Merchant workspace (MCP server)
A remote Model Context Protocol server. A merchant links their Vortex IQ account once, then asks Meta AI about their store in plain English.What merchants can ask
Linking an account
1
Discover
/mcp also returns 401 with a WWW-Authenticate header pointing at the first document.2
Register your client
POST https://app.vortexiq.ai/oauth/mcp/register with your https redirect URIs and "token_endpoint_auth_method": "none". No pre-provisioned credentials are needed. If you would rather use a fixed client_id, contact support@vortexiq.ai.3
Authorize
Send the merchant to
https://app.vortexiq.ai/oauth/mcp/authorize with response_type=code, your client_id and redirect_uri, a PKCE S256 code_challenge, state, resource=https://app.vortexiq.ai/mcp and scope=mcp:read. They sign in to Vortex IQ and approve on a consent screen that names your app and says the access is read-only.4
Exchange and refresh
Exchange the code at
POST /oauth/mcp/token. Access tokens last 1 hour. Refresh tokens last 30 days and rotate on every use.5
Call the server
POST https://app.vortexiq.ai/mcp with Authorization: Bearer <access_token>. Methods: initialize, tools/list, tools/call, ping.6
Unlink
When the merchant unlinks, call
POST /oauth/mcp/revoke (RFC 7009) with either token. The whole grant ends at once. Merchants can also disconnect from Connected apps inside Vortex IQ.Security and data handling
- Per merchant. Each call runs as the merchant who linked their account. It returns only their organisation’s data, within their role’s permissions. There is no shared or service account.
- Read-only, end to end. Every tool is read-only, and the access token only works through the MCP server. It cannot be used against any other Vortex IQ API, and the connector never changes a merchant’s store, products, orders or settings.
- Short-lived, revocable tokens. PKCE S256 is required, authorization codes are single-use and expire in 5 minutes, and access tokens are audience-bound to
https://app.vortexiq.ai/mcp(RFC 8707). Revoking any token ends the whole grant. - Origins. Server-to-server calls are always accepted. Browser calls are accepted from
meta.ai,muse.aiand their subdomains (and from Claude); any other origin gets 403. - Transport. HTTPS only.
- Policies. Privacy policy, terms of service, Trust Centre.
Errors
Product catalogue
So shoppers can find products from merchants who choose to take part. This part is in development.- Merchants opt in, one store at a time. Sharing is off until the merchant ticks a box in Vortex IQ Settings, and only opted-in stores are ever searched. See Show your products in Meta AI.
- Rollout. BigCommerce stores first. Adobe Commerce (including Magento Open Source) follows once those stores’ product catalogues are syncing to Vortex IQ.
- Read-only, checkout on the merchant’s site. Results carry the store’s own price and currency and link to the product page. There is no basket or checkout in Meta AI in the first release.
- One product format. BigCommerce and Adobe Commerce products are returned in the same shape, whichever platform a store runs on.
Support
- Email: support@vortexiq.ai
- System status: monitor.vortexiq.ai
- Documentation: docs.vortexiq.ai