Career
The Shopify AI Toolkit is one skill now: what it checks and what it leaves to you
On September 25, 2026 Shopify merged the AI Toolkit's skills into one shopify skill. What to do if you installed the old ones, how the Toolkit, the skill, the Dev MCP and the CLI differ, and where the validator stops.
Bas Lefeber
Founder, learnshopify.dev · October 5, 2026 · 12 min read
On September 25, 2026, Shopify merged the skills in its AI Toolkit into a single skill called shopify. The changelog entry is flagged "Action required", so if you installed the Toolkit before that date there may be something for you to do. That part is short and is covered below.
The bigger question is the one you face every day you write Shopify code with Claude Code, Cursor, Codex or VS Code: what do you let the tool do, and what do you still check yourself? The Toolkit changes that answer, so this post covers both. What it does for you, how its four parts fit together, how to set it up today, and where it stops.
I wrote about the Toolkit when it became generally available in June, in the Shopify AI Toolkit in Cursor, Claude Code and VS Code. That post explains what it is. This one is about what changed since and how to work with it.
The short version
As of October 5, 2026: the separate shopify- skills (shopify-admin, shopify-liquid, shopify-functions and the rest) are deprecated and one shopify skill replaces them. If you installed the plugin, many tools update it for you. If you installed skills with npx skills, you remove the old ones and add the new one yourself. The Dev MCP server and the ucp skill are not affected. The Toolkit gives your agent current Shopify knowledge and a validator. Whether valid code is the right code for the store is still your call.
What changed on September 25
Until then the Toolkit shipped one skill per part of the platform: one for the Admin API, one for Liquid, one for Functions, and so on, more than twenty in total. Now the plugins and the Toolkit's repository expose one shopify skill that covers all of it. Shopify's Toolkit documentation says the skill covers every Shopify developer surface, and that your agent reads the guidance for a surface only when a task needs it. The repository holds two skills today: shopify and ucp, the separate skill for the Universal Commerce Protocol command line.
Shopify gives the reason in the changelog entry. The earlier setup sometimes confused agents, and skill descriptions were cut short when they took up too much of the context window. One skill means fewer descriptions in the agent's context.
My read: that reason applies to your own setup as well. Every skill and every MCP server you add puts its description in front of the model on every task. More tools is not automatically a better agent.
If you installed the old skills
What you do depends on how you installed the Toolkit. The changelog entry says you are affected if you run its skills through a plugin, through npx skills, or through a similar tool that installs the individual skills.
| How you installed it | What to do |
|---|---|
| A plugin (Claude Code, Cursor, Codex, VS Code and others) | Often nothing. Shopify says many agent environments that support plugins update skills automatically. If yours does not, or you want the new skill now, update the plugin with your tool's own plugin management. |
Skills, with npx skills | Remove the old skills and add the new one. The two commands are below. Run them in every environment where you installed the old skills. |
| The Dev MCP server | Nothing. Shopify says Dev MCP users are unaffected. |
Only the ucp skill | Nothing. It is unchanged. |
For npx skills, these are the commands from the migration section of the docs. The first one skips any skill you never installed, so you can run it as it is. Add the -g flag to both if you installed the skills globally.
npx skills remove shopify-admin shopify-admin-execution shopify-app-pricing shopify-app-review shopify-app-store-review shopify-custom-data shopify-customer shopify-dev shopify-functions shopify-hydrogen shopify-liquid shopify-onboarding-dev shopify-onboarding-merchant shopify-partner shopify-payments-apps shopify-polaris-admin-extensions shopify-polaris-app-home shopify-polaris-checkout-extensions shopify-polaris-customer-account-extensions shopify-pos-ui shopify-shopifyql shopify-storefront-graphql shopify-use-shopify-clinpx skills add Shopify/shopify-ai-toolkitThe changelog entry prints a slightly different pair: its remove command has a -y flag and a shorter list of names, and its add command names the skill with --skill shopify. I used the version from the docs page here because its list of names is the longer one.
The docs say the old skills are deprecated and no longer receive updates. Skills installed with npx skills also do not update on their own: you run npx skills update to get new versions. According to the repository's changelog, running that with version 1.5.24 or later of the skills CLI replaces each retired skill with a notice that tells you to remove it and add shopify.
