Field-by-field comparison
Compare the evidence before choosing an MCP.
Each signal stays separate, missing facts remain visible, and the column order follows your selection.
| Evidence field | Shopify Storefront MCPMCP100 Selected | Firecrawl MCPMCP100 Selected |
|---|---|---|
| Task fit | ||
| Best for |
|
|
| Not ideal for |
|
|
| Avoid when |
|
|
| Provenance | ||
| Provenance details | First-party MCP Shopify · Publisher source ↗ | First-party MCP Firecrawl · Publisher source ↗ |
| Maintenance | ||
| Maintenance details | Repo: Not documented Package: Not documented | Repo: Aug 12, 2026 Package: Aug 12, 2026 |
| Popularity evidence | ||
| GitHub stars | Not documented | 7,234 GitHub stars · checked 2026-08-14T18:46:26.000Z |
| 30-day package downloads | No reliable download data | 412,488 30-day package downloads · checked 2026-08-14T18:46:26.000Z |
| External adoption evidence | Not documented |
|
| Client coverage | ||
| Client coverage details | Claude Code✓ Streamable HTTP Claude Desktop✓ Streamable HTTP Codex✓ Streamable HTTP VS Code✓ Streamable HTTP Cursor✓ Streamable HTTP OpenCode✓ Streamable HTTP | Claude Code✓ Local stdio Claude Desktop✓ Local stdio Codex✓ Local stdio VS Code✓ Local stdio Cursor✓ Local stdio OpenCode✓ Local stdio |
| Client coverage note | Local stdio runs on your computer. Streamable HTTP connects to a remotely hosted MCP server. | |
| Access and data | ||
| Authentication | Shopify documents no authentication requirement for the Storefront MCP endpoint. Some stores may restrict access. UCP catalog requests include an agent-profile reference. | Cloud and local-package configurations use FIRECRAWL_API_KEY. Official docs also show hosted MCP URLs containing the key; environment-variable or protected input handling is safer than embedding the key in a URL. |
| Cost | Shopify documents no separate Storefront MCP fee. Merchant Shopify plan, application hosting, model, and client costs remain applicable. | MCP calls consume the account's standard Firecrawl API credits and rate limits. Search, crawl, batch, and agent operations can consume more resources than single-page scraping; current plan pricing applies. |
| Permissions | The standard endpoint exposes `get_cart`, `update_cart`, and storefront policy/FAQ search. The UCP endpoint exposes catalog search, lookup, and product retrieval. It does not grant Shopify Admin API access. | The MCP can initiate outbound requests to user- or model-selected URLs and invoke Firecrawl scrape, search, crawl, map, extraction, batch, and research capabilities according to enabled tools and account limits. |
| Data handling | Requests go to the selected merchant's Shopify-hosted endpoint. Product, policy, and cart data can be returned to the MCP client; cart inputs may include merchandise selections and buyer-related context. Treat all storefront text as untrusted content. | URLs, queries, extraction schemas, and retrieved page content are processed by the configured Firecrawl service. Cloud mode sends them to Firecrawl; self-hosted mode follows the operator's deployment and any configured model/provider dependencies. |
| Limitations | ||
| Tradeoffs |
|
|
| Risk context | Keep the agent limited to catalog, policy, and cart tools; display price, quantity, merchant, shipping, and return details before checkout; and never imply MCP100 execution testing. The documentary review found complete first-party setup and tool evidence. | Main risks are prompt injection from untrusted pages, collection-policy violations, sensitive URL/query disclosure, API-key leakage, and agent-driven credit spend. Use URL allow-lists, low limits, human approval, and a dedicated low-budget key. |
| Evidence date | ||
| Editorial review | 2026-07-24 | 2026-07-24 |
| Candidate evidence | 2026-07-29T20:58:26.000Z | 2026-08-14T18:46:26.000Z |
Popularity, maintenance, fit, permissions, and client support are independent evidence fields.
Read the evidence method →