Vendune
docs/connectors.mdView on GitHub ↗

OpenAI, Claude and external chat clients

There are two distinct connections. Both use the same commerce capabilities.

Models inside the merchant chat

Operators can configure encrypted global provider settings and shop overrides in Vendune Platform → AI providers; ordinary shops inherit that selection. Configured flags are not provider-health checks. See provider inheritance.

For a local environment-based setup, set credentials in the private, ignored .env, then restart the server:

OPENAI_API_KEY=your-api-key
OPENAI_MODEL=gpt-6-sol
ANTHROPIC_API_KEY=your-api-key
ANTHROPIC_MODEL=claude-sonnet-5-5

In /#merchant, sign in with a personal member account and open the assistant model settings. Choose Local, OpenAI, or Claude. You can override the model ID per turn. The server uses OpenAI Responses with structured outputs, or Anthropic Messages with output_config.format. No subscription cookies, ChatGPT browser automation, or Claude subscription tokens are used. These APIs require separate provider credentials/access and may incur charges. The database and local-model route do not require a paid service.

Credentials are never returned to the frontend or stored in conversations. Cloud selection sends the bounded catalog, graph context and conversation history to that provider. No silent provider fallback occurs. Failures are stored as explicit error messages; they never create an executable proposal. The server validates IDs, ranges and trusted revisions for every provider.

Official references: OpenAI structured outputs, Claude structured outputs.

Claude Desktop / local MCP clients

The Python bridge forwards real JSON-RPC requests over stdio to the running Rust MCP endpoint. Add this entry to your client's MCP configuration, replacing the absolute checkout path. Preserve existing entries in your config.

{
  "mcpServers": {
    "vendune": {
      "command": "python3",
      "args": ["/absolute/path/vendune/scripts/mcp_stdio.py"],
      "env": {
        "COMMERCE_URL": "http://127.0.0.1:8787",
        "COMMERCE_TENANT": "atelier"
      }
    }
  }
}

This configuration exposes the customer/read tools. For merchant planning and approval, set COMMERCE_SESSION_TOKEN privately to a personal member session and COMMERCE_TENANT to its shop. A scoped integration key is another option through the same authenticated server path. Do not commit a filled credential/config. The tool sequence is merchant.plan → inspect the stored preview → merchant.apply with explicit approval. knowledge.graph and knowledge.search expose the actual graph and retrieval route. The bridge is transport, not another commerce implementation.

ChatGPT / Claude remote connectors

The Rust endpoint is /mcp, a stateless JSON-response subset of Streamable HTTP. GET returns 405 because this prototype offers no SSE subscription. Localhost is not directly reachable by ChatGPT or Claude's hosted services. Use a supported secure tunnel or a deployed HTTPS endpoint for remote access. Keep the local demo bound to loopback until its production identity layer exists.

For an authorized OpenAI API client, the remote MCP tool configuration is:

{
  "type": "mcp",
  "server_label": "commerce",
  "server_url": "https://your-commerce-host.example/mcp",
  "authorization": "Bearer YOUR_PRIVATE_MERCHANT_TOKEN",
  "require_approval": "always"
}

For ChatGPT's UI, an authorized account/workspace owner must add the custom MCP app in Developer Mode. Account availability and authentication requirements depend on the product/plan. This repository does not register an app in your ChatGPT/Claude account or implement a full OAuth authorization server. For a remote UI connector that requires OAuth, an OAuth gateway is still needed; a personal session or integration key is not a replacement for that OAuth gateway.

ChatGPT developer-mode setup and secure-tunnel guidance and OpenAI remote MCP API.

Verification boundary

scripts/providers.py exercises both adapters against local HTTP contract servers and verifies the real merchant conversation and approval routes. Those tests do not prove live OpenAI/Anthropic inference. Real local Ollama inference is tested separately. Live cloud checks require your own API keys; no borrowed credentials or fabricated cloud results are included.

Personal workspace credentials (v0.4)

For normal merchant MCP access, set COMMERCE_SESSION_TOKEN to that user's opaque login session and COMMERCE_TENANT to one of their memberships. The bridge uses this token preferentially. Knowledge and merchant tools check scoped authority on the server; readers cannot apply proposals. Sessions expire after 12 hours and must be renewed through personal login. Never distribute the legacy global MERCHANT_TOKEN to SaaS merchants. Public product/cart tools work without merchant credentials; complete graph/vector tools do not. The generated local configuration intentionally contains no embedded credentials.