Short answer. An MCP server lets a compatible AI client call your Magento store through defined tools. We group Magento MCP projects into three practical types. Storefront servers let shopping agents search your catalog. Admin servers let authorized users work with store data from MCP-capable clients such as Claude, ChatGPT or Cursor. Developer servers help coding agents work on Magento code. Client support, plan availability and transport requirements differ, so choose the type first, then check your client.
What is a Magento MCP server?
MCP (Model Context Protocol) is an open standard, first released by Anthropic. It lets an AI client call tools on another system. For Magento, a tool can be “search products”, “get order status” or “list DI preferences”. A Magento MCP server decides which tools exist, who may call them and what they may change.
“Magento 2 MCP” is the practical shorthand for connecting a Magento 2 or Adobe Commerce installation to MCP-capable AI clients.
Adobe documents two different MCPs for Adobe Commerce. Commerce MCP is for agentic commerce, from discovery to checkout, and is labelled “Coming Soon”. Commerce Developer MCP is development tooling for Adobe Commerce as a Cloud Service. They serve different use cases and are not two versions of the same server. We count separately documented products or projects, not vendors, so Adobe appears twice. Where two components are separate installs but form one product flow, such as angeo mcp-server and mcp-checkout, we describe them together.
How is MCP different from APIs, UCP, WebMCP and ACP?
| Technology | Main purpose |
|---|---|
| MCP | An AI client calls tools on a server |
| REST / GraphQL | General application integration with Magento |
| UCP | Agentic commerce interoperability; a business profile at /.well-known/ucp lists services and transports, including an MCP binding |
| WebMCP | Tools a web page offers to an AI agent in the browser |
| ACP | OpenAI’s agentic commerce protocol: product feeds and checkout |
| Product feeds | Machine-readable catalog distribution to shopping surfaces |
Many MCP servers use Magento’s REST or GraphQL APIs underneath. MCP adds tool descriptions that AI clients understand.
Magento MCP server types: storefront, admin and developer
| Type | Who uses it | What it touches | Typical risks |
|---|---|---|---|
| Storefront | Shoppers’ AI agents | Public catalog, prices, stock. Sometimes cart and checkout. | High-volume automation, unwanted checkout actions, prompt injection through product content |
| Admin | Authorized staff | Orders, customers, CMS, configuration, reports | Unintended changes to live data, customer data sent to the model |
| Developer | Developers | Codebase, CLI, configuration and database of the install it points at | Command and file execution, malicious instructions in code or docs, destructive changes |
These are category-level risks, not findings against any project listed below. The grouping is ours, not an official MCP or Magento taxonomy.
Where does a Magento MCP server run? Deployment and architecture models
These four models mix architecture (module or sidecar), access context (local) and hosting (platform). They are a practical grouping, not a formal MCP taxonomy.
| Model | Advantage | Main concern |
|---|---|---|
| Magento module | Reuses Magento services and ACL directly | More code running inside the store |
| Sidecar service | Can be isolated and scaled separately | One more service and one more set of API credentials |
| Local developer tool | No public MCP endpoint needed | Local command, file and database access |
| Platform service | Less infrastructure to run | Vendor dependency and data-boundary questions |
How to evaluate a Magento MCP server
For each project we look at: what it actually is, where it runs, how clients get access, what it can write, which safety controls it documents, its license and its status. Status means the latest release, repository activity or vendor availability label we found on 18 September 2026.
We use one vocabulary for writes: None documented, Read-only by design, Cart and checkout, Admin data, Code and files, CLI and database, Not documented.
“Not documented” does not mean “not supported”. It means we did not find the capability in the sources we reviewed. Security controls are taken from project documentation. We did not penetration-test the servers or audit their controls.
What can go wrong?
| Risk | Example |
|---|---|
| Prompt injection | A product description or review tells the agent to ignore its instructions |
| Too many permissions | The agent can edit customers when it only needs the catalog |
| Credential leak | An API token or admin password sits in a client config file |
| Unintended writes | The agent updates live prices or stock |
| Data exposure | Order or customer data is returned to the model |
| Tool abuse | High-frequency catalog or order queries |
| Destructive commands | A developer server runs a CLI, shell or database command |
Read-only does not mean data-safe. A read-only admin MCP server can still expose customer records, orders, internal configuration and other sensitive business data.
