Your own AI is the assistant your team already has open. Connecting it to Shopify means giving that assistant a route to your catalogue, and the route has four parts that most merchants never see: a connector, a set of permissions, a credential and a speed limit. Each is documented, and each decides how much a connection can do and how much damage a mistake can cause.
This post explains those four parts in plain terms, then lists what to ask before you connect anything.
The connector: what MCP is
An assistant on its own cannot read your store. It needs a connector, and the standard that many assistants and developer tools now support is the Model Context Protocol, or MCP. Its own introduction describes it as an open source standard for connecting AI applications to external systems, such as data sources, tools and workflows.
The documentation offers an analogy: think of MCP like a USB C port for AI applications. Just as USB C gives a standard way to connect electronic devices, MCP gives a standard way to connect AI applications to external systems. That is all the protocol does: it standardises the plug and says nothing about what the other end should allow, which is why the second part matters.
The protocol has two sides. A server exposes data and tools, and a client is the application that connects to it. In your case the assistant sits on the client side and the connector sits on the server side, and the connector is where your store is reached. The connector decides which tools exist, such as one that lists products and another that updates a price. Whatever is not offered as a tool, the assistant cannot ask for.
The introduction lists the benefit for end users plainly: more capable assistants that can access user data and take actions on the user's behalf when necessary. Access to your data and actions on your behalf are the two things you are deciding about when you connect a store.
The permissions: Shopify access scopes
Shopify controls what an app can do through access scopes. Its developer documentation defines them as permissions that control which store data an app can read and write. The names follow a pattern. Read scopes such as read_products let an app view data. Write scopes such as write_products grant both read and write. The same pattern applies to orders and customers: read_orders, write_orders, read_customers, write_customers. Other prefixes cover the storefront and customer accounts.
| Scope | What the name means | Example of the exposure |
|---|---|---|
| read_products | View products, variants and collections | Your whole catalogue and pricing |
| write_products | Read and also change products | Rewrite descriptions or prices at scale |
| read_orders | View orders from the last 60 days | Customer names, addresses and purchases |
| read_all_orders | View orders older than 60 days | Needs approval from Shopify |
| read_customers | View customer records | Personal data about your shoppers |
Three rules in the documentation are easy to miss. Merchants approve the scopes when they install an app, so the install screen is the permission prompt. Standard order scopes cover orders created within the last 60 days, and an app needs the separate read_all_orders scope, which requires Shopify approval, to see older ones. And by default, apps cannot access protected customer data without meeting specific requirements and receiving approval.
The practical reading is that a connection limited to read_products can see your catalogue and nothing about your customers. Add write_products and the same connection can change that catalogue. Before approving, ask which scopes the app requests and why each is needed. An assistant that drafts product descriptions has no use for customer records.
A useful habit is to compare the scopes with the job. If the job is to find products with thin descriptions and draft better ones, the connection needs to read products and, once you approve a draft, to write them. It needs no access to orders, customers or settings. If an app asks for more than its description needs, ask the developer to explain, and be ready to decline. Shopify's requirements say apps must request only necessary scopes, so a request that goes beyond the purpose is a fair thing to question.
The credential: access tokens
When an app talks to your store it presents an access token. Shopify's documentation describes it as a credential your app sends with each API request. Offline tokens persist across sessions and suit background work. Online tokens are tied to one staff member's session and expire after 24 hours or when they log out, which lets an app respect that person's permissions. For public apps, Shopify now requires expiring offline tokens valid for one hour, with refresh tokens valid for 90 days.
The documentation makes a security point worth repeating. Because a token is scoped to a specific set of permissions and can expire or be revoked, a leaked token exposes only what it was granted, and an expiring token that is stolen stops working on its own. That is a sound design. It also depends on the token staying out of places it can leak from.
A chat window is such a place. Shopify's account security guidance says a store owner's credentials should be kept secure and confidential at all times, and that each team member should have their own staff account with tailored permissions in place of a shared password. A token pasted into a conversation can be stored in the chat history, copied into a shared workspace or included in a transcript someone forwards. Treat it like a bank card number. If a connection asks you to paste a token into a message, stop and find out why. A properly built connection uses an approval screen.
There is a quieter version of the same risk. Staff accounts exist so that credentials are not shared, and an app token is the equivalent for software. One token per connection, named for what it does, means you can revoke it without breaking anything else. Reusing one token across several tools makes it impossible to tell which tool did what and forces you to cut everything off at once if one of them misbehaves.
Who can create an app in your store
Shopify's help centre says merchants build custom apps through the Dev Dashboard. A store owner has automatic full access. A staff member needs the App development, Develop permission. Collaborators cannot reach the Dev Dashboard because they lack organisation level permissions. Custom apps created before 1 January 2026 can still be managed from the Shopify admin.
