Credentials and connections
Use each credential only for its declared target and rotate it when exposure is possible.
Use this when
Use this when connecting an external tool, CI job, MCP client, or Shopify Admin client.Before you start
Distinguish the workspace API key from the per-store Admin token. Real credential values must never enter Documentation, receipts, support messages, or logs.Steps
- Workspace API key: begins
meg_sk_…, is shown once, and scopes an external control client to one workspace. Put it inMEGURO_API_TOKEN. - Safe key retries: Console keeps one request identity for a pending create or rotation, including across navigation, and resends that same operation after an interrupted response. A completed retry returns the recorded key metadata without the secret; choose Rotate explicitly to obtain another one. Meguro never creates or rotates another key merely to recover plaintext that was already delivered once.
- Per-store Admin token: begins
meg_pw_…, targets one practice store, and is sent by the agent asX-Shopify-Access-Token. - Hosted control plane: OAuth 2.1 remote MCP over stateless Streamable HTTP
/mcp, with workspace API keys accepted as Bearer authorization. - Before authorization, only
docs_read,templates_list,template_get, andplan_validateare callable. Other tools require an authorized principal through OAuth or a workspace API key. - Compatibility bridge: clients without remote transport support can use
mcp-remoteto reach the hosted MCP URL. - Separate shopper plane: a practice store’s
/api/mcpendpoint models Storefront shopper interactions and does not replace the control plane.