Security checklist
- Authentication. For remote servers, prefer standards-based authentication such as OAuth 2.1 where supported, or narrowly scoped credentials. Local developer servers rely on OS and process permissions and should avoid unnecessary network exposure. Never put an admin password in a config file.
- Authorization. For remote deployments, validate the authentication protocol’s issuer, audience and scopes where applicable.
Originis not an authentication mechanism. - Token lifecycle. Prefer expiring credentials with rotation and revocation over long-lived static secrets.
- Permissions per tool. Where an admin MCP server exposes Magento data, verify that each tool is subject to the intended Magento ACL.
- A write switch. Check whether one setting can block all changes.
- Approval for writes. Clearly mark state-changing tools, and use client-side confirmation and/or server-side approval controls before consequential actions.
- Audit log. For sensitive admin deployments, consider an audit log that records calls and masks customer data.
- Rate limits. Per client and per tool — and switched on in production.
- Transport security. Enforce HTTPS, protect browser-based sign-in flows against CSRF, and follow the server’s documented protocol and origin requirements.
- Separation. Storefront and admin servers use different endpoints and credentials, and the MCP endpoint does not reuse a Magento admin session.
- Untrusted text. Product descriptions, reviews and code comments are data, not instructions.
Magento MCP servers compared
Absence of documentation is not evidence that a feature is absent. Both tables show what each project documents, not what we tested.
Main comparison
| Project | Type | What it is | Runs where | Access | Writes | License | Status (18 Sep 2026) | Source |
|---|---|---|---|---|---|---|---|---|
| Mirasvit Agentic Commerce | Storefront | Commercial extension | Magento + browser (WebMCP) | Public | None documented | Commercial | Commercial, available | Vendor documentation |
| Meetanshi Agentic Commerce | Storefront | Commercial extension | Magento | Bearer token, HMAC | Cart and checkout | Commercial | Commercial, available | Vendor documentation |
| Adobe Commerce MCP | Platform | Platform capability | Adobe-managed | Adobe | Cart and checkout | Proprietary (Adobe) | Coming soon (Adobe label) | Adobe documentation |
| Magebit MCP module | Admin | Magento module + sub-modules | Magento | Bearer or OAuth 2.1 | Admin data | MIT | Maintainer label: in progress; updated Aug 2026 | Official repository |
| Scandiweb MCP | Admin | Magento module | Magento | OAuth or bearer (admin token) | Admin data | OSL-3.0 | Release not verified | Vendor article |
| Mirasvit AI Agent Connector | Admin | Commercial extension | Magento | OAuth 2.1 | Admin data | Commercial | Commercial, launched Mar 2026 | Vendor documentation |
| yuriyakishin/module-mcp-server | Admin | Magento module | Magento | OAuth 2.1 | Not documented | Not documented | Release not verified | Packagist |
| adwise/magento2-mcp | Admin | Magento module | Magento | Bearer, OAuth discovery; stdio or SSE | Admin data | Not documented | Release 1.0.0, Jul 2026 | Packagist |
| thomastx05/magento-mcp | Admin | Sidecar service | Node, next to Magento | OAuth 1.0 integration | Admin data | Not documented | Release not verified | Our list (secondary) |
| magendooro/magemcp | Admin | Sidecar service | Python, next to Magento | Not documented | Not documented | Not documented | Release not verified | Our list (secondary) |
| iranimij/magento-mcp | Admin | Module + Node server | Magento + Node | Admin username and password | Admin data | Not documented | Last release Jun 2025 | Official repository |
| Magento 2 and Adobe Commerce PhpStorm plugin | Developer | IDE plugin exposing MCP tools | JetBrains IDE | Local | Code and files | OSL-3.0 | 2026.3 line, Jul 2026 | Official repository |
| n98-magerun2 MCP | Developer | CLI MCP server | Local CLI | Local | CLI and database | MIT | MCP server since 9.3.0 | Official repository |
| Adobe Commerce Developer MCP | Developer | Adobe development tooling | Coding agent + Adobe | Local + Adobe | Code and files | Proprietary (Adobe) | Documented, Aug 2026 | Adobe documentation |
| Inchoo Bricklayer | Developer | Composer package | Local | Local | Code and files | Not documented | Release 1.15.1, Jun 2026 | Packagist |
| elgentos magento2-dev-mcp | Developer | Node MCP server | Local (npx) | Local | CLI and database | MIT | Marked abandoned on GitHub | Official repository, security advisory |
| angeo mcp-server + mcp-checkout | Storefront | Two Magento modules | Magento | Anonymous, rate-limited, remote HTTP | mcp-server: none (read-only by design). mcp-checkout: cart and checkout | MIT | Release 2.1.1, Sep 2026 | Packagist |
Documented security and permissions
We did not penetration-test the servers or audit their controls. Every cell below is based on the project’s own documentation.
