
Security News
Ruby's Bundler 4.0.18 Extends Cooldown to bundle lock and bundle cache
The supply chain control that delays freshly published gems now covers lockfile generation and gem vendoring in Ruby projects.
@den.dance/shopify-mcp-pro
Advanced tools
The working Shopify MCP server — fixed analytics, auto-refresh auth, ShopifyQL support, Shopify API 2026-04
The working Shopify MCP server. Connect Claude to your Shopify store — products, orders, customers, inventory, analytics and more.
Most Shopify MCP packages have broken analytics (stubs that return wrong data), use deprecated API fields that crash at runtime, and require a static token that expires silently. This one doesn't.
Built by Denis Maleev.
| What's fixed | Detail |
|---|---|
| Analytics tools were stubs | getSalesReport, getConversionReport, getTrafficReport now powered by ShopifyQL — real data |
| Auth that actually works | Uses Client ID + Secret from Shopify Dev Dashboard, tokens refresh automatically — no silent expiry |
| Deprecated API fields | getInventoryLevels, listAbandonedCheckouts updated to Shopify 2026-04 field schema |
| Runtime crashes | getShippingZones no longer crashes on stores with no delivery profiles |
New: runShopifyQL | Run any ShopifyQL query directly — same data as Admin → Analytics |
| Shopify Admin API | 2026-04 (current GA) + @shopify/shopify-api v13 |
npx @den.dance/shopify-mcp-pro
Note: Shopify no longer shows a static access token by default. This server uses OAuth with Client ID + Secret.
Edit your Claude Desktop config file:
~/Library/Application Support/Claude/claude_desktop_config.json%APPDATA%\Claude\claude_desktop_config.json~/.config/Claude/claude_desktop_config.json{
"mcpServers": {
"shopify": {
"command": "npx",
"args": ["@den.dance/shopify-mcp-pro"],
"env": {
"SHOPIFY_STORE_DOMAIN": "your-store.myshopify.com",
"SHOPIFY_CLIENT_ID": "your-client-id",
"SHOPIFY_CLIENT_SECRET": "your-client-secret",
"SHOPIFY_API_VERSION": "2026-04",
"SHOPIFY_LOG_LEVEL": "WARNING"
}
}
}
}
Restart Claude Desktop after saving.
claude mcp add shopify -e SHOPIFY_STORE_DOMAIN=your-store.myshopify.com \
-e SHOPIFY_CLIENT_ID=your-client-id \
-e SHOPIFY_CLIENT_SECRET=your-client-secret \
-- npx @den.dance/shopify-mcp-pro
| Variable | Required | Description |
|---|---|---|
SHOPIFY_STORE_DOMAIN | Yes | e.g. my-store.myshopify.com |
SHOPIFY_CLIENT_ID | Yes | From Shopify Dev Dashboard |
SHOPIFY_CLIENT_SECRET | Yes | From Shopify Dev Dashboard |
SHOPIFY_API_VERSION | No | Defaults to 2026-04 |
SHOPIFY_LOG_LEVEL | No | error, warning, info, debug (default: warning) |
TRANSPORT_MODE | No | stdio (default) or sse |
PORT | No | HTTP port for SSE mode (default: 3000) |
read_products, write_productsread_ordersread_customersread_inventory, write_inventoryread_analyticsread_reportsread_draft_orders, write_draft_ordersread_fulfillments, write_fulfillmentsread_shippingread_marketing_events, write_marketing_eventsread_discounts, write_discountsread_price_rules, write_price_rulesread_themesread_content, write_contentread_metaobjects, write_metaobjectsread_gift_cards, write_gift_cardsYou don't need all scopes — the server works with whatever you grant. Tools requiring missing scopes return auth errors without affecting others.
listProducts — list with filters, pagination, sortgetProduct — get by ID (includes inventory item IDs)createProduct, updateProductgetInventoryLevels — current stock across locationsadjustInventory — adjust quantitieslistCollectionssetMetafieldlistMetaobjectDefinitions, createMetaobject, listMetaobjectslistOrders, getOrdercreateDraftOrder, listDraftOrderscreateFulfillment, listFulfillmentOrdersgetShippingZonescreateRefundlistTransactionslistCustomers, getCustomergetCustomerAnalyticscreateCompany, listCompaniesgetFinancialSummarycreateGiftCard, listGiftCardscreateDiscountCode, listDiscountslistPriceRulescreatePage, listPagescreateArticle, listBlogscreateRedirectcreateWebhook, listWebhooksgetSalesReport — revenue, orders, AOV (ShopifyQL)getProductAnalytics — top products by sales (ShopifyQL)getConversionReport — product conversion funnel (ShopifyQL)getTrafficReport — sales by referrer source (ShopifyQL)getAbandonmentReport — cart abandonment by date rangelistAbandonedCheckoutsgetMarketingReportgetCustomerAnalyticsrunShopifyQL — run any ShopifyQL query directlygetShopInfolistThemeslistLocationslistMarketsgetInventoryReportgetCustomReportrunShopifyQL lets you run raw ShopifyQL queries — Shopify's native SQL-like analytics language:
FROM sales SHOW total_sales, gross_sales, total_orders SINCE '2026-01-01' UNTIL '2026-05-19'
FROM products SHOW total_sales BY product_title ORDER BY total_sales DESC LIMIT 10
FROM sessions SHOW sessions BY referrer_source
Requires read_reports scope + Level 2 customer data access in your Shopify app settings.
For HTTP-based access or cloud deployment:
TRANSPORT_MODE=sse \
SHOPIFY_STORE_DOMAIN=your-store.myshopify.com \
SHOPIFY_CLIENT_ID=your-client-id \
SHOPIFY_CLIENT_SECRET=your-client-secret \
PORT=3000 \
npx @den.dance/shopify-mcp-pro
Endpoints:
GET /sse — SSE streamPOST /messages?sessionId={id} — send messagesGET /health — health checkConfigure Claude Desktop for remote SSE:
{
"mcpServers": {
"shopify-remote": {
"transport": {
"type": "sse",
"url": "https://your-server.com/sse"
}
}
}
}
MIT
FAQs
The working Shopify MCP server — fixed analytics, auto-refresh auth, ShopifyQL support, Shopify API 2026-04
We found that @den.dance/shopify-mcp-pro demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
The supply chain control that delays freshly published gems now covers lockfile generation and gem vendoring in Ruby projects.

Security News
During a UK cyber test, a Mythos 5 agent used sockpuppets, social engineering, and prompt injection to try to get a maintainer to merge malware.

Company News
Socket is now in the AWS Security Hub Extended plan. Adopt it through AWS, apply committed spend, and block malicious open source packages.