Skip to main content

Your AI assistant

cope-mcp is an MCP server you run on your own computer. It lets your AI assistant read your COPE store through the public API, using your API key. You can then ask things like “what did we sell last week?”, “did the refund for this order go through?” or “which webhook deliveries failed today?”. It only reads unless you turn changes on. With changes on, it can refund a payment, change a subscription, create, send or cancel an offer, and create or change a product, and it asks you to confirm each change before anything happens. See Making changes.

Set it up

  1. In the COPE dashboard, create an API key under Settings → API Keys and choose Read only. See API key integrations.
  2. Add the server to your MCP client. For Claude Desktop, add this to claude_desktop_config.json:
Pin the version, as in @0.1.0 above, so an update never runs unless you choose it. The server needs Node.js 20 or later.

Tools

Lists return at most 25 items per page, and each result says how many pages there are.

Making changes

Changes are off by default. To turn them on, set COPE_MCP_WRITES to on and use a full-access key; a read-only key refuses every change. Every change asks you first. Your MCP client shows exactly what will happen, for example “Refund 12.50 EUR of payment pay_… to j***@example.com (50.00 EUR is still refundable)?”. Nothing changes unless you tick the box and accept. If what the question shows changed while you were deciding, you are asked again. If your client cannot show such a question, changes are refused. A network problem does not make a change twice. Each change carries a key derived from what you confirmed and the current state, and COPE applies one key once. If the answer is lost, your assistant is told the change may or may not have been made and should look before asking again. If it was made, the next question shows the new state, so a second refund is always a new question you answer yourself.

Buyer data

Everything the server returns passes through your assistant’s AI provider. By default, buyers’ names, email addresses, phone numbers, VAT IDs, company names, addresses and card digits are masked, for example j***@example.com and J. D.. Set COPE_MCP_PII=full only if your agreement with that provider covers your buyers’ personal data.

Questions about COPE itself

This server reads your store. For questions about how COPE works, also add the docs search MCP server at https://docs.cope.com/mcp, which needs no key. See AI shopping agents.

Security

  • Use a read-only key unless you turned changes on. It reads what you can and changes nothing, so a leaked key cannot write. Keep the key out of shared configuration files. If it leaks, or you stop using the server, deactivate or delete it in the dashboard; it stops working within 60 seconds.
  • The key is sent only to COPE’s API and never appears in tool results or error messages.
  • Results contain text your buyers and team wrote, such as product descriptions and names. The server labels every result as data, not instructions. Still, review what your assistant proposes before you act on it.