| Project | Authentication | Permissions | Write controls | Audit | Rate limits |
|---|---|---|---|---|---|
| Mirasvit Agentic Commerce | Public read | Per-protocol switches | No writes documented | Not documented | Not documented |
| Meetanshi Agentic Commerce | Bearer token, HMAC | Per-product switches | Per-product checkout block | Activity dashboard | Not documented |
| Adobe Commerce MCP | Adobe | Not documented | Not documented | Not documented | Not documented |
| Magebit MCP module | Bearer, or OAuth 2.1 with PKCE and read/write scopes | Per-tool admin ACL + underlying Magento ACL | Global toggle + per-token flag; confirmation hint for destructive tools | PII-redacting audit log (documented) | Per admin and tool; off by default |
| Scandiweb MCP | OAuth or bearer, expiring admin token | Magento admin role tree | Double check on content writes; explicit confirm for cascading deletes | Not documented | Not documented |
| Mirasvit AI Agent Connector | OAuth 2.1 | Scoped to the authorizing admin’s role | Not documented | Not documented | Not documented |
| yuriyakishin/module-mcp-server | OAuth 2.1 | Magento ACL | Not documented | Not documented | Not documented |
| adwise/magento2-mcp | Bearer (admin or integration), OAuth discovery | Own ACL resource | Not documented | Not documented | Not documented |
| thomastx05/magento-mcp | OAuth 1.0 integration | Not documented | Two-phase commit; price and volume limits (per our list) | Not documented | Not documented |
| magendooro/magemcp | Not documented | Not documented | Not documented | PII redaction (per our list) | Not documented |
| iranimij/magento-mcp | Admin username and password | Not documented | Not documented | Not documented | Not documented |
| Magento 2 and Adobe Commerce PhpStorm plugin | Local process | OS and IDE user | IDE MCP server off by default | Not documented | Not documented |
| n98-magerun2 MCP | Local process | OS user, database credentials | Not documented | Not documented | Not documented |
| Adobe Commerce Developer MCP | Local agent + Adobe | Not documented | Not documented | Not documented | Not documented |
| Inchoo Bricklayer | Local process | OS user | Not documented | Not documented | Not documented |
| elgentos magento2-dev-mcp | Local process | OS user | Not documented | Not documented | Not documented |
| angeo mcp-server + mcp-checkout | mcp-server: anonymous. mcp-checkout: anonymous guest session | Public catalog only; no admin tools | mcp-server: no writes. mcp-checkout: separate install, off by default, server-side limits, tool annotations | Not documented | Yes |
“Not documented”: not found in the sources we reviewed. “Release not verified”: we did not verify a release date. Nothing in these tables is our judgment of quality or an audit result.
Summary by group
This is a grouping, not a ranking.
- Shopping agents: Mirasvit Agentic Commerce, Meetanshi Agentic Commerce, Adobe Commerce MCP (coming soon), angeo.
