{"_id":"storefront-mcp","_rev":"2-370a85ec86b4f8c44b10b7590811ef25","name":"storefront-mcp","dist-tags":{"latest":"1.0.1"},"versions":{"1.0.0":{"name":"storefront-mcp","version":"1.0.0","keywords":["mcp","model-context-protocol","mcp-server","ecommerce","ai-agents","nextjs","woocommerce"],"license":"Apache-2.0","_id":"storefront-mcp@1.0.0","maintainers":[{"name":"maarmapa","email":"mario@boykot.cl"}],"homepage":"https://github.com/Maarmapa/storefront-mcp#readme","bugs":{"url":"https://github.com/Maarmapa/storefront-mcp/issues"},"bin":{"storefront-mcp":"dist/src/cli/cli.js"},"dist":{"shasum":"83aeb151b3e93a6aa20851979c859d24ab3b3f13","tarball":"https://registry.npmjs.org/storefront-mcp/-/storefront-mcp-1.0.0.tgz","fileCount":13,"integrity":"sha512-QvasjX7vwjpCXTD0YyBbCLAu4/ow/ZaS1NyFcndpdURZ10C13+L4fLpF0Gtyp9qktDBwMp0IkrQNRHDbLAJK3g==","signatures":[{"sig":"MEUCIAm6AddfllKesltR7RtGb8RhFd56f9EP9EOVbE/wpUzkAiEAnUDek1UhnaOtN3CX3dupZYAywMIEha7YFonSH3UrjWE=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":82053},"engines":{"node":">=20"},"gitHead":"0f1381047840760ea46ac5e95c74776b1268e5dd","scripts":{"dev":"next dev","build":"next build","start":"next start","build:cli":"tsc -p tsconfig.build.json","typecheck":"tsc --noEmit","prepublishOnly":"npm run build:cli"},"_npmUser":{"name":"maarmapa","email":"mario@boykot.cl"},"repository":{"url":"git+https://github.com/Maarmapa/storefront-mcp.git","type":"git"},"_npmVersion":"10.9.7","description":"MCP server template for e-commerce storefronts: public catalog tools for AI agents, token-gated back-office tools for you. Runs standalone via `npx storefront-mcp` (stdio) or as a Next.js App Router route.","directories":{},"_nodeVersion":"22.22.2","dependencies":{"@modelcontextprotocol/sdk":"^1.17.0"},"_hasShrinkwrap":false,"devDependencies":{"next":"^15.4.0","react":"^19.0.0","react-dom":"^19.0.0","typescript":"^5.6.0","@types/node":"^22.0.0","@types/react":"^19.0.0"},"_npmOperationalInternal":{"tmp":"tmp/storefront-mcp_1.0.0_1785892589994_0.31353671864845767","host":"s3://npm-registry-packages-npm-production"}},"1.0.1":{"name":"storefront-mcp","version":"1.0.1","description":"MCP server template for e-commerce storefronts: public catalog tools for AI agents, token-gated back-office tools for you. Runs standalone via `npx storefront-mcp` (stdio) or as a Next.js App Router route.","keywords":["mcp","model-context-protocol","mcp-server","ecommerce","ai-agents","nextjs","woocommerce"],"license":"Apache-2.0","repository":{"type":"git","url":"git+https://github.com/Maarmapa/storefront-mcp.git"},"bin":{"storefront-mcp":"dist/src/cli/cli.js"},"engines":{"node":">=20"},"scripts":{"dev":"next dev","build":"next build","start":"next start","build:cli":"tsc -p tsconfig.build.json","prepublishOnly":"npm run build:cli","typecheck":"tsc --noEmit"},"dependencies":{"@modelcontextprotocol/sdk":"^1.17.0"},"devDependencies":{"@types/node":"^22.0.0","@types/react":"^19.0.0","next":"^15.4.0","react":"^19.0.0","react-dom":"^19.0.0","typescript":"^5.6.0"},"mcpName":"io.github.Maarmapa/storefront-mcp","_id":"storefront-mcp@1.0.1","gitHead":"387a570769d44d10a2bc9c23e87d7af438137541","bugs":{"url":"https://github.com/Maarmapa/storefront-mcp/issues"},"homepage":"https://github.com/Maarmapa/storefront-mcp#readme","_nodeVersion":"22.22.2","_npmVersion":"10.9.7","dist":{"integrity":"sha512-s6kuYrf4Jt2B2qQOWqtdfJiCum48KJyPNTihvknBSZCz5s3FUVns6Ec19ltc8g/9ArWUNOFMck753tT9DqMeag==","shasum":"796a500a56f6094bae2e9dc1cec1f845cfdcc58e","tarball":"https://registry.npmjs.org/storefront-mcp/-/storefront-mcp-1.0.1.tgz","fileCount":13,"unpackedSize":81959,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEYCIQDbsd0ySb1jx7+cFjMUWitr0emCsDKQzr9IRjpc2UbT1wIhALLOWQRjcDqmwNeyt3FmcBYbZCFAnzwF5uew3oIEGq+1"}]},"_npmUser":{"name":"maarmapa","email":"mario@boykot.cl"},"directories":{},"maintainers":[{"name":"maarmapa","email":"mario@boykot.cl"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/storefront-mcp_1.0.1_1785895605814_0.8295600836537054"},"_hasShrinkwrap":false}},"time":{"created":"2026-08-05T01:16:29.787Z","modified":"2026-08-05T02:06:46.132Z","1.0.0":"2026-08-05T01:16:30.154Z","1.0.1":"2026-08-05T02:06:45.953Z"},"bugs":{"url":"https://github.com/Maarmapa/storefront-mcp/issues"},"license":"Apache-2.0","homepage":"https://github.com/Maarmapa/storefront-mcp#readme","keywords":["mcp","model-context-protocol","mcp-server","ecommerce","ai-agents","nextjs","woocommerce"],"repository":{"type":"git","url":"git+https://github.com/Maarmapa/storefront-mcp.git"},"description":"MCP server template for e-commerce storefronts: public catalog tools for AI agents, token-gated back-office tools for you. Runs standalone via `npx storefront-mcp` (stdio) or as a Next.js App Router route.","maintainers":[{"name":"maarmapa","email":"mario@boykot.cl"}],"readme":"# storefront-mcp\n\n**An MCP server template for e-commerce storefronts.** AI agents get your\ncatalog; only you get your back office.\n\n*(Español más abajo / Spanish below.)*\n\n---\n\n## Quickstart (30 seconds)\n\n```bash\nnpx storefront-mcp\n```\n\nThat starts an MCP server over **stdio** serving a demo catalog (the bundled\n`memory` adapter) with the 6 public tools. Plug it into Claude Desktop or\nClaude Code by adding this to your MCP config (`claude_desktop_config.json`,\nor `claude mcp add storefront -- npx storefront-mcp`):\n\n```json\n{\n  \"mcpServers\": {\n    \"storefront\": {\n      \"command\": \"npx\",\n      \"args\": [\"storefront-mcp\"]\n    }\n  }\n}\n```\n\nWant the 5 back-office tools too? On stdio there is no HTTP header, so the\ngate is the presence of `MCP_SECRET` in the server process env — whoever\nlaunches the process owns the machine it runs on:\n\n```json\n{\n  \"mcpServers\": {\n    \"storefront\": {\n      \"command\": \"npx\",\n      \"args\": [\"storefront-mcp\"],\n      \"env\": { \"MCP_SECRET\": \"anything-non-empty\" }\n    }\n  }\n}\n```\n\nPrefer curl? `npx storefront-mcp --http 8787` serves the same JSON-RPC\ncontract over plain HTTP on localhost, with the real\n`Authorization: Bearer <MCP_SECRET>` check (same behavior as the Next.js\nroute below):\n\n```bash\nnpx storefront-mcp --http 8787 &\ncurl -s http://127.0.0.1:8787/ -H 'content-type: application/json' \\\n  -d '{\"jsonrpc\":\"2.0\",\"id\":1,\"method\":\"tools/list\"}'\n```\n\nPick the adapter with `CATALOG_ADAPTER` (`memory` by default,\n`woocommerce` for the Store API skeleton). To serve your own catalog, write\nan adapter (see below) — the CLI, the Next.js route and the registry entry\n(`server.json`) all reuse the same tool definitions and privilege boundary.\n\n## What is this\n\nA [Model Context Protocol](https://modelcontextprotocol.io) server, packaged\nas a Next.js App Router route, that exposes an online store to AI agents\n(Claude, custom GPTs, agent frameworks — anything that speaks MCP over\nStreamable HTTP). It ships with **11 tools**:\n\n| Public (no auth) | Sensitive (Bearer token) |\n| --- | --- |\n| `search_products` | `get_stock_bulk` |\n| `get_product` | `get_top_products` |\n| `get_color_card` | `get_recent_orders` |\n| `list_brands` | `get_order_status` |\n| `get_promotions` | `get_sales_summary` |\n| `get_quote` | |\n\nIt is extracted from a production server that runs at a real art-supply store\nin Chile, with everything store-specific removed and replaced by a clean\nadapter interface.\n\n## Why\n\nAI agents are becoming a sales channel. When someone asks their assistant\n\"find me a warm gray alcohol marker in stock near me\", the stores that win\nare the ones the agent can actually *query*: structured search, real\navailability, a quote with a payment link. A public MCP endpoint is how your\nstore shows up in that conversation — on your own domain, with your own data,\nunder your own rules.