Things that used the old names
The rename reaches a few places outside the skills folder. The repository's changelog for version 2.0.0 lists them:
- Saved prompts and custom agents. Anything that loaded
shopify-adminby name should loadshopifyand say which topic it is about. - Allowlists. A permission entry for one of the old skills, or a
shopify-*pattern, needs an entry forshopify. - Script paths. The validation script moved from each skill's own folder to the
scriptsfolder of theshopifyskill, and it takes the topic as a flag, for example--api admin.
One more rename, for people on the Dev MCP server. The changelog entry says they are unaffected, and for the skills that is true. But version 1.16.0 of @shopify/dev-mcp was published the same day, and its README no longer lists the validate_theme_codeblocks tool that version 1.15.4 documented. Theme validation is the validate_theme tool now, and other code goes through a tool called validate. If your agent instructions or permission lists name the old tool, update them.
What the docs do not say
Shopify does not give a command per tool for forcing a plugin update. The changelog entry only says to use the agent's plugin management tools. So for that step, your editor's own documentation is the source, not Shopify's.
Toolkit, skill, Dev MCP, CLI: which is which
Four names get used as if they were the same thing. They are not, and knowing the difference tells you what you have installed.
| Name | What it is | How it reaches your editor |
|---|---|---|
| AI Toolkit | The whole package. Shopify describes it as connecting your AI tool to developer docs and API schemas, to code validation, and to store management through Shopify CLI. | Three routes: a plugin, agent skills, or the Dev MCP server. |
| The plugin | The install Shopify recommends. It bundles everything into one install and updates automatically. | One command or one marketplace action per tool. |
The shopify skill | Instructions and scripts your agent reads when a task is about Shopify: a guide per surface (Liquid, the Admin API, Functions, Hydrogen, Polaris, Shopify CLI and more), a script that searches the docs and a script that validates code. | Inside the plugin, or on its own with npx skills add. On its own it does not update itself. |
| Dev MCP server | A local server that speaks MCP, the Model Context Protocol, published as the npm package @shopify/dev-mcp. It searches Shopify's docs and API schemas and validates GraphQL, Liquid and theme files, and UI extension code. It needs no authentication. | An entry in your tool's MCP configuration. |
| Shopify CLI | The command-line tool for generating and working with Shopify apps, themes and custom storefronts. It is the part that runs things, including queries against a store. | Its own install (@shopify/cli). The skill's developer onboarding guide has the agent check whether it is installed and install it if not. |
The Dev MCP server used to have its own documentation page. That address now redirects to the Toolkit page, where the server is the third install route. Its README on npm says the full plugin is recommended when your tool supports it. So: plugin if you can, skills if your tool has no plugins or you want to manage them yourself, Dev MCP if you prefer MCP.
One thing Shopify does not answer: whether to run the plugin and the Dev MCP server next to each other. The docs present them as alternatives and say nothing about combining them. I am not going to guess.
Where the CLI comes in
The Spring '26 Edition, where the Toolkit was announced as generally available on June 17, 2026, puts the split in one line: the skills help an agent understand how to build, and the CLI then executes the commands. Searching docs and validating code change nothing on a store. Running a command can.
For store data that means two commands. shopify store auth signs the CLI in to one store with the access scopes you name. shopify store execute then runs an Admin API query against it. The command's reference states that mutations are disabled by default: to change store data you have to run it again with --allow-mutations. The Toolkit docs describe store tasks as something the agent prepares and runs with you choosing when to execute them.
Set it up today
You need Node.js 18 or higher and a supported tool. As of October 5, 2026 the docs list Claude Code, Codex, Antigravity CLI, Cursor, Hermes, OpenClaw, Pi and Visual Studio Code. These are the plugin commands for the three most common ones, copied from the Toolkit documentation.
claude plugin install shopify-ai-toolkit@claude-plugins-officialcodex plugin add shopify@openai-curated/add-plugin shopifyIn VS Code, make sure the Agent plugins preview is enabled in your settings, open the Command Palette, run Chat: Install Plugin From Source and enter https://github.com/Shopify/shopify-ai-toolkit as the repository URL. The docs page has the commands for the other tools.
If you followed my June post, the Claude Code command there was a two-step form that starts with /plugin marketplace add. The docs page and the repository's README both show the single command above now.
