MCP Integration
This server exposes custom order-status data to AI assistants over the Model Context Protocol. Create a token in the application, then connect a client below.
Connection URL
https://mcp-custom-order-status-dev.cblyst.com/mcp
Tools (8)
| Name | Purpose | Permission | Safety |
|---|---|---|---|
cos_help_get |
Get tool details | none | read |
cos_help_search |
Search available tools | none | read |
cos_line_item_status_get |
Get per-line-item statuses | cos:lineitems:read |
read |
cos_line_item_status_set |
Set per-line-item status | cos:lineitems:write |
write |
cos_order_history_list |
List an order's status history | cos:orders:read |
read |
cos_order_status_get |
Get an order's custom status | cos:orders:read |
read |
cos_order_status_set |
Set an order's custom status | cos:orders:write |
destructive |
cos_status_list |
List order-status definitions | cos:status:read |
read |
Permissions
| Scope | Allows | |
|---|---|---|
cos:status:read |
Read your custom order-status definitions — their names, colours and display order. | safe |
cos:orders:read |
Read your orders' current custom status and their status-change history. | safe |
cos:lineitems:read |
Read per-line-item statuses and quantity allocations for your orders. | safe |
cos:lineitems:write |
Move units of a line item between statuses. Does not email your customers and does not change the order's overall status. | safe |
cos:orders:write |
Change an order's custom status. This writes Shopify order tags, can email your customer, and can trigger your Shopify Flow automations. | destructive |
Endpoints
| Path | Purpose |
|---|---|
/mcp | MCP endpoint (Streamable HTTP) |
/health | Liveness and readiness |
/.well-known/oauth-protected-resource | OAuth protected-resource metadata (RFC 9728) |
/.well-known/oauth-authorization-server | OAuth authorization-server metadata (RFC 8414) |
/oauth/register | Dynamic client registration (RFC 7591) |
/oauth/token | Token exchange and refresh |
/oauth/revoke | Token revocation (RFC 7009) |
/authorize | Consent screen |
/connect | Setup instructions |
Authentication
Bearer tokens (prefix cos_, shown once at
creation, 90-day default lifetime) or OAuth 2.1 with
PKCE for connector-based clients. Revoking a token immediately disconnects everything
derived from it.
Client setup
Claude (web & desktop)
Settings → Connectors → Add custom connector URL: https://mcp-custom-order-status-dev.cblyst.com/mcp
Uses the OAuth flow: you will be sent to a consent screen to paste your token and choose permissions.
Claude Code
claude mcp add --transport http order-status https://mcp-custom-order-status-dev.cblyst.com/mcp \ --header "Authorization: Bearer YOUR_TOKEN"
Adds the server to the current project.
Cursor
Config file: ~/.cursor/mcp.json
{
"mcpServers": {
"order-status": {
"url": "https://mcp-custom-order-status-dev.cblyst.com/mcp",
"headers": {
"Authorization": "Bearer YOUR_TOKEN"
}
}
}
}
Restart Cursor after saving.
VS Code (Copilot)
Config file: .vscode/mcp.json
{
"servers": {
"order-status": {
"type": "http",
"url": "https://mcp-custom-order-status-dev.cblyst.com/mcp",
"headers": {
"Authorization": "Bearer YOUR_TOKEN"
}
}
}
}
Workspace-scoped; commit it only if the token is not inline.
Windsurf / Antigravity
Config file: ~/.codeium/windsurf/mcp_config.json
{
"mcpServers": {
"order-status": {
"url": "https://mcp-custom-order-status-dev.cblyst.com/mcp",
"headers": {
"Authorization": "Bearer YOUR_TOKEN"
}
}
}
}
Same shape as Cursor.
ChatGPT
Settings → Connectors → Add URL: https://mcp-custom-order-status-dev.cblyst.com/mcp
Requires a publicly reachable HTTPS URL.
Verify a deployment
| Check | Command | Expect |
|---|---|---|
| Health | curl -s https://mcp-custom-order-status-dev.cblyst.com/health |
200 with {"status":"ok"} — 503 means the database is unreachable |
| Auth challenge | curl -si https://mcp-custom-order-status-dev.cblyst.com/mcp | head -5 |
401 with a WWW-Authenticate header — without it, connectors fail blank |
| Discovery | curl -s https://mcp-custom-order-status-dev.cblyst.com/.well-known/oauth-protected-resource |
JSON naming this server as the protected resource |