MEGURO Docs
Documentation

Task-oriented technical guidance for practice, evidence, automation, and verification.

Contents
Account and billing

Credentials and connections

Use each credential only for its declared target and rotate it when exposure is possible.

Use this when

Use this when connecting an external tool, CI job, MCP client, or Shopify Admin client.

Before you start

Distinguish the workspace API key from the per-store Admin token. Real credential values must never enter Documentation, receipts, support messages, or logs.

Steps

  • Workspace API key: begins meg_sk_…, is shown once, and scopes an external control client to one workspace. Put it in MEGURO_API_TOKEN.
  • Safe key retries: Console keeps one request identity for a pending create or rotation, including across navigation, and resends that same operation after an interrupted response. A completed retry returns the recorded key metadata without the secret; choose Rotate explicitly to obtain another one. Meguro never creates or rotates another key merely to recover plaintext that was already delivered once.
  • Per-store Admin token: begins meg_pw_…, targets one practice store, and is sent by the agent as X-Shopify-Access-Token.
  • Hosted control plane: OAuth 2.1 remote MCP over stateless Streamable HTTP /mcp, with workspace API keys accepted as Bearer authorization.
  • Before authorization, only docs_read, templates_list, template_get, and plan_validate are callable. Other tools require an authorized principal through OAuth or a workspace API key.
  • Compatibility bridge: clients without remote transport support can use mcp-remote to reach the hosted MCP URL.
  • Separate shopper plane: a practice store’s /api/mcp endpoint models Storefront shopper interactions and does not replace the control plane.

Success looks like

The external control client is limited to its workspace, while the agent under test can reach only the intended practice store.

If it fails

An invalid or revoked workspace key must be replaced in Settings → API keys. Rotate credentials after possible exposure and update every intended client; never paste Cognito tokens, browser cookies, or browser storage into a terminal.

Next action

Open Settings → API keys to manage workspace keys, or Connection settings to manage hosted MCP authorizations.