No plugin support in your tool? Install the skills directly with the npx skills add Shopify/shopify-ai-toolkit command from the section above. And if you prefer MCP, this adds the Dev MCP server to Claude Code:
claude mcp add --transport stdio shopify-dev-mcp -- npx -y @shopify/dev-mcp@latestRestart Claude Code afterwards. In Cursor, the same server goes into your MCP settings like this:
{ "mcpServers": { "shopify-dev-mcp": { "command": "npx", "args": ["-y", "@shopify/dev-mcp@latest"] } }}There is nothing to switch on after that. The docs say your AI tool draws on Shopify's developer resources automatically when you ask it something about Shopify.
What it sends to Shopify
One thing to know before you install it on client work: usage telemetry is on by default. The telemetry section of the README lists what the skill's scripts send to shopify.dev each time they run. That includes the search query and the search result, the validation result and the code that was validated. When the agent passes them along, it also includes the names of your model and your tool, and your most recent message to the agent, cut off at 2,000 characters. The Dev MCP server's README says its release builds send usage events too, and that these can include tool inputs and results.
You can turn it off. Shopify recommends an empty opt-out file, because it also works in tools that do not pass your shell environment on to the scripts they start:
mkdir -p ~/.config/shopify-ai-toolkit && touch ~/.config/shopify-ai-toolkit/opt-outOn Windows the file is %APPDATA%\shopify-ai-toolkit\opt-out. The README says the opt-out covers the skill scripts, the MCP server and the plugin's hooks at once. Setting OPT_OUT_INSTRUMENTATION=true in your environment is the other documented way.
What the Toolkit does for you
A model on its own writes Shopify code from memory. Memory is where the mistakes come from: a field that was renamed, a filter from another framework, an API version that has moved on. With the Toolkit the agent looks things up in the current docs and schemas, and checks what it wrote before it hands it to you.
I build this site with Claude Code and the Dev MCP server, and one rule in the repository exists because of what happens without that check. I once shipped a lesson that taught a filter called titleize. It exists in Rails. It does not exist in Shopify Liquid. A student spent ten minutes on code that looked correct and never worked. Since then, every Liquid construct in a lesson goes through the validator before it ships.
That class of mistake is what the Toolkit removes. Here is the line, and what the Dev MCP server's theme validation says about it (run on October 5, 2026):
<h2>{{ product.title | titleize }}</h2>ERROR: Unknown filter 'titleize' used.The skill's instructions tell the agent what to do with that error: read it, search the docs for the thing it names, fix that, and validate again. For anyone learning Shopify, that matters. An invented filter gets caught before it reaches you.
What it leaves to you
Now a second snippet, through the same validator on the same day. An AI was asked to show the product price:
<div class="product-price"> <span class="price">${{ product.price }}</span></div>Theme file snippets/ai-price.liquid passed all checks from Shopify's Theme Check.It passes, and it should. Every part of it is real Liquid. It is also wrong. product.price is a number in the currency's subunit, so a product that costs 18.99 shows up as 1899. And the dollar sign is typed in by hand, so a store that sells in euros shows a dollar sign anyway. The fix is the money filter, which does both jobs.
A validator answers one question: is this valid Shopify code? It cannot answer the next one: is this the right code for this store? From here on this is my read, but Shopify says something close to it on the docs page: "The toolkit doesn't remove the need to review and test the result."
The things I still check by hand in generated Shopify code:
- Where the data lives. A metafield and a value parsed out of the product title both validate. Only one of them survives the merchant renaming a product.
- Which part of the platform does the job. Theme code, an app or a Function can all produce something that looks like the feature. Which one is right depends on whether the rule has to hold at checkout, and no validator knows that.
- The cases nobody typed into the prompt. A sold-out variant, a product without an image, a second currency. The code is valid for all of them. Whether it behaves well is a separate matter.
- Whether a write should run at all. The CLI makes you opt in to mutations. Whether this change belongs on this store today is not a question about syntax.
I gave more examples of this in the June post, and the wider argument is in do you still need to learn Shopify development in the AI era. The short form: the better the tools get at producing valid code, the more of your value sits in the second question.
Learn this properly · free lesson
Review the AI's price code
The price snippet above is a lesson here. An AI wrote it, it shows a number on the page, and a teammate wants to merge it. Review it and make the call. About 7 minutes, free, in your browser.