\n\n## The core design: privilege separation\n\n**An agent may browse the shop window; it never sees the operation.**\n\nEvery tool is either *public* or *sensitive*, and the boundary is enforced\ntwice in the protocol layer (`src/lib/protocol.ts`, shared by the Next.js\nroute and the standalone CLI):\n\n1. **`tools/list`** — without a valid `Authorization: Bearer <MCP_SECRET>`\n   header, only the public tools are returned. Sensitive tools are not merely\n   locked; they are invisible.\n2. **`tools/call`** — a caller who guesses a sensitive tool's name anyway gets\n   JSON-RPC error **`-32001`** before any data code runs.\n\nThe check is **fail-closed**: if the `MCP_SECRET` env var is not set, the\nsensitive tools are blocked for everyone. There is no\n\"nothing-configured-so-everything-is-open\" mode. Token comparison is\nconstant-time.\n\nTransport nuance: over HTTP (the Next.js route and `--http` mode) the gate is\nthe Bearer header, because remote callers are untrusted. Over **stdio**\n(`npx storefront-mcp`) there is no header — the client and server share a\nmachine — so the gate is whether `MCP_SECRET` exists in the server process\nenv. Same boundary, enforced at the trust seam each transport actually has.\n\nThe same split exists at the data layer: the `CatalogAdapter` interface only\nknows public storefront data, and the optional `OpsAdapter` (orders, revenue,\nexact stock) is a separate contract you can simply not implement — in which\ncase sensitive tools return an error even to authenticated callers. Ops\nimplementations must anonymize customer PII: line items carry name/qty/price,\nnever emails, addresses or phone numbers, even behind auth.\n\n## Quickstart as a web endpoint (2 minutes)\n\nTo serve MCP from your own domain (the deployable Next.js route):\n\n```bash\ngit clone <this repo> && cd storefront-mcp\nnpm install\nnpm run dev\n```\n\nThat's it — the default `memory` adapter serves the toy catalog in\n`examples/toy-catalog.json` (a fictional store, \"Demo Art Supply\"). Try it:\n\n```bash\n# descriptor\ncurl http://localhost:3000/api/mcp\n\n# list tools (public only — no token sent)\ncurl -s http://localhost:3000/api/mcp -H 'content-type: application/json' \\\n  -d '{\"jsonrpc\":\"2.0\",\"id\":1,\"method\":\"tools/list\"}'\n\n# search\ncurl -s http://localhost:3000/api/mcp -H 'content-type: application/json' \\\n  -d '{\"jsonrpc\":\"2.0\",\"id\":2,\"method\":\"tools/call\",\"params\":{\"name\":\"search_products\",\"arguments\":{\"query\":\"leather dye\"}}}'\n\n# a sensitive tool without a token → -32001\ncurl -s http://localhost:3000/api/mcp -H 'content-type: application/json' \\\n  -d '{\"jsonrpc\":\"2.0\",\"id\":3,\"method\":\"tools/call\",\"params\":{\"name\":\"get_sales_summary\",\"arguments\":{}}}'\n\n# now with the token\nexport MCP_SECRET=$(openssl rand -hex 32)   # also set it in .env.local and restart\ncurl -s http://localhost:3000/api/mcp -H 'content-type: application/json' \\\n  -H \"authorization: Bearer $MCP_SECRET\" \\\n  -d '{\"jsonrpc\":\"2.0\",\"id\":4,\"method\":\"tools/call\",\"params\":{\"name\":\"get_sales_summary\",\"arguments\":{}}}'\n```\n\nTo connect it to Claude Code: `claude mcp add --transport http my-store\nhttp://localhost:3000/api/mcp`.\n\n## Writing your own adapter\n\nThe protocol layer never touches data directly. It calls two interfaces\ndefined in `src/lib/adapter.ts`:\n\n- **`CatalogAdapter`** — `searchProducts`, `getProduct`, `listBrands`,\n  `getColorCard`, `getPromotions`, `getQuote`. Public by definition: assume\n  every byte it returns is world-readable.\n- **`OpsAdapter`** (optional) — `getStockBulk`, `getTopProducts`,\n  `getRecentOrders`, `getOrderStatus`, `getSalesSummary`.\n\nSteps:\n\n1. Copy `src/lib/adapters/memory.ts` (the reference implementation) to a new\n   file and point it at your database / API / ERP.