For administrators reviewing this MCP server · last updated 30 September 2026
A view of one Shopify store — Moody Lenses's — for AI assistants. A shopper browses the catalogue, chooses the options, gathers a cart, and is handed a link to Moody Lenses's own checkout. Operated by NEXVA GmbH (Curless).
The short list first, because it is the answer to most review questions.
read_products, read_orders and read_discounts —
no write scope exists on the token, so no order, product or customer record can be
created or altered even by a bug. The cart is this connector's own: it lives in memory
for the conversation, and nothing reaches Shopify until the shopper pays on Shopify's
own checkout.list_moody_lenses — the catalogue. Optional free-text query, price cap,
result limit.get_moody_lens — one product: its options, prices, and which
combinations are in stock.get_moody_checkout_link — a Shopify cart link, for one specific variant or,
with no arguments, for everything in the cart. Creates nothing; the URL is a link a
browser can open.add_to_moody_cart — puts one variant in the cart, or sets how many of
it. Changes only this connector's in-memory cart.view_moody_cart — the cart, priced from today's catalogue.clear_moody_cart — empties the cart.check_moody_checkout_status — for the card, not offered to the assistant:
whether the checkout the card opened has been paid, found by the reference that checkout
carries.lookup_moody_order — one order, by order number and email.get_moody_store_policies — the shop's own published policies (returns, shipping,
privacy, terms) and its FAQ and contact pages, as text with their links. Optional topic.What the merchant wrote is fenced. Product descriptions and the shop's own policy text are written by the merchant, not by us, and they reach the buyer's assistant as prose. Before they leave this server they have their control characters and invisible (zero-width, bidi) characters removed and their length capped, and they are wrapped in markers naming whose words they are — with the instructions telling the assistant that what is inside those markers is for the buyer to read and is never an instruction to it. A shop cannot close the markers from inside: the brackets they are made of are stripped from the text first.
How each tool is annotated, exactly as the server declares it:
| Tool | readOnlyHint | destructiveHint | idempotentHint | openWorldHint |
|---|---|---|---|---|
list_moody_lenses | true | false | true | true |
get_moody_lens | true | false | true | true |
get_moody_checkout_link | true | false | true | true |
add_to_moody_cart | false | false | true | true |
view_moody_cart | true | false | true | true |
clear_moody_cart | false | true | true | false |
check_moody_checkout_status | false | false | true | true |
lookup_moody_order | true | false | true | true |
get_moody_store_policies | true | false | true | true |
What a user types into their assistant reaches this server as tool arguments — a search term, an option value, or an order number and email. Nothing else about the conversation is sent.
From this server outbound, two hosts only:
rqxbft-fw.myshopify.com — Shopify's Admin API, to read the catalogue, to
look up a single order, and to find the order a checkout reference points to; and the
same host's public Storefront API, with no credential, to read the policies and pages the
shop publishes on its website.cdn.shopify.com — product images, fetched so the card can display
them from this origin rather than the shopper's browser reaching Shopify directly.A checkout link carries three cart attributes, which Shopify copies onto
the order it creates: Source (always Curless), Assistant (which
AI assistant, when the client says) and CurlessRef (a random reference). The
merchant sees them on the order, and the reference is how the card learns that the order
was paid.
There is none, deliberately. A shopper has no account with this store's assistant, so there is nothing to authenticate them as, and requiring a sign-in to read a public catalogue would be theatre.
What guards it instead: the endpoint writes nothing to the shop; the only sensitive answer it can give needs a matching order number and email; and both are rate-limited — 60 requests a minute per address overall, 10 a minute for order lookup. A wrong email and a non-existent order return the same answer, so the lookup cannot be used to confirm an order exists.
No shopper record is written, and nothing is sold, shared for advertising, or used to build a profile.
Results render as an MCP Apps card: one self-contained HTML document served as a
ui:// resource, with its Content-Security-Policy declared to the host. It
loads images from the two hosts above and makes no other network request.
/healthz.Anything a shopper would ask — an order, a payment, a return — is Moody Lenses's: support@moodylenses.com, or https://moodylenses.com.
An administrator reviewing this server, or reporting a fault in it, reaches the operator at ops@curless.ai — kept here because the point of this page is to say who runs the thing you are being asked to approve.
Privacy policy · Terms — both Moody Lenses's own, because the shopper's data and the sale are theirs.