- Admin work: Magebit, Scandiweb, Mirasvit AI Agent Connector, yuriyakishin, adwise, thomastx05, magendooro, iranimij.
- Development: Magento 2 and Adobe Commerce PhpStorm plugin, n98-magerun2 MCP, Adobe Commerce Developer MCP, Inchoo Bricklayer, elgentos (abandoned).
- Local-first: PhpStorm plugin, n98-magerun2 MCP, Inchoo Bricklayer, elgentos. Adobe Commerce Developer MCP also involves Adobe’s cloud service.
- Documented remote HTTP access: Magebit, Mirasvit AI Agent Connector, adwise (SSE), angeo. Scandiweb, Mirasvit Agentic Commerce and Meetanshi describe connecting hosted AI clients.
- No writes documented or read-only by design: Mirasvit Agentic Commerce; angeo mcp-server without mcp-checkout.
Storefront and agentic-commerce servers
Storefront servers serve shoppers’ agents, not your staff. They are part of agentic commerce and should only expose public data.
Mirasvit Agentic Commerce
- What it is
- Commercial Magento extension. The vendor documents four adapters: UCP, a storefront MCP server, the feed side of OpenAI’s ACP, and WebMCP tools on the page, plus
llms.txt,agents.mdand an agent sitemap. - Access
- Public catalog data. Each protocol has its own switch.
- Writes
- None documented. The vendor lists in-conversation checkout as a roadmap item.
- Security note
- Public-facing even without writes: plan rate limits.
- Source
- Vendor page
Meetanshi Agentic Commerce
- What it is
- Commercial Magento extension. The vendor documents a UCP profile, a generic MCP server, WebMCP tools and ACP.
- Access
- Bearer token and HMAC signatures, according to the vendor.
- Writes
- Cart and checkout. Agents can build a cart and hand it to the shopper’s browser.
- Security note
- The widest feature set also means the widest attack surface. Per-product switches can hide items or block agentic checkout.
- Source
- Vendor page
Adobe Commerce MCP
- What it is
- Adobe platform capability for agentic commerce, presented at Summit in April 2026. Adobe describes access to catalog, cart, pricing, inventory, promotions, checkout, order management and post-purchase flows.
- Access
- Adobe-managed. Adobe’s documentation labels it “Coming Soon”.
- Writes
- Cart and checkout, according to Adobe.
- Security note
- Not yet something you can install. Check availability and requirements with Adobe.
- Source
- Adobe documentation
angeo mcp-server and mcp-checkout (built by angeo.dev)
- What it is
- Two MIT Magento modules.
angeo/module-mcp-serverexposes what an anonymous shopper can see: product search, product cards, categories and store info, with store-specific tool instructions and an optional “Add to Claude” storefront widget.angeo/module-mcp-checkoutis a separate install with six guest cart and checkout tools and pay-by-link handoff to Stripe, Mollie or Adyen.angeo/module-ucpcan advertise the endpoint through UCP’s MCP binding. - Access
- Anonymous, rate-limited, remote HTTP. No admin tools, by design.
- Writes
- mcp-server: read-only by design. mcp-checkout: cart and checkout, disabled by default and limited on the server side. Tools carry MCP tool annotations.
- Security note
- Our recorded test where Claude places a real order demonstrates a write-capable flow. It is not a recommendation to open checkout to any agent. Enable it only after you review rate limits, cart validation, the payment flow and fraud controls. Maintained mainly by one developer.
- Source
- Packagist
Admin servers: work with store data through AI clients
This is the busiest category. Projects differ most in how they control writes.
Magebit MCP module
- What it is
- Magento module (MIT) with a
POST /mcpendpoint. Domain tools come as separate sub-modules: orders, catalog, customers, CMS, promotions, reports, tax and more. - Access
- Bearer token, or OAuth 2.1 with PKCE and
mcp:read/mcp:writescopes. The README describes OAuth as the right choice for hosted clients such as Claude and ChatGPT. - Writes
- Admin data, per installed sub-module — including catalog deletes.
