Authentication
The MCP server is:Protected resource metadata
MCP clients can discover StoreInspect’s protected-resource metadata from the MCP origin:Resource-bound tokens
Access tokens are issued for the MCP resource:Scopes and permissions
StoreInspect MCP uses narrow scopes:
MCP connections authorized before July 20, 2026 might not include the billing scopes. Existing Store/contact tools continue to work. Reconnect the client only if it reports
insufficient_scope when using a billing tool.
The MCP server also checks the current StoreInspect plan and credit state at request time. Billing tools can be used on Free or inactive plans, while every store and contact tool still requires active paid access. Plan changes, disabled access, or exhausted credits are not trusted from stale token claims.
Billing tools never mutate subscriptions directly. They return an authenticated, short-lived Stripe-hosted URL that a human must open and confirm. StoreInspect does not accept arbitrary Price IDs or return URLs from MCP clients.
Revocation
Manage connected MCP clients from the StoreInspect dashboard:Contact credit controls
Thereveal_contacts tool can spend contact credits only when the tool input includes:
Logging
StoreInspect logs MCP usage for account visibility, support, abuse monitoring, and quota enforcement. Logs may include:- Request ID
- User/account ID
- OAuth client ID
- MCP tool name
- Status and error code
- Rows returned
- Credits spent
- Latency
Troubleshooting
For setup, OAuth, permission, quota, and reveal-confirmation issues, see MCP troubleshooting.Recommended usage
- Review high-impact actions before confirming them in your AI client.
- Revoke clients you no longer use.
- Ask agents to preview contacts before revealing contact channels.