Try this lesson — freeA way to work with it
This is how I would set up the routine, whichever editor you use.
- Install one route and keep it current. The plugin if your tool supports it. If you use
npx skills, putnpx skills updatein your routine, because nothing does it for you. - Do not accept Shopify code that skipped the validator. The skill tells the agent to validate generated code before it returns it. If you see Liquid or GraphQL in a reply with no validation step before it, ask for it.
- Then read the diff for what a validator cannot see. The data model, the choice of theme, app or Function, and the cases from the list above.
- Keep store writes deliberate. Leave
--allow-mutationsoff until you have read the mutation and know which store it will run against. - Test on a store. Shopify's own wording is review and test. A green validation is the start of that, not the end.
The Toolkit was introduced on April 9, 2026. Its skills and its install commands have both changed since. The docs page is where the current ones are.
Frequently asked questions
What is the Shopify AI Toolkit?
It is Shopify's package for connecting AI coding tools to the platform. According to Shopify's documentation it gives your agent developer docs and current API schemas, validation for GraphQL, Liquid and extension code, and store management through Shopify CLI. It was introduced on April 9, 2026 and announced as generally available in the Spring '26 Edition on June 17, 2026.
What changed in the Shopify AI Toolkit on September 25, 2026?
All the separate shopify- skills, such as shopify-admin, shopify-liquid and shopify-functions, were consolidated into a single skill called shopify. Shopify's stated reason is that the earlier setup sometimes confused agents and caused skill descriptions to be truncated when they took up too much of the context window.
Do I need to do anything if I installed the old Shopify skills?
It depends on how you installed them. Shopify says many agent environments that support plugins update skills automatically, and that you can otherwise update the plugin with your agent's plugin management tools. If you used npx skills, remove the deprecated shopify- skills with npx skills remove and install the new one with npx skills add Shopify/shopify-ai-toolkit. The exact commands are on the AI Toolkit documentation page. The old skills no longer receive updates.
What is the difference between the AI Toolkit and the Shopify Dev MCP server?
The AI Toolkit is the whole package and can be installed three ways: as a plugin, as agent skills, or through the Dev MCP server. The Dev MCP server is the npm package @shopify/dev-mcp, a local server that searches Shopify's docs and API schemas and validates code, without authentication. Shopify recommends the plugin when your tool supports it. As of October 5, 2026 the old Dev MCP documentation address redirects to the AI Toolkit page.
Is the Dev MCP server affected by the skills consolidation?
No. The September 25, 2026 changelog entry says users of the ucp skill and the Dev MCP are unaffected.
How do I install the Shopify AI Toolkit in Claude Code?
As of October 5, 2026, Shopify's documentation gives this terminal command for the plugin: claude plugin install shopify-ai-toolkit@claude-plugins-official. You need Node.js 18 or higher. To use the Dev MCP server instead, the documented command is claude mcp add --transport stdio shopify-dev-mcp -- npx -y @shopify/dev-mcp@latest, followed by a restart of Claude Code.
Does the Shopify AI Toolkit send data to Shopify?
Yes, usage telemetry is on by default. The Toolkit's README says the skill scripts send events that include search queries and results, validation results and the validated code, model and client names, and the most recent user message truncated to 2,000 characters when the agent passes it. You can opt out by creating an empty file at ~/.config/shopify-ai-toolkit/opt-out or by setting OPT_OUT_INSTRUMENTATION=true.
Do I still need to review Shopify code if the AI Toolkit validated it?
Yes. Validation tells you the code is valid Shopify code: real filters, real fields, correct syntax. It does not tell you whether the code is the right design for the store. A snippet that prints product.price without the money filter passes validation and still shows 1899 for a price of 18.99. Shopify's documentation says the Toolkit does not remove the need to review and test the result.
Start free
Ready to become a Shopify developer?
You just read how it works. Now write it yourself: real tickets from a live store, in an editor where the storefront updates as you type. Module 1 is free, no card.
Free · No credit card · Your first win in minutes
About the author
Bas Lefeber, Founder, learnshopify.dev
Bas builds learnshopify.dev, where developers learn production-grade Shopify theme development against a live storefront. He writes about Liquid, theme architecture, and the parts of the job that still matter now that AI writes the code.
Keep going in the curriculum