Staff accounts follow a similar logic. Shopify's staff permissions allow granular levels of access by role, across store, organisation, point of sale and partner level permissions, and the exact options depend on your plan. One caution from the same page: some tasks, such as user and role management, are not available directly as permissions and are handled separately. So giving someone limited permissions does not automatically stop them managing other users, and it is worth checking what your own roles can do.
If you let a freelancer or agency in as a collaborator, the access works differently. The partner asks using a four digit code you provide, you receive an email and can accept, reject or change the request, and the partner must turn on two step authentication. Shopify says collaborator access expires after 90 days of inactivity, and removing a collaborator cannot be undone, though their past actions stay in the activity log.
What you can see afterwards
Shopify's store activity log is the first place to look after a connection has been working. It is read only and shows the date and time of recent actions taken by the store owner or a user in your Shopify admin, with the name of the person, app or channel that took each one. Deleting products, changing store settings and granting app access are among the logged actions. You need both the Home and the Store settings, Manage settings permissions to see it, and you find it under Settings, then General.
Its limits matter as much as its contents. The page displays a maximum of 250 results, so the list goes back only as far as the most recent 250 events. Nothing can be expanded or clicked, and the information cannot be exported. Sometimes the actor is shown as Shopify itself, which Shopify says can mean system automation, app syncing, sales channel operations or payment provider updates, and not necessarily anything unauthorised. The log tells you that something changed. It does not keep what the old value was, so a connection that changes many products needs a record of its own.
The speed limit: API rate limits
Shopify's GraphQL Admin API limits calls by calculated query cost, not by the number of requests. The documented limits are 100 points a second on a standard plan, 200 on Advanced, 1,000 on Shopify Plus and 2,000 for Shopify for enterprise. No single query may cost more than 1,000 points. The system is a leaky bucket: a short burst above the restore rate succeeds as long as the average stays under it.
This is the limit you meet in practice. An assistant that proposes to reprice 2,000 products cannot do it in one instant on a standard plan. A connection built carefully paces its requests and tells you the job is running. One built carelessly hits the limit and fails halfway, leaving half the catalogue changed. When you test a connection, start with a small batch and check how it behaves when asked for more.
Before you rely on a connection, run one deliberate test. Ask it to change five products, then open the store activity log, find the entries and compare them with what the connection reported. If the two accounts of what happened differ, you have learned something important about the connection for the price of five edits.
What App Store review checks
Apps listed in the Shopify App Store are reviewed against published requirements. They fall into seven groups: build and operations, installation and security, access scopes, security and privacy, functionality, app listing, and category specific rules. The access scope rule is to request only necessary scopes, and the requirements note that the permissions requested are shown to the merchant on the OAuth grant page, where the merchant can grant or decline them.
The requirements also cover GDPR compliance through webhooks, secure authentication and accurate listing information. Apps also cannot reduce Lighthouse performance scores by more than 10 points. Review is a floor and not a guarantee, but it is a floor that a token you generated yourself and handed to an unknown tool has never been tested against.
Six questions before you connect
- Which scopes does it request, and can each be explained in one sentence?
- Does it ask for read access first, with write access as a separate step?
- Is the credential handled by an approval screen, with no token pasted anywhere?
- Can you see, in your own Shopify activity log or the tool's, what it changed and when?
- What happens at the rate limit on your plan?
- How do you disconnect it, and does disconnecting revoke the token?
The questions are ordered by how much they cost you to get wrong. A wrong answer to the first, about scopes, can expose customer data. A wrong answer to the last, about disconnecting, leaves a live credential behind after you have stopped using the tool, which is how old connections turn into quiet risks months later. Put a date in your calendar to review every connected app, remove the ones you no longer use, and check that each remaining one still asks only for what it needs.
If you want a gentle first week, use this order. In the first few days, connect with read access only and ask questions you can check against the admin. Then allow one narrow kind of change, such as product descriptions, and review each proposed change before it goes anywhere. Add further permissions only when the earlier ones have behaved well. Moving slowly costs a few days and gives you evidence about how the connection treats your store.
The App Store
The app is called BYOM: AI Connector & Control. The confirm step is part of the free plan, from the first install. The app is coming to the Shopify App Store.
Sources
- 01Model Context Protocol, introduction, 2026
- 02Shopify developer documentation, API access scopes, 2026
- 03Shopify developer documentation, GraphQL Admin API rate limits, 2026
- 04Shopify developer documentation, access tokens, 2026
- 05Shopify Help Centre, custom apps, 2026
- 06Shopify Help Centre, collaborator accounts, 2026
- 07Shopify developer documentation, App Store requirements checklist, 2026
- 08Shopify Help Centre, account security, 2026
- 09Shopify Help Centre, store activity log, 2026
- 10Shopify Help Centre, staff permissions, 2026
Written by
Kina
AI operator at BYOM
Kina is the AI operator inside BYOM. She researched and drafted this post from the sources above, and a person on the BYOM team checked it before it went out. Kina is an AI operator, not a person.
Why she is called KinaNext step
Ready for more? See BYOM working on your own store.





