Shopify for AI agents
Shopify is an ecommerce platform that runs online stores, from product catalogs to checkout, orders, and fulfillment. Merchants of all sizes use it to sell products and manage inventory. Connect it once through Arc0, and your agent, or Claude, ChatGPT and Cursor, can use it through one MCP endpoint, limited to what each user approved.
What agents do in Shopify.
Adjust inventory levels
Update the inventory count for a product at a specific location after a stock check.
Review an order before cancelling
Look up an order's status and items before cancelling it, since cancellation can trigger a refund.
Complete a draft order
Finalize a draft order into a real order once pricing and items are confirmed.
407 Shopify actions, graded by risk.
Every Shopify action is tagged read, write or destructive, so one policy covers the whole app and new actions inherit the right default.
read
206Look things up. Allowed by default.
- shopify.get_appGet App
- shopify.get_blogGet Single Blog
- shopify.get_eventGet event by ID
- shopify.get_orderGet order
- shopify.get_themeRetrieve a single theme
- shopify.query_jobQuery job
- shopify.get_eventsGet events list (Deprecated)
- shopify.get_themesGet themes
- shopify.list_blogsRetrieve a list of all blogs
- shopify.list_orderList orders (Deprecated)
- shopify.list_pagesRetrieve list of pages
- shopify.query_nodeQuery node by ID
- shopify.query_shopQuery Shop (GraphQL)
- shopify.get_articleGet Article
- shopify.get_countryGet country
- shopify.get_productGet product
write
152Create and change things. Allow, or ask the user first.
- shopify.create_blogCreate a new blog
- shopify.create_pageCreate a new page
- shopify.update_blogModify an existing blog
- shopify.update_pageUpdate Page
- shopify.create_orderCreate an order
- shopify.create_themeCreate Theme
- shopify.send_invoiceSend an invoice
- shopify.update_orderUpdate Order
- shopify.update_themeModify existing theme
- shopify.create_articleCreate Article
- shopify.create_countryCreate Country
- shopify.create_productCreate a product (Deprecated)
- shopify.create_webhookCreate Webhook (Deprecated)
- shopify.update_articleUpdate Article
- shopify.update_commentUpdate Comment
- shopify.update_countryUpdate Country
destructive
49Delete, cancel or archive. Ask first, or deny outright.
- shopify.delete_blogDelete a blog
- shopify.delete_pageDelete a page
- shopify.cancel_orderCancel an order
- shopify.delete_orderDelete an order
- shopify.delete_themeDelete theme
- shopify.delete_articleDelete Article
- shopify.delete_collectRemove product from collection
- shopify.delete_commentRemove a comment
- shopify.delete_countryDelete country
- shopify.delete_productDelete a product
- shopify.delete_webhookDelete webhook subscription (Deprecated)
- shopify.delete_customerDelete a customer
- shopify.delete_redirectDelete redirect
- shopify.delete_metafieldDelete a metafield by its ID
- shopify.delete_metaobjectDelete metaobject
- shopify.delete_order_riskDelete order risk
Shopify in three steps.
- 01Your users connect ShopifyThey sign in to Shopify on Arc0 Connect, under your brand, and approve the access you ask for.
- 02You set the rulesReads run, writes like “create a new blog” can wait for the user, and “delete a blog” can be denied outright.
- 03Any agent can actYour agent calls Shopify through the Arc0 SDK or MCP, and so can Claude, ChatGPT and Cursor. Every call lands on the audit log.
await arc0.policies.set('shopify', { read: 'allow', write: 'ask', // create_blog destructive: 'deny', // delete_blog }) # Claude Code: the same connection, one URL $ claude mcp add --transport http arc0 \ https://mcp.arc0.ai/u/u_8f2
How Shopify connects.
Users sign in to Shopify on Arc0 Connect and approve the scopes you request. Build with Arc0’s Shopify OAuth app, or bring your own so the Shopify consent screen names you. Tokens refresh automatically, and you can export them whenever you want.
The same Shopify connection serves your agent over MCP and your own backend over REST and the proxy, so a user connects once. How Arc0 handles credentials →
- AUTH
- API key · OAuth 2.0 · OAuth 2.0 client credentials
- CREDENTIALS
- Per-tenant encrypted vault
- MODEL SEES
- Results only, never credentials
- AUDIT LOG
- Every call, on every plan
Use Shopify from any agent.
Shopify and Arc0, answered.
Can I use Shopify with Claude, ChatGPT or Cursor?
Yes. Connect Shopify to Arc0 once, then add your Arc0 MCP URL to Claude, ChatGPT, Cursor, Claude Code or any other remote-MCP client. Each assistant only gets the Shopify actions you allow.
How do users connect Shopify?
Users sign in to Shopify on Arc0 Connect and approve the scopes you request. Build with Arc0’s Shopify OAuth app, or bring your own so the Shopify consent screen names you. Tokens refresh automatically, and you can export them whenever you want.
Which Shopify actions can my agent take?
407 in total: 206 read, 152 write and 49 destructive, such as “create a new blog”. Your policies decide which of them each agent may call.
Can I stop my agent from deleting things in Shopify?
Yes. Actions like “delete a blog” are graded destructive. Set destructive actions to deny, or to ask so the user approves each one, and blocked calls still show up on the audit log.
Can my own backend call Shopify too?
Yes. The same Shopify connection is available over REST and through the Arc0 proxy, so your product and your agent share one connection per user.
Plug Shopify into your agent.
Your users connect Shopify once, under your brand. Your agent gets 407 actions behind your policies, with every call on the record.
Free to build · MCP + REST · Audit log on every plan