\n2. Register it in `src/lib/adapters/index.ts` and select it with the\n   `CATALOG_ADAPTER` env var.\n3. Keep the contract's honesty rules: return `stock: null` when you could not\n   verify availability (never invent a number), set a per-call timeout so a\n   hung backend degrades into a note instead of a hung agent, and keep\n   `get_quote` charge-free — it quotes and returns a `payment_link`; the\n   human pays.\n\nA **WooCommerce skeleton** (`src/lib/adapters/woocommerce.ts`) is included,\nbuilt on the public Store API, with TODOs marking what you need to fill in\n(variant charts, quoting strategy). It deliberately implements only the\ncatalog side.\n\n## Discovery: getting found\n\nAgents can only call what they can find. Two artifacts, templates in\n`discovery/`:\n\n- **`/.well-known/mcp.json`** — machine-readable descriptor\n  (`discovery/well-known-mcp.json`; replace `{{DOMAIN}}`, serve from\n  `public/.well-known/mcp.json`). List only public tools in it.\n- **`/llms.txt`** — human/LLM-readable site guide\n  (`discovery/llms-txt-snippet.md`); includes an agent policy section: re-check\n  stock before closing a sale, quotes never charge, `stock: null` means\n  unknown.\n\nAdditionally, `GET /api/mcp` returns a JSON descriptor so anyone poking the\nendpoint understands what it is.\n\nFor the official [MCP Registry](https://registry.modelcontextprotocol.io),\n`server.json` at the repo root is the manifest: it points at the\n`storefront-mcp` npm package with stdio transport, so registry clients can\nrun it via `npx`.\n\n## Serving MCP from your WordPress domain\n\nIf your storefront runs WordPress/WooCommerce but the MCP server deploys\nelsewhere (e.g. Vercel), `wordpress-proxy/mcp-proxy.php` is a **mu-plugin**\nthat serves `https://yourshop.com/api/mcp` by proxying to the upstream:\n\n- hooks `init` at priority 0 (answers before WordPress routing),\n- forwards POST bodies and the `Authorization` header untouched (the upstream\n  enforces the privilege split),\n- handles CORS preflight, answers GET with a readable descriptor,\n- caps payloads at 256 KB,\n- on upstream failure returns a JSON-RPC error object — never an HTML error\n  page, because the client is a program.\n\nInstall: drop the file in `wp-content/mu-plugins/` and define\n`STOREFRONT_MCP_UPSTREAM` in `wp-config.php`.\n\n## Why not just Shopify's MCP?\n\nIf you are on Shopify: Shopify already gives every store a hosted MCP endpoint\nwith a generic `search_catalog`-style tool, and it is good. Use it. This\ntemplate is for the cases it does not cover:\n\n- **You are not on Shopify** — WooCommerce, custom stack, headless, an ERP\n  from 2009 that somehow still works.\n- **Your differentiator is a tool the platform will never generate.** The\n  production server this template comes from sells art supplies: its killer\n  tool is `get_color_card` — the full color chart of a marker line with\n  *live stock per shade*. Any store can say \"we sell these markers\"; only the\n  store that wired its own inventory can say \"shade E00 is in stock right now,\n  shade R29 is not\". That per-variant answer closes sales, and it required\n  domain knowledge no generic platform tool has.\n- **You want the privilege-separated back office** — the same endpoint, with a\n  token, answering \"what were my top sellers this month?\" to *you* while\n  showing agents only the shop window.