- Security note
- The README documents per-tool admin ACL plus the underlying Magento ACL, a global write toggle plus a per-token write flag, a confirmation hint for destructive tools, a PII-redacting audit log, and an origin allowlist to tighten for production. Rate limiting exists but is off by default.
- Source
- Official repository
Scandiweb MCP
- What it is
- Magento module (OSL-3.0) for store content.
- Access
- OAuth or bearer sign-in. Both produce an ordinary Magento admin token that expires on Magento’s OAuth schedule (four hours by default, per Scandiweb).
- Writes
- Admin data: CMS, categories and products through the content module.
- Security note
- Every tool sits in Magento’s admin role tree. Content writes are checked against the tool and the native resource. Deletes that cascade need an explicit confirmation.
- Source
- Scandiweb article
Mirasvit AI Agent Connector
- What it is
- Commercial admin-side extension (launched March 2026) with four tools: store info, a read-only SQL reader, REST API calls and GraphQL queries and mutations.
- Access
- OAuth 2.1, scoped to the authorizing admin user’s permissions.
- Writes
- Admin data through REST and GraphQL, as far as the admin role allows.
- Security note
- A read-only SQL tool can still reach sensitive tables. Scope the admin role carefully.
- Source
- Vendor manual
yuriyakishin/module-mcp-server
- What it is
- Magento module with 40+ tools and guided prompts, according to its Packagist listing.
- Access
- OAuth 2.1 and native Magento ACL.
- Writes
- Not documented in the sources we reviewed.
- Security note
- Check the tool list for write tools before granting roles.
- Source
- Packagist
adwise/magento2-mcp
- What it is
- Lightweight Magento module (1.0.0, July 2026).
- Access
- Bearer tokens (admin or integration), OAuth discovery with browser login, stdio or SSE transport. Requires its own ACL resource.
- Writes
- Admin data: configuration, cache and indexers; more through optional sub-modules.
- Security note
- SSE accepts a token in the URL for clients that cannot set headers — prefer the header.
- Source
- Packagist
thomastx05/magento-mcp
- What it is
- Node sidecar service that talks to Magento’s API.
- Access
- Magento OAuth 1.0 integration credentials.
- Writes
- Admin data: bulk changes.
- Security note
- Documents a two-phase commit for bulk changes, with limits on price and volume.
- Source
- Our list (secondary): community-listed project, primary documentation not verified
magendooro/magemcp
- What it is
- Python sidecar over Magento REST and GraphQL.
- Access
- Not documented in the sources we reviewed.
- Writes
- Not documented in the sources we reviewed.
- Security note
- Documents PII redaction.
- Source
- Our list (secondary): community-listed project, primary documentation not verified
iranimij/magento-mcp
- What it is
- Small early project: Magento module plus a Node server.
- Access
- Admin username and password in the client configuration.
- Writes
- Admin data: customers and products.
- Security note
- Do not copy the password-in-config pattern on a live store.
- Source
- Official repository
Developer servers: help coding agents work on Magento
Do not connect a coding MCP server to production unless you have deliberately designed and tested its command, file and database permissions. Developer servers can run shell commands, write files and query databases.
Magento 2 and Adobe Commerce PhpStorm plugin
- What it is
- The official Magento IDE plugin (OSL-3.0). It exposes Magento-specific MCP tools through the JetBrains IDE MCP server: inspection of modules, DI configuration, plugins, observers, layout, UI components and ACL/menu declarations, scaffolding, and project-local CLI environment discovery.
- Access
- Local, inside the IDE. The IDE’s MCP server is off by default.
- Writes
- Code and files it generates in the open project.
- Security note
- Review generated code like any other change.
- Source
- Repository
n98-magerun2 MCP
- What it is
- MCP server built into the n98-magerun2 CLI (MIT). Start it with
magerun2 mcp:server:start; the elgentos README points to version 9.3.0. - Access
- Local, with the permissions of the user who runs it.
- Writes
- CLI and database: anything magerun can do, including configuration and database commands.
