shopify-operations-mcp
Local package path declaredCredentials listedRepository declared by sourceUpdated 2026-08-17
io.github.jpka/shopify-operations-mcp · Registry status: active
At a glance
Safe-write Shopify operations: plan-before-execute writes with out-of-band approval and audit.
Vendor's own description, untranslated and unverified
- Execution location
- Local package path declaredMCP-Register · 2026-08-16
- Required secrets declared
- Credentials listedMCP-Register · 2026-08-16
- Declared version and change
0.1.2· Source-reported change date 2026-08-17MCP-Register · 2026-08-18- Repository as declared
- github.com/jpka/shopify-operations-mcpMCP-Register · 2026-08-16
- Configuration
- can be built from the disclosed start template
Inspect connection paths and prerequisites
Related categories
- MCP servers for commerce238
- MCP servers with declared required secrets6,067
- Locally executed MCP servers17,056
- MCP servers with a repository URL30,107
- Local MCP servers with a repository URL16,152
- MCP servers over stdio only13,710
6 of 13 categories. All categories in the segment catalogue
Page last changed:
Sources and collection
- Runs
- Local package path declared
- Credentials
- Credentials listed
- Registry record changed
- 2026-08-17
- Setup
- Template available
- Registry name
io.github.jpka/shopify-operations-mcp- Package coordinate
npm:shopify-operations-mcp- Declared version
0.1.2- Source-reported listing date
- 2026-08-17
- Source-reported change date
- 2026-08-17
- First seen by tracevero
- 2026-08-16
- Vendor's website
- https://github.com/jpka/shopify-operations-mcp
Evidence for this page: The values on this page come from several collections. Each row therefore states its own origin. What the confidence levels mean
Measured values
| Required secrets declared | Credentials listed yes Original data – Required secret variables (raw): SHOPIFY_ADMIN_TOKEN Original data – Required secret headers (raw): confirmed absent Source: MCP-Register · collected on 2026-08-16 · derived |
|---|---|
| Execution location | Local package path declared local Original data – Transports (raw): stdio Source: MCP-Register · collected on 2026-08-16 · derived |
| Path argument present | no Original data – Path arguments (raw): confirmed absent Original data – Path environment variables (raw): confirmed absent Source: MCP-Register · collected on 2026-08-16 · derived |
| Repository URL listed | Repository declared by source yes Original data – Repository (raw): https://github.com/jpka/shopify-operations-mcp Source: MCP-Register · collected on 2026-08-16 · derived |
| Field of use, derived from the vendor description | Commerce Original data – Description (raw): Safe-write Shopify operations: plan-before-execute writes with out-of-band approval and audit. Source: MCP-Register · collected on 2026-08-26 · derived |
| Declared version | 0.1.2 Source: MCP-Register · collected on 2026-08-18 · self-declared |
What is measured is what a manifest declares, not what a piece of software does. This registry fetches no repository URL, no endpoint and no package index; nothing here is verified. Which value comes from which source, and by which rule it was formed, is set out in the Methodology.
Source data25
Evidence for this page: The values on this page come from several collections. Each row therefore states its own origin.