\n\n## Repository layout\n\n```\nsrc/lib/protocol.ts           protocol core (JSON-RPC, auth boundary, dispatch) — shared by both transports\nsrc/app/api/mcp/route.ts      Next.js transport (Streamable HTTP + Bearer)\nsrc/cli/cli.ts                standalone transport: `npx storefront-mcp` (stdio via the official MCP SDK, or --http)\nsrc/lib/tools.ts              tool definitions + SENSITIVE_TOOLS set\nsrc/lib/adapter.ts            CatalogAdapter / OpsAdapter contracts + types\nsrc/lib/adapters/memory.ts    reference adapter (toy catalog, fake back office)\nsrc/lib/adapters/woocommerce.ts  Store API skeleton with TODOs\nsrc/lib/adapters/index.ts     adapter registry (env CATALOG_ADAPTER)\nexamples/toy-catalog.json     the demo data\nserver.json                   MCP Registry manifest (registry.modelcontextprotocol.io)\ntsconfig.build.json           compiles lib + cli to dist/ for the npm bin\ndiscovery/                    /.well-known/mcp.json + llms.txt templates\nwordpress-proxy/mcp-proxy.php mu-plugin to serve MCP under your WP domain\n```\n\n## License\n\nApache-2.0 — see [LICENSE](LICENSE) and [NOTICE](NOTICE).\n\n---\n\n# storefront-mcp (Español)\n\n**Plantilla de servidor MCP para tiendas online.** Los agentes de IA ven tu\ncatálogo; tu operación la ves solo tú.\n\n## Partir en 30 segundos\n\n```bash\nnpx storefront-mcp\n```\n\nEso levanta un servidor MCP por **stdio** con un catálogo de demostración (el\nadaptador `memory`) y las 6 tools públicas. Para conectarlo a Claude Desktop\no Claude Code, agrega esto a tu configuración MCP (o ejecuta\n`claude mcp add storefront -- npx storefront-mcp`):\n\n```json\n{\n  \"mcpServers\": {\n    \"storefront\": {\n      \"command\": \"npx\",\n      \"args\": [\"storefront-mcp\"]\n    }\n  }\n}\n```\n\n¿Quieres también las 5 tools de trastienda? En stdio no existe el header\nHTTP, así que la llave es la **presencia** de `MCP_SECRET` en el entorno del\nproceso del servidor (quien lanza el proceso es dueño de la máquina donde\ncorre):\n\n```json\n{\n  \"mcpServers\": {\n    \"storefront\": {\n      \"command\": \"npx\",\n      \"args\": [\"storefront-mcp\"],\n      \"env\": { \"MCP_SECRET\": \"cualquier-valor-no-vacio\" }\n    }\n  }\n}\n```\n\n¿Prefieres curl? `npx storefront-mcp --http 8787` sirve el mismo contrato\nJSON-RPC por HTTP en localhost, con el chequeo real de\n`Authorization: Bearer <MCP_SECRET>` (mismo comportamiento que la ruta de\nNext.js). El adaptador se elige con `CATALOG_ADAPTER` (`memory` por defecto,\n`woocommerce` para el esqueleto de la Store API).\n\n## Qué es\n\nUn servidor [MCP](https://modelcontextprotocol.io) empaquetado como ruta de\nNext.js (App Router) que expone una tienda online a agentes de IA (Claude,\nGPTs personalizados, frameworks de agentes — cualquier cliente MCP sobre\nStreamable HTTP). Trae **11 tools**: 6 públicas de catálogo\n(`search_products`, `get_product`, `get_color_card`, `list_brands`,\n`get_promotions`, `get_quote`) y 5 sensibles protegidas por token\n(`get_stock_bulk`, `get_top_products`, `get_recent_orders`,\n`get_order_status`, `get_sales_summary`).\n\nEstá extraído de un servidor en producción de una tienda real de materiales\nde arte en Chile, con todo lo específico de esa tienda removido y reemplazado\npor una interfaz de adaptadores.\n\n## Por qué\n\nLos agentes de IA se están convirtiendo en un canal de venta. Cuando alguien\nle pide a su asistente \"búscame un marcador gris cálido con stock\", ganan las\ntiendas que el agente puede *consultar* de verdad: búsqueda estructurada,\ndisponibilidad real, una cotización con link de pago. Un endpoint MCP público\nes la forma de aparecer en esa conversación — en tu propio dominio, con tus\ndatos y tus reglas.\n\n## El diseño central: separación de privilegios\n\n**Un agente puede mirar la vitrina; nunca ve la operación.**\n\nCada tool es *pública* o *sensible*, y el límite se aplica dos veces en la\ncapa de protocolo:\n\n1. **`tools/list`** — sin un `Authorization: Bearer <MCP_SECRET>` válido,\n   solo se devuelven las tools públicas. Las sensibles no están bloqueadas:\n   son invisibles.\n2. **`tools/call`** — quien adivine el nombre de una tool sensible recibe el\n   error JSON-RPC **`-32001`** antes de que corra cualquier código de datos.