- Security note
- Capability equals your shell and database access.
- Source
- elgentos README
Adobe Commerce Developer MCP
- What it is
- Adobe’s development MCP servers and skills for Adobe Commerce as a Cloud Service. Adobe documents converting existing PHP extensions to App Builder apps, building new App Builder apps and storefront customizations, and migration based on the migration assessment.
- Access
- Local coding agents, such as Claude, Cursor and GitHub Copilot, together with Adobe’s cloud service.
- Writes
- Code and files: App Builder apps and storefront components.
- Security note
- For Adobe’s cloud service, not for self-hosted Magento Open Source code.
- Source
- Adobe documentation
Inchoo Bricklayer
- What it is
- Composer package (release 1.15.1, June 2026) that exposes Magento’s runtime state: DI preferences, plugin chains, EAV attributes and observers.
- Access
- Local.
- Writes
- Code and files it generates.
- Security note
- Lets the agent read resolved runtime state instead of guessing from source files.
- Source
- Packagist
elgentos magento2-dev-mcp
- What it is
- Node MCP server that wrapped magerun commands (MIT).
- Access
- Local, via npx.
- Writes
- CLI and database, including configuration.
- Security note
- The repository is currently marked as abandoned on GitHub, and its maintainers point users to the MCP server built into n98-magerun2. A published security advisory reports that versions up to 1.0.2 are affected by CVE-2026-5603, an OS command injection with a local attack vector.
- Source
- Security advisory
How do I connect Magento to Claude, Claude Code, Cursor or ChatGPT?
| Client | Server type | Local or remote | Main requirement |
|---|---|---|---|
| Claude Code | Developer (or admin) | Local, or remote HTTP | MCP server added to Claude Code’s configuration |
| Cursor, Codex, other coding agents | Developer | Local | MCP configuration in the agent |
| Claude (web or desktop) | Admin or storefront | Remote HTTPS | Custom connector; depends on plan |
| ChatGPT | Admin or storefront | Remote, or Secure MCP Tunnel | Custom app in developer mode; depends on plan and workspace |
| Shoppers’ agents | Storefront | Remote | Public endpoint; optional UCP profile |
Claude Code, Cursor and other coding agents
Use a local developer server: the Magento 2 and Adobe Commerce PhpStorm plugin through the IDE’s MCP server, or magerun2 mcp:server:start. In PhpStorm, the MCP server is off by default; turn it on in Settings → Tools → MCP Server. On Adobe Commerce as a Cloud Service, Adobe’s Commerce Developer MCP and skills are built for coding agents. Point any of them at a development install.
Claude (web or desktop)
Add an admin or storefront server that is reachable over HTTPS as a custom connector. Connector and MCP availability in Claude depends on the client and the plan, so check Anthropic’s current connector documentation before you deploy.
ChatGPT
As of 18 September 2026, OpenAI documents the following. ChatGPT calls these integrations “apps” (they were “connectors” until December 2025). Custom MCP apps are added in developer mode and connect to remote MCP servers. According to OpenAI’s Help Center, full MCP support including write actions is rolling out in beta for Business, Enterprise and Edu, and write actions can require user confirmation. For a private, on-premises or local server, OpenAI documents Secure MCP Tunnel: a client inside your network opens an outbound HTTPS connection, so the MCP server is not exposed to the public internet. Check your plan and workspace before you deploy.
Shoppers’ agents
Use a storefront server. If it implements UCP’s MCP binding, advertise that endpoint in your UCP business profile at /.well-known/ucp, as the UCP specification describes. See Magento UCP modules compared.
Which type of Magento MCP server fits your use case?
- Staff manage orders and content through AI. An admin server. Look for OAuth, per-tool ACL, a write switch, confirmation for writes and an audit log.
- AI shopping agents should see your catalog. A storefront server, alone or inside an agentic commerce module. Look for public-data-only access and rate limits.
- Developers use Claude Code, Cursor or PhpStorm. A local developer server. Look for active maintenance and no production credentials.
