# Connections and permissions

A connection defines which ShopMCP features an AI client can call. Create separate connections for different tasks and people. Start with read access.

Skill settings are workflow instructions. They do not change Shopify scopes or restrict MCP tools that are already allowed. For a reliable read-only analysis, the connection itself must have read-only access. Shopify app permissions and the signed-in staff account also limit every call.

API keys use the installed ShopMCP app permissions for the store together with the connection's permissions. They do not inherit an individual Shopify staff member's permissions. OAuth connections use the Shopify online session of the person connecting the client, so that person's Shopify permissions apply. If the online session expires or is revoked, that person must reconnect the client.

Only the store owner manages API keys, settings of existing connections, skills and the theme archive, because a key passes on the app access of the whole store. Staff and collaborator accounts see connections read-only in the app and can create new connections without an API key that work through OAuth only. They add the connector URL `https://shopmcp.app/mcp` in their AI client, sign in with their own Shopify login and choose the connection. Access is always the intersection of their own Shopify permissions, the connection permissions and the consent they gave.

Advanced connection limits can separately restrict product content, prices, media, customer-data tools, and refunds. Price changes require both product-content and price approval. Refunds are also capped at the exact declared total amount. Batches are limited to 250 entries. Inventory locations and metafield namespaces can be restricted with allowlists.

When customer-data access is disabled, structured customer, contact, and address fields are removed from tool responses. Free-text fields can still contain personal information. Review those contents carefully too.

Disable or revoke connections that are no longer used. Review connection permissions and the audit log regularly. Do not share API keys in prompts or screenshots.