| Description (raw) | Safe-write Shopify operations: plan-before-execute writes with out-of-band approval and audit. Source: MCP-Register · collected on 2026-08-26 · self-declared |
|---|---|
| Environment variables (raw) | SHOPIFY_STORE_DOMAIN, SHOPIFY_ADMIN_TOKEN, SHOPIFY_CONFIG, SHOPIFY_PLAN_TTL_MS, SHOPIFY_APPROVAL_SERVER_PORT, SHOPIFY_PROTECTED_TAGS, SHOPIFY_CALLER_ID, SHOPIFY_AUDIT_PATH Source: MCP-Register · collected on 2026-08-16 · self-declared |
| Required secret variables (raw) | SHOPIFY_ADMIN_TOKEN Source: MCP-Register · collected on 2026-08-16 · self-declared |
| Transports (raw) | stdio Source: MCP-Register · collected on 2026-08-16 · self-declared |
| Path arguments (raw) | confirmed absent Source: MCP-Register · collected on 2026-08-16 · self-declared |
| Repository (raw) | https://github.com/jpka/shopify-operations-mcp Source: MCP-Register · collected on 2026-08-16 · self-declared |
| Package registries (raw) | npm Source: MCP-Register · collected on 2026-08-16 · self-declared |
| Required secret headers (raw) | confirmed absent Source: MCP-Register · collected on 2026-08-16 · self-declared |
| Path environment variables (raw) | confirmed absent Source: MCP-Register · collected on 2026-08-16 · self-declared |
| Remote URLs (raw) | confirmed absent Source: MCP-Register · collected on 2026-08-16 · self-declared |
| Remote hosts (raw) | confirmed absent Source: MCP-Register · collected on 2026-08-16 · self-declared |
| Registry status message (raw) | confirmed absent Source: MCP-Register · collected on 2026-08-16 · self-declared |
| First listed in the registry (raw) | 2026-08-17 Source: MCP-Register · collected on 2026-08-18 · self-declared |
| Last changed in the registry (raw) | 2026-08-17 Source: MCP-Register · collected on 2026-08-18 · self-declared |
| Schema version of the raw record (raw) | https://static.modelcontextprotocol.io/schemas/2025-12-11/server.schema.json Source: MCP-Register · collected on 2026-08-16 · self-declared |
| Delivery form (raw) | package Source: MCP-Register · collected on 2026-08-16 · self-declared |
| Repository platform (raw) | github Source: MCP-Register · collected on 2026-08-16 · self-declared |
| Repository subfolder (raw) | confirmed absent Source: MCP-Register · collected on 2026-08-16 · self-declared |
| Package identifiers (raw) | shopify-operations-mcp Source: MCP-Register · collected on 2026-08-16 · self-declared |
| Package versions (raw) | 0.1.2 Source: MCP-Register · collected on 2026-08-18 · self-declared |
| Runtime hints (raw) | confirmed absent Source: MCP-Register · collected on 2026-08-16 · self-declared |
| Environment variable formats (raw) | string Source: MCP-Register · collected on 2026-08-16 · self-declared |
| Environment variable descriptions (raw) | SHOPIFY_ADMIN_TOKEN=Shopify Admin API access token. Required and only ever read from the environment — never from the config file. · SHOPIFY_APPROVAL_SERVER_PORT=Port the localhost human-approval HTTP server binds to (127.0.0.1 only). Default 4319. · SHOPIFY_AUDIT_PATH=File path for the tamper-evident JSONL audit log. Default shopify-operations-audit.jsonl in the working directory. · SHOPIFY_CALLER_ID=Identity recorded as the caller on every audit log row. Default unknown. · SHOPIFY_CONFIG=Path to a config.json with shopify/plans/approvalServer/protectedTags settings. Defaults to ./config.json in the working directory. · SHOPIFY_PLAN_TTL_MS=How long a plan token stays valid before it must be executed or expires, in milliseconds. Default 60000. · SHOPIFY_PROTECTED_TAGS=Comma-separated tags that plans may never modify; any plan touching an item carrying one is refused. Default do-not-touch. · SHOPIFY_STORE_DOMAIN=The myshopify.com store domain, e.g. my-store.myshopify.com. Overrides shopify.storeDomain from the config file. Source: MCP-Register · collected on 2026-08-16 · self-declared |
| Icon formats (raw) | confirmed absent Source: MCP-Register · collected on 2026-08-16 · self-declared |
