AI agent is involved. For deterministic, compliance-critical operations (financial transactions, regulatory reporting), direct API gives you predictable behavior without agent-driven decision-making. MCP shines when AI agents need to dynamically discover and call Shopify actions at runtime.
What AI frameworks and AI clients does the StackOne Shopify MCP server support?
The StackOne Shopify MCP server supports both. MCP clients (paste-and-go apps): Claude Desktop, Claude Code, Cursor, VS Code, Goose. Agent frameworks (code SDKs you build with): OpenAI Agents SDK, Anthropic, Vercel AI, Google ADK, CrewAI, Pydantic AI, LangChain, LangGraph, Azure AI Foundry.

Put your AI agents to work

All the tools you need to build and scale AI agent integrations, with best-in-class connectivity, execution, and security.