Connect an AI Assistant to Exchange It with MCP
Updated Sep 30, 2026
Connecting an AI assistant lets you generate a per-store connection token and add Exchange It as a custom connector in ChatGPT or Claude, so your assistant can read returns, analytics, and policy data — and, with the right permission, unmasked customer contact details.
Where to find it
Open the Exchange It settings and find the Connect AI assistant (MCP) card. Everything you need — permissions, the token generator, the connector URL, and your active tokens — lives on this card.
Prerequisites
Connecting an AI assistant (MCP) is an Advanced plan feature. If your store is not eligible, the card shows an "Upgrade to Advanced Plan" banner instead of the working controls; upgrade to generate a connection token and manage returns from ChatGPT or Claude.
Set it up
- Under Permissions, review what the token will grant. Read returns (required) is always on and cannot be turned off. Turn on Access unmasked customer PII only if you want your assistant to be able to see unmasked customer contact details; leave it off to keep customer email, phone, and address masked.
- Click Generate connection token. This mints a per-store token (shaped like
eit_mcp_…) with the permissions you selected and stores it against your shop. Only a hash of the token is kept on Exchange It's side — never the raw token. - The full token is shown in the Connection token field. This is the only time you will see the full token, so use the Copy button to copy it before leaving the page. If you lose it, revoke it and generate a new one.
- Copy the value from the Connector URL field using its Copy button. This is the per-store URL you will paste when adding Exchange It as a custom connector.
Connect it in ChatGPT or Claude
In ChatGPT or Claude, add a custom connector using the Connector URL you copied. When the connect page opens, paste your connection token.
For programmatic access, instead of using the connect page you can send the token as a header in the form Authorization: Bearer <your token>.
Tools your assistant can use
Once connected, your assistant can call these read-only tools:
get_returns_analytics— Returns-specialized analytics for your store over a period (volume by status, reason breakdown, refund-vs-exchange split, top returned products). Optionalperiodinput (7d, 30d, 90d, or 12mo; defaults to 30d). No customer PII.list_returns— Lists your store's returns, most recent first, filterable by status and a start date, with an optional limit. Customer contact details are masked unlessincludePiiis set, which requires the customer PII permission.get_return— Fetches a single return by its Exchange It return id, Shopify return GID, or original order name. Customer details are masked unlessincludePiiis set, which requires the customer PII permission.get_return_policy— Returns your store's returns policy and settings: window/expiration rules, country/product/order rules, return fees, and exchange settings. Read-only, no secrets.get_shop_overview— High-level KPIs for your store: install status, plan, currency, and lifetime returns/exchange counters. Read-only.recommend_resolution— Analyzes one return (by its id) and drafts a suggested resolution — approve, refund minus fees, or exchange — with a deep link into your Exchange It admin. It makes no changes.shopify_read— Runs any read-only GraphQL query against your store's Shopify Admin API (orders, customers, products, returns, fulfillment, transactions, metafields, and more). Mutations and subscriptions are rejected server-side, and the store token is used server-side and never returned. Customer PII stays masked by the underlying Shopify field unless the credential carries the customer PII permission.get_help_article— Fetches one Exchange It help-center article by slug and returns its markdown body.search_help_docs— Keyword search over the Exchange It help center, returning ranked results with slug, title, category, and snippet; use it to find the slug forget_help_article.
Among these, list_returns, get_return, and shopify_read can return unmasked customer details, but only when the token carries the customer PII permission.
What it can access
Every token carries the Read returns (required) permission, which grants read-only access to your returns. If you enabled Access unmasked customer PII, the token additionally allows the PII-capable tools to reveal unmasked customer contact details. All tools are read-only — no tool changes your data, and recommend_resolution only drafts a suggestion with a deep link into your Exchange It admin.
Managing and revoking
Active tokens appear under Active connection tokens, each shown by its last four characters and its granted scopes. To rotate or disable a token, click Revoke next to it; the token is marked revoked immediately and can no longer be used. Revoking is always available even if your plan changes, so you can clean up a leftover token at any time. To rotate a token, revoke the old one and click Generate connection token to mint a fresh one, then reconnect your assistant.