Field-by-field comparison
Compare the evidence before choosing an MCP.
Each signal stays separate, missing facts remain visible, and the column order follows your selection.
| Evidence field | Shopify Storefront MCPMCP100 Selected | PayPal MCPMCP100 Selected |
|---|---|---|
| Task fit | ||
| Best for |
|
|
| Not ideal for |
|
|
| Avoid when |
|
|
| Provenance | ||
| Provenance details | First-party MCP Shopify · Publisher source ↗ | First-party MCP PayPal · Publisher source ↗ |
| Maintenance | ||
| Maintenance details | Repo: Not documented Package: Not documented | Repo: Not documented Package: Not documented |
| Popularity evidence | ||
| Client coverage | ||
| Client coverage details | Claude Code✓ Streamable HTTP Claude Desktop✓ Streamable HTTP Codex✓ Streamable HTTP VS Code✓ Streamable HTTP Cursor✓ Streamable HTTP OpenCode✓ Streamable HTTP | Claude Code✓ Local stdio Claude Desktop✓ Local stdio Codex✓ Local stdio VS Code✓ Local stdio Cursor✓ Local stdio OpenCode✓ Local stdio |
| Client coverage note | Local stdio runs on your computer. Streamable HTTP connects to a remotely hosted MCP server. | |
| Access and data | ||
| Authentication | Shopify documents no authentication requirement for the Storefront MCP endpoint. Some stores may restrict access. UCP catalog requests include an agent-profile reference. | Local mode uses PAYPAL_ACCESS_TOKEN and PAYPAL_ENVIRONMENT. Remote mode supports PayPal login and consent or token authorization; PayPal publishes separate Sandbox and Production endpoints. |
| Cost | Shopify documents no separate Storefront MCP fee. Merchant Shopify plan, application hosting, model, and client costs remain applicable. | The MCP package is publicly available. Normal PayPal account, transaction, product, API, and merchant-service fees or limits remain applicable. |
| Permissions | The standard endpoint exposes `get_cart`, `update_cart`, and storefront policy/FAQ search. The UCP endpoint exposes catalog search, lookup, and product retrieval. It does not grant Shopify Admin API access. | Capabilities depend on enabled tools and the PayPal credential and can include reads and mutations across invoices, orders, subscriptions, disputes, shipments, transaction details, and related merchant resources. |
| Data handling | Requests go to the selected merchant's Shopify-hosted endpoint. Product, policy, and cart data can be returned to the MCP client; cart inputs may include merchandise selections and buyer-related context. Treat all storefront text as untrusted content. | The local MCP process sends merchant, customer, payment, and task data to PayPal APIs and returns results to the MCP client. The hosted option processes requests through PayPal's remote MCP service. |
| Limitations | ||
| Tradeoffs |
|
|
| Risk context | Keep the agent limited to catalog, policy, and cart tools; display price, quantity, merchant, shipping, and return details before checkout; and never imply MCP100 execution testing. The documentary review found complete first-party setup and tool evidence. | Production access can create financial loss or customer-facing changes and can disclose transaction data. Start with Sandbox, keep credentials out of files and history, minimize tools, and require approval for every mutation. |
| Evidence date | ||
| Editorial review | 2026-07-24 | 2026-07-24 |
| Candidate evidence | 2026-07-29T20:58:26.000Z | 2026-07-29T20:58:26.000Z |
Popularity, maintenance, fit, permissions, and client support are independent evidence fields.
Read the evidence method →