| Connection paths (source structure) | {"packages":[{"registryType":"npm","identifier":"shopify-operations-mcp","version":"0.1.2","transport":"stdio","environment":[{"name":"SHOPIFY_STORE_DOMAIN","description":"The myshopify.com store domain, e.g. my-store.myshopify.com. Overrides shopify.storeDomain from the config file.","format":"string","required":true,"secret":false},{"name":"SHOPIFY_ADMIN_TOKEN","description":"Shopify Admin API access token. Required and only ever read from the environment — never from the config file.","format":"string","required":true,"secret":true},{"name":"SHOPIFY_CONFIG","description":"Path to a config.json with shopify/plans/approvalServer/protectedTags settings. Defaults to ./config.json in the working directory.","format":"string","required":false,"secret":false},{"name":"SHOPIFY_PLAN_TTL_MS","description":"How long a plan token stays valid before it must be executed or expires, in milliseconds. Default 60000.","format":"string","required":false,"secret":false},{"name":"SHOPIFY_APPROVAL_SERVER_PORT","description":"Port the localhost human-approval HTTP server binds to (127.0.0.1 only). Default 4319.","format":"string","required":false,"secret":false},{"name":"SHOPIFY_PROTECTED_TAGS","description":"Comma-separated tags that plans may never modify; any plan touching an item carrying one is refused. Default do-not-touch.","format":"string","required":false,"secret":false},{"name":"SHOPIFY_CALLER_ID","description":"Identity recorded as the caller on every audit log row. Default unknown.","format":"string","required":false,"secret":false},{"name":"SHOPIFY_AUDIT_PATH","description":"File path for the tamper-evident JSONL audit log. Default shopify-operations-audit.jsonl in the working directory.","format":"string","required":false,"secret":false}],"additional_arguments_declared":false}],"remotes":[]} Source: MCP-Register · collected on 2026-09-08 · self-declared |
Embed this badge
Paste this line into a README of your own. The badge states how many values the registry holds for the entry and when it last looked, and it links back to this page.
[](https://tracevero.com/mcp/io-github-jpka-shopify-operations-mcp)
The image is drawn again on every request, so it always reports the current state while the pasted line stays as it is. It carries no rating and no traffic light – only the two measured figures.
Changes
| 2026-09-08 | Connection paths (source structure): – → {"packages":[{"registryType":"npm","identifier":"shopify-operations-mcp","version":"0.1.2","transport":"stdio","environment":[{"name":"SHOPIFY_STORE_DOMAIN","description":"The myshopify.com store domain, e.g. my-store.myshopify.com. Overrides shopify.storeDomain from the config file.","format":"string","required":true,"secret":false},{"name":"SHOPIFY_ADMIN_TOKEN","description":"Shopify Admin API access token. Required and only ever read from the environment — never from the config file.","format":"string","required":true,"secret":true},{"name":"SHOPIFY_CONFIG","description":"Path to a config.json with shopify/plans/approvalServer/protectedTags settings. Defaults to ./config.json in the working directory.","format":"string","required":false,"secret":false},{"name":"SHOPIFY_PLAN_TTL_MS","description":"How long a plan token stays valid before it must be executed or expires, in milliseconds. Default 60000.","format":"string","required":false,"secret":false},{"name":"SHOPIFY_APPROVAL_SERVER_PORT","description":"Port the localhost human-approval HTTP server binds to (127.0.0.1 only). Default 4319.","format":"string","required":false,"secret":false},{"name":"SHOPIFY_PROTECTED_TAGS","description":"Comma-separated tags that plans may never modify; any plan touching an item carrying one is refused. Default do-not-touch.","format":"string","required":false,"secret":false},{"name":"SHOPIFY_CALLER_ID","description":"Identity recorded as the caller on every audit log row. Default unknown.","format":"string","required":false,"secret":false},{"name":"SHOPIFY_AUDIT_PATH","description":"File path for the tamper-evident JSONL audit log. Default shopify-operations-audit.jsonl in the working directory.","format":"string","required":false,"secret":false}],"additional_arguments_declared":false}],"remotes":[]} |
|---|---|
| 2026-08-26 | Field of use, derived from the vendor description: – → Commerce |
| 2026-08-26 | Description (raw): – → Safe-write Shopify operations: plan-before-execute writes with out-of-band approval and audit. |
These are the 3 most recent changes to this entry. Full history
tracevero · https://tracevero.com/mcp/io-github-jpka-shopify-operations-mcp