Developers / MCP

Run your store from any AI assistant.

Two Model Context Protocol servers bring storefront.js into Claude, Cursor, VS Code and any other MCP client. The admin server works on your store with the permissions you already have; the storefront server lets an assistant browse a store and fill a cart. The tool list on this page is read live from the running servers.

Admin tools
Storefront tools
Example session
You

Refund order 1042 in full. It arrived damaged.

get_orderRead-onlycanViewOrders
orderId: "1042"
refund_orderIrreversiblecanRefundOrders
orderId: "1042", refundedAmountMinor: "4800", refundedCurrency: "USD"
Assistant

Refunded $48.00 to the original payment method. Order 1042 now shows as refunded.

Connect a client

Pick a server, then copy the setup for your client. Remote servers sign you in through your browser, so there is no token to paste.

Terminal
claude mcp add --transport http storefront-admin https://mcp.storefrontjs.com/admin/mcp

Then run /mcp inside Claude Code and choose the server to sign in through your browser.

Claude Desktop and claude.ai: open Settings, then Connectors, add a custom connector and paste the server URL.

Sign-in and permissions

The admin server uses OAuth 2.1 with dynamic client registration. Your client handles the whole flow; all you do is sign in and pick a store.

What happens when you connect

  1. Your client reads the server's metadata to find out where to sign in.

    https://mcp.storefrontjs.com/.well-known/oauth-protected-resource
  2. It fetches the authorization server's metadata: where to register, where to authorize and where to get tokens.

    https://api.storefrontjs.com/.well-known/oauth-authorization-server
  3. It registers itself and opens your browser, where you sign in and choose which store to connect.

  4. It exchanges your approval for a token and sends it with every request. You never handle the token yourself.

An assistant can't do more than you can

  • Every tool names the team permission it needs. If your role doesn't have it, the server refuses the call, whatever the assistant asks for.
  • The connection is checked against your team membership on every call. Remove a permission in the dashboard and the next call is refused.
  • Tools that change data are marked as such, so your client can ask you before running them. Irreversible ones, like refunds and deletions, are marked separately.

Tool reference

Every tool both servers offer, grouped by what it works on. Each group is a tool set: add ?toolsets= with its id to the admin server URL to connect only those tools. Open a tool to read its full description and arguments.

Loading the tool list from the MCP servers…