npm · shopify-operations-mcp
$npx -y shopify-operations-mcp@0.1.2 SHOPIFY_STORE_DOMAIN (required) — The myshopify.com store domain, e.g. my-store.myshopify.com. Overrides shopify.storeDomain from the config file.
SHOPIFY_ADMIN_TOKEN (required) · secret — Shopify Admin API access token. Required and only ever read from the environment — never from the config file.
SHOPIFY_CONFIG — Path to a config.json with shopify/plans/approvalServer/protectedTags settings. Defaults to ./config.json in the working directory.
SHOPIFY_PLAN_TTL_MS — How long a plan token stays valid before it must be executed or expires, in milliseconds. Default 60000.
SHOPIFY_APPROVAL_SERVER_PORT — Port the localhost human-approval HTTP server binds to (127.0.0.1 only). Default 4319.
SHOPIFY_PROTECTED_TAGS — Comma-separated tags that plans may never modify; any plan touching an item carrying one is refused. Default do-not-touch.
SHOPIFY_CALLER_ID — Identity recorded as the caller on every audit log row. Default unknown.
SHOPIFY_AUDIT_PATH — File path for the tamper-evident JSONL audit log. Default shopify-operations-audit.jsonl in the working directory.