> ## Documentation Index
> Fetch the complete documentation index at: https://docs.depict.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# The AI assistants connected to a store

> Lists the store's OAuth grants to MCP clients (AI assistants such as Claude Code), newest first: one per connected assistant, with its name, scopes and approval time. Never carries tokens. Read-only; the Settings page shows it under Connections, and a `grant_id` from it disconnects that assistant through DELETE /mcp/grants/{grant_id}.



## OpenAPI

````yaml /api-reference/openapi/lite.json get /mcp/grants
openapi: 3.1.0
info:
  title: Search & Merchandising API
  version: 1.0.0
  description: >-
    REST API behind Depict: Search & Merchandising, the native Shopify app:
    onboarding, collections, boost & bury, dashboards, A/B testing and
    multi-store management. Endpoints are served under the /api/lite prefix and
    are authenticated with the Shopify session token that App Bridge issues to
    the embedded app.
servers:
  - url: /api/lite
security:
  - ShopifySessionToken: []
paths:
  /mcp/grants:
    get:
      summary: The AI assistants connected to a store
      description: >-
        Lists the store's OAuth grants to MCP clients (AI assistants such as
        Claude Code), newest first: one per connected assistant, with its name,
        scopes and approval time. Never carries tokens. Read-only; the Settings
        page shows it under Connections, and a `grant_id` from it disconnects
        that assistant through DELETE /mcp/grants/{grant_id}.
      operationId: mcpGrantsList
      parameters:
        - schema:
            type: string
            description: Lite merchant id, e.g. `shopify-<shop id>`.
          required: true
          description: Lite merchant id, e.g. `shopify-<shop id>`.
          name: merchant_id
          in: query
      responses:
        '200':
          description: The grants.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/McpGrants'
        '400':
          description: '`merchant_id` is missing; `detail` carries zod''s messages.'
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Detail'
        '401':
          description: Not authenticated.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Detail'
        '403':
          description: Authenticated, but this identity may not call the API.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Detail'
        '404':
          description: Merchant not found for this caller.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Detail'
        '500':
          description: Internal error.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Detail'
components:
  schemas:
    McpGrants:
      type: object
      properties:
        grants:
          type: array
          items:
            $ref: '#/components/schemas/McpGrant'
      required:
        - grants
    Detail:
      type: object
      properties:
        detail:
          type: string
      required:
        - detail
      description: 'Every 4xx/5xx body: `{detail}`.'
    McpGrant:
      type: object
      properties:
        grant_id:
          type: string
          description: Pass it to DELETE /mcp/grants/{grant_id} to disconnect.
        client_id:
          type: string
          description: >-
            The assistant's OAuth client, one per registration (each install of
            an assistant registers anew).
        client_name:
          type:
            - string
            - 'null'
          description: The name the assistant registered under; null when it gave none.
        redirect_to:
          anyOf:
            - type: object
              properties:
                kind:
                  type: string
                  enum:
                    - loopback
                    - https
                    - http
                host:
                  type: string
                  description: Its host name, the part a user can check.
                scheme:
                  type: string
                  description: >-
                    Its scheme, colon included: `https:`, `http:` or an app's
                    own, e.g. `cursor:`.
              required:
                - kind
                - host
                - scheme
            - type: object
              properties:
                kind:
                  type: string
                  enum:
                    - custom
                host:
                  type: 'null'
                scheme:
                  type: string
                  description: >-
                    Its scheme, colon included: `https:`, `http:` or an app's
                    own, e.g. `cursor:`.
              required:
                - kind
                - host
                - scheme
            - type: 'null'
          description: >-
            Where its approval sent the browser, the part of the assistant a
            user can check (the name is free text); null for grants approved
            before this was recorded.
        scopes:
          type: array
          items:
            type: string
          description: 'What the grant allows: `depict:read`, `depict:write`.'
        created_at:
          type: string
          format: date-time
          description: When it was approved (ISO 8601, UTC).
      required:
        - grant_id
        - client_id
        - client_name
        - redirect_to
        - scopes
        - created_at
  securitySchemes:
    ShopifySessionToken:
      type: http
      scheme: bearer
      bearerFormat: JWT
      description: >-
        Shopify App Bridge session token of the embedded Depict: Search &
        Merchandising app. The shop in the token determines the merchant;
        merchant_id parameters must belong to that shop.

````