Vendune

Guide / Model Context Protocol

Connect Claude Desktop to a commerce MCP server.

Use a local stdio bridge to connect a compatible MCP client to the same Rust commerce operations used by the storefront.

Start the Rust app first

Complete the commerce quickstart. The bridge forwards requests to a running server; it does not start the application. No model download is needed to expose public product and cart tools.

Add the MCP server configuration

Add this entry to your client's MCP configuration. Replace the checkout path with your actual absolute path and preserve any existing server entries.

{
  "mcpServers": {
    "vendune": {
      "command": "python3",
      "args": ["/absolute/path/vendune/scripts/mcp_stdio.py"],
      "env": {
        "COMMERCE_URL": "http://127.0.0.1:8787",
        "COMMERCE_TENANT": "atelier"
      }
    }
  }
}

This is the public/customer configuration. Ask the client to list the available commerce tools and inspect products in the demo shop. Tool availability depends on authorization; do not assume the public configuration permits merchant mutations.

Use personal authority for merchant operations

For ordinary merchant access, set COMMERCE_SESSION_TOKEN privately to the opaque session of a signed-in personal user, and COMMERCE_TENANT to one of that user's shop memberships. Personal sessions expire after 12 hours. The bridge prioritizes the personal session over the legacy global credential.

Keep tokens out of committed configuration and logs. Reader accounts may plan but cannot apply changes. Workspace selection cannot grant membership.

Inspect before applying

merchant.plan → inspect the stored preview → merchant.apply
                                               explicit approval

AI planning requires its chosen model service. The stored proposal carries the actual change fields and revisions; the model's summary alone is not an execution guarantee. Server-side role, tenant and revision checks also apply to direct MCP invocation.

What about hosted ChatGPT or Claude?

Hosted clients cannot reach your localhost. They need a secure reachable endpoint and account-side configuration. This prototype exposes a partial stateless JSON-response subset of Streamable HTTP; it does not provide full protocol conformance or a production OAuth server.

Local bridge support is separate from a verified hosted-account integration. The project has not configured a ChatGPT or Claude account for you.

Use the full connection guide for provider configuration, remote connector requirements and verification boundaries.