MCP server for managing Shopware 6 e-commerce platform via Admin API, providing tools for products, orders, categories, sales channels, themes, and media
The Shopware Admin MCP has 20 tools with generally clear naming conventions and adequate descriptions. Most tools follow verb_noun patterns (fetch_, list_, create_, update_, delete_). All visible tools have input schemas defined with Zod. However, there are significant gaps: many parameters lack detailed descriptions (e.g., constraints, formats, ranges), output schemas are not documented anywhere in the codebase, and error handling is minimal. The serializeLLM utility suggests responses are JSON-stringified without shape validation. Parameter descriptions exist but are often minimal (e.g., 'Product ID' for 'id' param lacks context about format). No enum constraints visible for multi-value parameters like product visibility or order status, they accept arrays of strings without format guidance. Tools like `upload_media_by_url` and `theme_config_change` have color parameters without hex format validation hints in descriptions. The server lacks recovery guidance in error cases and has no explicit permission gates or audit trail patterns.
Creates one or more new product categories with optional parent category relationships
Deletes one or more categories by their IDs
Retrieves a paginated list of all categories with their hierarchy information and SEO URLs
Updates one or more existing categories with new name, parent, or active status
Retrieves a paginated list of countries with optional search term filtering
Performs data aggregation on entity fields using count, max, min, stats, terms, or histogram aggregation types with optional filtering
Output schemas are undocumented. serializeLLM() returns free-form JSON strings without shape validation, type documentation, or field contracts. Downstream agent calls cannot reliably extract structured data (e.g., product IDs, order totals) from responses.
No pagination parameter documentation. category_list and product_list hard-code limit=50 and page defaults without exposing limits to the agent. Large result sets may truncate silently, and agents cannot request higher page numbers if results exceed 50 items.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-22 | C | 65 | 2026-07-28+ | v2 |
| 2026-03-09 | F | 43 | - | v1 |
Retrieves a list of all available entity types from the Shopware Admin API
Fetches the schema for a single entity type, e.g. product, order, category, etc.
Retrieves complete details for a single order including customer info, addresses, line items, and payment/delivery status
Retrieves a paginated list of orders with optional search and status filtering
Updates an order's status, billing address, or shipping address
Creates a new product with pricing, tax, stock, visibility, categories, and media
Retrieves detailed information for a single product by ID
Retrieves a paginated list of products with search term filtering
Updates an existing product's attributes including name, description, stock, visibility, categories, and media
Retrieves all active sales channels with their domains, configuration, and assigned themes
Updates a sales channel's active status or maintenance mode
Updates theme configuration for a sales channel including brand colors, background color, and logo
Retrieves the theme configuration values for a specific sales channel
Uploads media to Shopware from an external URL and associates it with the product media folder
Color parameters (brandPrimaryColor, brandSecondaryColor, brandBackgroundColor) lack format constraints in descriptions. Should explicitly state 'hex format, e.g. #7a9ccd' in parameter description; currently only in default value comment.
Error handling is minimal. Tools catch exceptions and return errors as JSON strings (line: `text: \`Error creating categories: ${serializeLLM(e)}\```) without categorization (retryable vs. fatal), actionable guidance, or recovery hints. LLM cannot infer next action from raw error.
No tool annotations (readOnlyHint, destructiveHint, idempotentHint). Destructive operations (category_delete, product operations, order updates) lack explicit destructive hints; read-only tools lack readOnlyHint.
Parameter descriptions are minimal and lack constraints. Example: 'Product name' (product_create) does not specify length limits, required format, or charset. 'Stock quantity' lacks min/max bounds. 'Tax rate percentage' does not specify decimal places or valid range (0 - 100? 0 - 50?).
No permission gates or scope declarations. Tools like category_delete and product_create do not verify agent authority. No audit trails or scope hints (e.g. 'requires: admin:write').
Some parameter descriptions reference external tools without being explicit. Example: 'use fetch_entity_schema to get a list of available fields' (dal_aggregate) assumes agent knows to call that first; should state this as a dependency hint in the description.
No confirmation pattern for destructive operations. category_delete immediately removes items without dry-run or confirmation step. Multi-item deletions (ids array) lack per-item success/failure reporting.
upload_media_by_url accepts arbitrary URLs without validation hints. Should specify: supported protocols (https only?), max file size, allowed content types, and timeout behavior.