Connect Cursor, Claude Code, VS Code
Clients with no OAuth of their own read a config file and send a bearer token. That covers Cursor, Claude Code, VS Code, Windsurf, and anything else that speaks streamable HTTP MCP.
Generate an API key
In your Shopify admin, open Apps → Click Context, go to the setup tab, and press Generate API key.
The key is shown once and stored only as a hash. Copy it now. If you lose it, generate a new one — which invalidates the old one.
Treat it like a password
The key grants read access to your store's behavioural data and lets the holder create and delete custom event rules. Keep it out of a repository. Most clients let you reference an environment variable rather than inlining the value.
Add the server to your MCP config
Paste this into your client's MCP configuration, replacing
YOUR_API_KEY:{ "mcpServers": { "click-context": { "type": "http", "url": "https://app.clickcontext.com/api/mcp/mcp", "headers": { "Authorization": "Bearer YOUR_API_KEY" } } } }Configuration lives in different places per client:
- Cursor
.cursor/mcp.jsonin the project, or~/.cursor/mcp.jsonfor every project.- Claude Code
- Run
claude mcp add, or edit.mcp.jsonin the project root. - VS Code
.vscode/mcp.json, or the MCP section of your user settings.- Windsurf
~/.codeium/windsurf/mcp_config.json.
New to MCP servers in Claude Code? The Claude Code MCP setup guide walks through adding one, with this store connection as the worked example.
Restart the client and check the tool list
Most clients read the config at start-up. After restarting you should see the Click Context tools listed. If the count is 37, the handshake and the key both worked.
The endpoint
- URL
https://app.clickcontext.com/api/mcp/mcp- Transport
- Streamable HTTP
- Auth
- HTTP header
Authorization: Bearer <key> - Identity
- Resolved from the key. You never pass a store id.
Do not use the Claude URL here
/api/mcp/sse exists for Claude's connector UI, which negotiates the transport itself. A config-file client takes the URL literally and will hang waiting on an SSE stream this deployment does not serve.
Rotating and revoking
Generating a new key immediately invalidates the previous one. There is one key per store, so rotating it disconnects every client using the old value — update them all in the same sitting.
Uninstalling the app ends access entirely, regardless of any key still sitting in a config file.
More than one store
A config file keys each server by name, so add one entry per store with that store's own key — no URL trick needed. Agencies connecting the same stores to Claude's connector UI do need one, and Connect multiple stores explains why.
If your client does support OAuth
Prefer it. OAuth tokens are scoped to a connection and can be revoked without disturbing anything else. See Connect Claude for the flow — any client implementing the same discovery will work the same way.