Field-by-field comparison
Compare the evidence before choosing an MCP.
Each signal stays separate, missing facts remain visible, and the column order follows your selection.
| Evidence field | PayPal MCPMCP100 Selected | Shopify Storefront MCPMCP100 Selected |
|---|---|---|
| Task fit | ||
| Best for |
|
|
| Not ideal for |
|
|
| Avoid when |
|
|
| Provenance | ||
| Provenance details | First-party MCP PayPal · Publisher source ↗ | First-party MCP Shopify · Publisher source ↗ |
| Maintenance | ||
| Maintenance details | Repo: Not documented Package: Not documented | Repo: Not documented Package: Not documented |
| Popularity evidence | ||
| Client coverage | ||
| Client coverage details | Claude Code✓ Local stdio Claude Desktop✓ Local stdio Codex✓ Local stdio VS Code✓ Local stdio Cursor✓ Local stdio OpenCode✓ Local stdio | Claude Code✓ Streamable HTTP Claude Desktop✓ Streamable HTTP Codex✓ Streamable HTTP VS Code✓ Streamable HTTP Cursor✓ Streamable HTTP OpenCode✓ Streamable HTTP |
| Client coverage note | Local stdio runs on your computer. Streamable HTTP connects to a remotely hosted MCP server. | |
| Access and data | ||
| Authentication | Local mode uses PAYPAL_ACCESS_TOKEN and PAYPAL_ENVIRONMENT. Remote mode supports PayPal login and consent or token authorization; PayPal publishes separate Sandbox and Production endpoints. | Shopify documents no authentication requirement for the Storefront MCP endpoint. Some stores may restrict access. UCP catalog requests include an agent-profile reference. |
| Cost | The MCP package is publicly available. Normal PayPal account, transaction, product, API, and merchant-service fees or limits remain applicable. | Shopify documents no separate Storefront MCP fee. Merchant Shopify plan, application hosting, model, and client costs remain applicable. |
| Permissions | Capabilities depend on enabled tools and the PayPal credential and can include reads and mutations across invoices, orders, subscriptions, disputes, shipments, transaction details, and related merchant resources. | The standard endpoint exposes `get_cart`, `update_cart`, and storefront policy/FAQ search. The UCP endpoint exposes catalog search, lookup, and product retrieval. It does not grant Shopify Admin API access. |
| Data handling | The local MCP process sends merchant, customer, payment, and task data to PayPal APIs and returns results to the MCP client. The hosted option processes requests through PayPal's remote MCP service. | Requests go to the selected merchant's Shopify-hosted endpoint. Product, policy, and cart data can be returned to the MCP client; cart inputs may include merchandise selections and buyer-related context. Treat all storefront text as untrusted content. |
| Limitations | ||
| Tradeoffs |
|
|
| Risk context | Production access can create financial loss or customer-facing changes and can disclose transaction data. Start with Sandbox, keep credentials out of files and history, minimize tools, and require approval for every mutation. | Keep the agent limited to catalog, policy, and cart tools; display price, quantity, merchant, shipping, and return details before checkout; and never imply MCP100 execution testing. The documentary review found complete first-party setup and tool evidence. |
| Evidence date | ||
| Editorial review | 2026-07-24 | 2026-07-24 |
| Candidate evidence | 2026-07-29T20:58:26.000Z | 2026-07-29T20:58:26.000Z |
Popularity, maintenance, fit, permissions, and client support are independent evidence fields.
Read the evidence method →