AgentsReady
Verified deep dive · Commerce

Shopify

Run the agent liveReport a change
3 minTime to key
YesNo-human path
0Gates to a test key
9/10Onboarding score
Live keys only:Email verificationManual reviewWaitlist

Fastest path to a key

  1. Agentic-commerce path (fastest): `npm install -g @shopify/ucp-cli` + `claude plugin install shopify-ai-toolkit@claude-plugins-official`; `ucp profile init --name agent`; `ucp catalog search ...` works with NO credenti…
  2. For Token tier: sign up / log in at dev.shopify.com (Dev Dashboard) -> Catalogs -> 'Get an API key' -> name -> Create -> copy client_id/client_secret -> exchange for a JWT bearer token at runtime.
  3. Admin approval
    Admin API path: Dev Dashboard account -> create free dev store -> `shopify app init` (Shopify CLI opens browser login) -> app installed on dev store -> Admin API access token.
  4. Merchant path with no developer work: add Claude connector https://setup.shopify.com/mcp (OAuth, CIMD) -> sign in to Shopify -> manage store / even create a business before a store exists.
  5. Working API key

Biggest gap

Completing checkout in-agent requires trusted-tier approval (most agents hand off to continue_url); Universal Cart behind a Google-Form waitlist; shopify.dev lacks a real llms.txt.

Worth copying

Tiered trust (anonymous -> signed profile -> token) lets agents start with no credential and upgrade; every doc page has a .md twin.

Sources (12) · checked 2026-10-11
53Readiness score / 100
L2 Agent-documentedBeats 71% of 1,846 companies
Access20/20
Context20/20
Interfaces8/32
Onboarding3/19
Trust2/9
llms.txt · root

Biggest gains

  1. +12 Remote MCP server for the product. Host a remote MCP server (e.g. mcp.<domain>/mcp, Streamable HTTP) for your core actions.
  2. +8 Machine-readable API spec. Publish an OpenAPI spec at a stable URL like /openapi.json and link it from llms.txt.
  3. +6 Agents can self-register OAuth clients. Support dynamic client registration (RFC 7591) or client ID metadata documents so MCP clients connect in one click.
All 20 checks
  • PASSAgents get the real page, not a bot wall10
  • PASSrobots.txt lets user-triggered agents in6
  • PASSContent is server-rendered4
  • PASSllms.txt exists8
  • PASSllms-full.txt exists3
  • PASSDocs available as markdown6
  • PASSSitemap2
  • PASSStructured metadata1
  • PASSPublic developer docs4
  • FAILMachine-readable API spec8
  • FAILRemote MCP server for the product12
  • FAILDocs MCP or searchable docs4
  • PASSSDKs and a CLI4
  • FAILOAuth discovery metadata5
  • FAILAgents can self-register OAuth clients6
  • FAILSelf-serve API keys5
  • PASSFree tier or test mode3
  • FAILAgent manifests4
  • PASSsecurity.txt2
  • FAILPublic status page3

Your fix pack: 9 changes, up to +47 points

Each change is ready to paste, filled in for shopify.com, with a command to check it worked. Or hand the whole list to your coding agent.

A remote MCP server lets Claude, ChatGPT and Cursor act on your product in one click, with no glue code.

Where: https://mcp.shopify.com/mcp (Streamable HTTP)
// npm i @modelcontextprotocol/sdk zod  — minimal remote MCP server (Streamable HTTP, stateless)
import { McpServer } from "@modelcontextprotocol/sdk/server/mcp.js";
import { StreamableHTTPServerTransport } from "@modelcontextprotocol/sdk/server/streamableHttp.js";
import express from "express";
import { z } from "zod";

const app = express();
app.use(express.json());

app.post("/mcp", async (req, res) => {
  const server = new McpServer({ name: "shopify.com", version: "1.0.0" });
  // One tool per core job. Clear verbs, typed inputs, small outputs.
  server.tool("create_<thing>", "Create a <thing> for the signed-in user.", { name: z.string() },
    async ({ name }) => {
      const key = req.headers.authorization?.replace("Bearer ", ""); // scoped API key or OAuth token
      const r = await fetch("https://shopify.com/v1/<things>", { method: "POST", headers: { Authorization: `Bearer ${key}` }, body: JSON.stringify({ name }) });
      return { content: [{ type: "text", text: await r.text() }] };
    });
  const transport = new StreamableHTTPServerTransport({ sessionIdGenerator: undefined });
  res.on("close", () => transport.close());
  await server.connect(transport);
  await transport.handleRequest(req, res, req.body);
});
app.listen(3000);
Check it worked:curl -s -X POST https://mcp.shopify.com/mcp -H 'Content-Type: application/json' -H 'Accept: application/json, text/event-stream' -d '{"jsonrpc":"2.0","id":1,"method":"initialize","params":{"protocolVersion":"2025-06-18","capabilities":{},"clientInfo":{"name":"t","version":"1"}}}' -i | head -15

Add the badge to your README

AgentsReady badge for shopify.com
[![AgentsReady](https://agentsready.dev/badge/shopify.com)](https://agentsready.dev/c/shopify.com)