\n\nEl chequeo es **fail-closed**: si `MCP_SECRET` no está definido en el\nentorno, las tools sensibles quedan bloqueadas para todos. No existe el modo\n\"no configuré nada, entonces todo queda abierto\". La comparación del token es\nde tiempo constante.\n\nMatiz por transporte: sobre HTTP (la ruta de Next.js y el modo `--http`) la\nllave es el header Bearer, porque quien llama desde afuera no es de\nconfianza. Sobre **stdio** (`npx storefront-mcp`) no hay header — cliente y\nservidor comparten la máquina — así que la llave es que `MCP_SECRET` exista\nen el entorno del proceso. Es el mismo límite, aplicado en la costura de\nconfianza que cada transporte realmente tiene.\n\nLa misma separación existe en la capa de datos: `CatalogAdapter` solo conoce\ndatos públicos de vitrina, y el `OpsAdapter` (órdenes, ventas, stock exacto)\nes un contrato aparte que puedes simplemente no implementar. Las\nimplementaciones de ops deben anonimizar la información de clientes: los\nítems llevan nombre/cantidad/precio, nunca correos, direcciones ni teléfonos,\nincluso detrás de la autenticación.\n\n## Partir como endpoint web (2 minutos)\n\nPara servir MCP desde tu propio dominio (la ruta de Next.js desplegable):\n\n```bash\ngit clone <este repo> && cd storefront-mcp\nnpm install\nnpm run dev\n```\n\nListo: el adaptador `memory` (el default) sirve el catálogo de juguete de\n`examples/toy-catalog.json`, una tienda ficticia. Los mismos `curl` de la\nsección en inglés funcionan tal cual.\n\n## Escribir tu propio adaptador\n\nLa capa de protocolo nunca toca datos directamente: llama a las interfaces de\n`src/lib/adapter.ts` (`CatalogAdapter` y, opcional, `OpsAdapter`). Copia\n`src/lib/adapters/memory.ts` como referencia, apúntalo a tu base de datos o\nAPI, y regístralo en `src/lib/adapters/index.ts`. Reglas de honestidad del\ncontrato: si no pudiste verificar stock, devuelve `stock: null` (nunca\ninventes un número); ponle timeout a cada llamada externa; y `get_quote`\njamás cobra — cotiza y devuelve un `payment_link` para que pague el humano.\n\nSe incluye un esqueleto para **WooCommerce** (Store API) con TODOs marcando\nlo que falta completar.\n\n## Discovery\n\nPlantillas en `discovery/`: `/.well-known/mcp.json` (descriptor legible por\nmáquinas; reemplaza `{{DOMAIN}}` y sírvelo desde `public/.well-known/`) y un\nsnippet para `/llms.txt` con la política para agentes. Además, `GET /api/mcp`\ndevuelve un descriptor JSON.\n\n## MCP bajo tu dominio WordPress\n\nSi tu tienda corre en WordPress/WooCommerce pero el servidor MCP vive en otra\nparte, `wordpress-proxy/mcp-proxy.php` es un mu-plugin que sirve\n`https://tutienda.com/api/mcp` haciendo proxy al upstream: engancha en `init`\ncon prioridad 0, reenvía el header `Authorization` sin tocarlo, maneja el\npreflight CORS, responde GET con un descriptor, limita los payloads a 256 KB\ny ante una falla del upstream responde con un error JSON-RPC, nunca con una\npágina HTML. Se instala copiando el archivo a `wp-content/mu-plugins/` y\ndefiniendo `STOREFRONT_MCP_UPSTREAM` en `wp-config.php`.\n\n## ¿Por qué no usar el MCP de Shopify y ya?\n\nSi estás en Shopify: Shopify le regala a cada tienda un endpoint MCP con un\n`search_catalog` genérico, y funciona bien. Úsalo. Esta plantilla es para lo\nque ese endpoint no cubre: tiendas fuera de Shopify (WooCommerce, stack\npropio, headless), y sobre todo **tools que ninguna plataforma va a generar\npor ti**. El ejemplo real detrás de esta plantilla: `get_color_card`, la\ncarta completa de colores de una línea de marcadores con *stock vivo por\ntono*. Cualquier tienda puede decir \"vendemos estos marcadores\"; solo la que\nconectó su propio inventario puede decir \"el tono E00 está disponible ahora\ny el R29 no\". Esa respuesta por variante cierra ventas, y ninguna tool\ngenérica la tiene.\n\n## Licencia\n\nApache-2.0 — ver [LICENSE](LICENSE) y [NOTICE](NOTICE).\n","readmeFilename":"README.md"}