- You run Adobe Commerce as a Cloud Service. Commerce Developer MCP for development. Commerce MCP for agentic commerce, once Adobe makes it available.
- You self-host Magento. A module or a sidecar, depending on how you isolate services.
- Security is a separate evaluation dimension. Compare documented controls rather than treating feature count as a security signal.
What does MCP not do?
MCP is an interaction protocol, not an indexing strategy.
- Connecting an MCP server does not guarantee that an AI assistant will discover, index or recommend your products.
- It does not replace crawlability, Product schema or product feeds.
- It gives a compatible agent direct tool access only when that agent chooses to use it.
Our observation (not a documented fact): in August 2026 we connected one demo Magento store to Claude as a custom connector and tried a few prompts by hand. A cold shopping prompt in a new chat, such as “Find me a grey backpack”, went to Claude’s built-in product search instead of the store’s MCP tools. A prompt about the store itself, “What do you sell here?”, did reach the connector. This was a handful of manual tries, not a systematic study.
MCP discovery mechanisms are less established than web crawling and product-feed distribution. See AEO options for Magento.
Frequently asked questions
What is the best MCP server for Magento 2?
There is no single best Magento MCP server, because the projects expose different capabilities. Compare them by type first — storefront, admin or developer — then by access, write scope, write safety, deployment model and maintenance.
What is the difference between a Magento MCP server and the Magento REST or GraphQL API?
The REST and GraphQL APIs are Magento's general interfaces for any application. An MCP server wraps selected operations as tools with descriptions that AI clients understand and can call directly. Many MCP servers use the Magento APIs underneath.
How do I connect Magento to Claude Code?
Use a local developer MCP server. Enable the MCP server in PhpStorm and use the Magento 2 and Adobe Commerce PhpStorm plugin's MCP tools, or run magerun2 mcp:server:start from n98-magerun2. Point it at a development install, not production.
How do I connect Magento to Cursor or another coding agent?
The same local MCP servers work with any MCP-capable coding agent. On Adobe Commerce as a Cloud Service, Adobe's Commerce Developer MCP and skills are built for coding agents.
How do I connect Magento to ChatGPT?
Deploy an MCP server that ChatGPT can reach remotely and add it as a custom app in ChatGPT developer mode. For a private or local server, OpenAI documents Secure MCP Tunnel, which keeps the server off the public internet. According to OpenAI's Help Center, full MCP support including write actions is rolling out in beta for Business, Enterprise and Edu.
Is elgentos magento2-dev-mcp still maintained?
No. The repository is currently marked as abandoned on GitHub, and its maintainers point users to the MCP server built into n98-magerun2. A published security advisory reports that versions up to 1.0.2 as affected by CVE-2026-5603, an OS command injection with a local attack vector.
Is it safe to give an AI agent access to Magento admin?
It can be, if the server uses standards-based authentication with expiring credentials, checks Magento admin roles for every tool, can block all writes with one switch, requires confirmation or approval before state-changing actions, and logs every call with customer data masked. Read-only access can still expose customer and order data.
Does Adobe have an official MCP server for Adobe Commerce?
Adobe documents two. Commerce MCP is for agentic commerce from discovery to checkout and is currently labelled Coming Soon. Commerce Developer MCP is development tooling for Adobe Commerce as a Cloud Service.
Does MCP replace SEO, product feeds or UCP?
No. MCP is an interaction protocol, not an indexing strategy. It does not make products appear in AI answers on its own, and it does not replace crawlability, Product schema, product feeds, UCP or ACP.
How we compared
We read each project’s README, Packagist listing, release notes, vendor page or official documentation on 18 September 2026. For thomastx05 and magendooro we relied on our own awesome-magento-aeo entries. We did not install the commercial extensions, and we did not audit any security control. Corrections are welcome — contact us.
- OpenAI: Developer mode and MCP apps
- OpenAI: Secure MCP Tunnel
- JetBrains: PhpStorm MCP server
- UCP specification
- Adobe: Summit 2026 announcements
- Project sources are linked in each entry and in the main table.