Commerce MCP
Getting started
The path from a developer account to production, step by step. Most of it is self-serve; production access is reviewed by Aiptimise.
The path#
- 1
Create a developer account
Sign up at developers.aiptimise.com/signup with your name, work email and a password of at least 10 characters. We email a verification link that expires after 24 hours. You cannot log in until the email is verified; the link takes you to log in and then to the application form.
- 2
Apply
The application asks for your agent or product name, company, website, platform (for example a ChatGPT app or an API agent), expected requests per day, a technical contact email and how shoppers will use it. You accept the data-use terms (version 2026-09-26) with the form. Your account becomes the owner of a new consumer: the record Aiptimise uses for your platform's access, keys and limits. One application per account.
- 3
Get your sandbox key
Aiptimise sets the sandbox approval rule: automatic for everyone, automatic for verified emails on your website's domain, or manual review. When you are approved at submission, the console shows your first key, named “Sandbox key”, once. Copy it then: only its hash is stored and it cannot be shown again. If your application goes to manual review, the console Overview shows it as under review; once it is approved, issue a key on the Keys page.
The sandbox reads the demo store only. New sandbox consumers get the scopes
catalog:read,offers:read,promotions:read,loyalty:read(notinventory:read), 60 requests per minute and up to 2 keys. Your console Overview shows the values that apply to you. - 4
Try the playground
Portal → Playground runs any tool as your consumer, through the same pipeline as an API call, without a key. It has its own limit of 30 calls per minute. Owners, developers and reviewers can use it.
- 5
Make your first call
Send your key as a bearer token to
https://app.aiptimise.com/api/mcp. List the tools your scopes allow, then call one against the demo store:curl https://app.aiptimise.com/api/mcp \ -H "Authorization: Bearer $AIPTIMISE_MCP_KEY" \ -H "content-type: application/json" \ -H "accept: application/json, text/event-stream" \ -d '{"jsonrpc":"2.0","id":2,"method":"tools/list"}'curl https://app.aiptimise.com/api/mcp \ -H "Authorization: Bearer $AIPTIMISE_MCP_KEY" \ -H "content-type: application/json" \ -H "accept: application/json, text/event-stream" \ -d '{"jsonrpc":"2.0","id":3,"method":"tools/call","params":{"name":"get_store_info","arguments":{"store_id":"edab46c9-76c6-4eb5-92dd-f593ed4bd9ad"}}}'Calling the server has the full transport rules and setup for the Anthropic and OpenAI APIs.
- 6
Request production
When your integration works against the demo store, an owner clicks “Request production access” on the console Overview. The request goes to the Aiptimise review queue with your application and your sandbox usage.
- 7
Aiptimise reviews
Aiptimise either approves or declines.
- Approve: your consumer moves to the production tier with a coverage mode, the scopes and the rate limits Aiptimise sets for you, and, for directory apps, optionally a directory endpoint.
- Decline the request: the sandbox keeps working and you can request again later.
- Reject the application: access is revoked.
The console Overview shows the decision and any reason given.
- 8
Go live
Your existing keys keep working and are now served your production coverage. The Coverage page lists the stores you can read. Aiptimise assigns your
utm_source, which everyproduct_urlthen carries.
What each tier can read#
| Tier | Stores | Scopes and limits |
|---|---|---|
| Sandbox | The demo store only. | The sandbox defaults above, unless Aiptimise changed them for you. |
| Production | Every store whose merchant has AI Discovery on and has not blocked you. With default_on coverage that is every such store; with explicit coverage, only stores that granted you access. The demo store stays readable. | Set by Aiptimise when approving: for example whether you get exact inventory (inventory:read). |
What merchants see when you reach production#
When your consumer goes live in production, each merchant whose store you can read gets a notification in Aiptimise (and in the email digest), once per store. It links to Settings → AI Agents, where the merchant can block your platform. A blocked store stops being served to you on the next request.
Keys and team#
- Only owners issue, rotate and revoke keys, on the Keys page. A key can be narrowed to fewer scopes and given an expiry.
- Rotate issues a replacement with the same name, scopes and expiry. The old key keeps working until you revoke it, so you can deploy the new one first. For a leaked key, tick “Revoke the old key now” when rotating.
- Revoke takes effect on the next request, which gets HTTP 401
invalid_token. - Rate limits count per consumer across all keys: more keys never mean more throughput.
- When the data-use terms change, new keys and rotations are blocked until an owner accepts the new version on the Overview. Existing keys keep working.
- Ask Aiptimise to add teammates as developers (playground, no keys) or reviewers (read-only, access for at most 90 days at a time).