Developers / MCP
Run your store from any AI assistant.
Two Model Context Protocol servers bring storefront.js into Claude, Cursor, VS Code and any other MCP client. The admin server works on your store with the permissions you already have; the storefront server lets an assistant browse a store and fill a cart. The tool list on this page is read live from the running servers.
- Admin tools
- Storefront tools
Refund order 1042 in full. It arrived damaged.
get_orderRead-onlycanViewOrdersorderId: "1042"refund_orderIrreversiblecanRefundOrdersorderId: "1042", refundedAmountMinor: "4800", refundedCurrency: "USD"Refunded $48.00 to the original payment method. Order 1042 now shows as refunded.
Connect a client
Pick a server, then copy the setup for your client. Remote servers sign you in through your browser, so there is no token to paste.
claude mcp add --transport http storefront-admin https://mcp.storefrontjs.com/admin/mcpThen run /mcp inside Claude Code and choose the server to sign in through your browser.
Claude Desktop and claude.ai: open Settings, then Connectors, add a custom connector and paste the server URL.
Sign-in and permissions
The admin server uses OAuth 2.1 with dynamic client registration. Your client handles the whole flow; all you do is sign in and pick a store.
What happens when you connect
Your client reads the server's metadata to find out where to sign in.
https://mcp.storefrontjs.com/.well-known/oauth-protected-resourceIt fetches the authorization server's metadata: where to register, where to authorize and where to get tokens.
https://api.storefrontjs.com/.well-known/oauth-authorization-serverIt registers itself and opens your browser, where you sign in and choose which store to connect.
It exchanges your approval for a token and sends it with every request. You never handle the token yourself.
An assistant can't do more than you can
- Every tool names the team permission it needs. If your role doesn't have it, the server refuses the call, whatever the assistant asks for.
- The connection is checked against your team membership on every call. Remove a permission in the dashboard and the next call is refused.
- Tools that change data are marked as such, so your client can ask you before running them. Irreversible ones, like refunds and deletions, are marked separately.
Tool reference
Every tool both servers offer, grouped by what it works on. Each group is a tool set: add ?toolsets= with its id to the admin server URL to connect only those tools. Open a tool to read its full description and arguments.
Loading the tool list from the MCP servers…