Developers

Use with AI tools

Connect Claude, ChatGPT or Cursor to your store over MCP.

Zaher runs an MCP server, so AI assistants can read and manage your store: "which orders are still unfulfilled?", "accept tomorrow's bookings", "set the blue hoodie's stock to 12".

It's the REST API in another protocol. Every endpoint is a tool, with the same scopes, plan and rate limit.

Create a connection URL

In your dashboard, go to Settings → APIs & Webhooks → AI assistants and choose Create connection URL. Its access decides which tools the assistant gets. Start with Read only: the assistant can look but can't change anything.

The URL is shown once and looks like this:

https://api.zaher.io/mcp/c/zk_mcp_…

Add it to your assistant

Settings → Connectors → Add custom connector, then paste your connection URL.

Ask

Try "What's my store's currency and plan?" — it calls store_get, which any connection can use.

The URL is a password

Anyone with your connection URL can use your store with its access. Don't share it or post it in screenshots. Give each assistant its own URL, with only the access it needs, and revoke it from the dashboard if it leaks.

Use an API key instead

Developers can connect with an API key sent as a header, instead of a connection URL. Point the client at https://api.zaher.io/mcp and send Authorization: Bearer zk_live_…:

claude mcp add --transport http zaher https://api.zaher.io/mcp \
  --header "Authorization: Bearer zk_live_…"

Connection URLs and API keys differ in one way: a connection URL works only for MCP, never for the REST API, and an API key never works inside a URL.

Tools

Your assistant only sees the tools its access allows. A write scope includes its reads, the same as in the REST API.

ToolDoesNeeds
store_getGet the storeAny key
orders_listList ordersorders:read
orders_getGet an orderorders:read
orders_fulfillUpdate fulfillment · changes dataorders:write
bookings_listList bookingsbookings:read
bookings_getGet a bookingbookings:read
bookings_acceptAccept a booking · changes databookings:write
bookings_cancelCancel a booking · changes databookings:write
products_listList productsproducts:read
products_getGet a productproducts:read
products_updateVariantUpdate a variant's price · changes dataproducts:write
products_updateStockSet or adjust stock · changes dataproducts:write
customers_listList customerscustomers:read
customers_getGet a customercustomers:read

Each tool takes the endpoint's path parameters, query and body as one set of arguments, and returns the same JSON as the API reference.

Changes to your store

Tools that change data are marked as such, so assistants ask you before they run them. Write tools also take an optional idempotency_key argument. An assistant that retries a change with the same key gets the first result back instead of applying it twice. See Idempotency.

Limits and errors

  • Plan and rate limit: the same as the API. MCP and REST requests share one limit per store; see Rate limits. Connection URLs have their own cap, separate from API keys.
  • Connection errors: a revoked or expired URL or key, a plan without API access, or too many requests fail the whole request, with the error body of the API. Your assistant reports it as a connection problem.
  • Tool errors: anything else — a booking that can't be accepted, an unknown order, an invalid argument — comes back as a tool error with the API's error code, so the assistant can read it and adjust.

On this page