MMecsto developers

Docs AI & MCP

AI & MCP

Mecsto ships Model Context Protocol servers so an AI agent can read and operate a real store — under the merchant’s own sign-in, with the same permissions the merchant has, and never more.

Two servers

The shape of it

An agent signs the merchant in with a one-time code sent to their email — the same OTP flow the Mecsto apps use. Every subsequent call runs as that merchant, under the platform’s normal row-level security. There is no service key, no admin token and no back door.

Reads are open, writes are not. Everything readable is available the moment the merchant signs in. Anything that changes a live store is refused until the merchant switches on an explicit consent gate. Money operations are not exposed at any setting.

Start here