Skip to content
HeyCrustDocs

Search documentation

Search by topic or tool name
Browse documentation
Tool reference

set_client_secret

Returns ok and a note about later merchant-session verification, or an app-ownership error..

On this page

Purpose

Store an app's Shopify client secret in Crust (encrypted, write-only — it is never returned by any tool). This is what turns on automatic contact capture and uninstall watches for merchants who open the app. Read the secret from the app repo's env (e.g. SHOPIFY_API_SECRET) or ask the developer for it; never print it back to them.

Credentials and scope

Owner workspace credential. The credential determines tool visibility. For tools with appId, use the HeyCrust app UUID from list_apps; the dashboard app selector does not supply MCP arguments for you.

Inputs

  • appId: required; string; format: uuid — The app id from list_apps.
  • clientSecret: required; string; minLength: 8; maxLength: 255 — The app's Shopify client secret (Partner Dashboard → Client credentials, often SHOPIFY_API_SECRET in the app's env). Stored encrypted, write-only.

Example request

The identifiers and merchant are fictional. Replace them with records returned for your own workspace; this example is schema-checked, not a promise that the fictional record exists.

json
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tools/call",
  "params": {
    "name": "set_client_secret",
    "arguments": {
      "appId": "11111111-1111-4111-8111-111111111111",
      "clientSecret": "REPLACE_WITH_YOUR_SHOPIFY_CLIENT_SECRET"
    }
  }
}

POST this JSON to https://heycrust.com/api/mcp with Content-Type: application/json and Authorization: Bearer <YOUR_CREDENTIAL>. The tool result normally contains JSON encoded as text in result.content; inspect JSON-RPC errors and result.isError before using it.

Result

Returns ok and a note about later merchant-session verification, or an app-ownership error.

Effects and verification

Writes the selected app's encrypted Shopify client secret and clears its invalid-secret flag. It does not return the secret. Obtain approval before submitting the secret; verification happens on subsequent valid merchant sessions.

Troubleshooting

A missing tool can mean that the credential lacks its catalog or required scopes. Invalid arguments are different from unavailable source data or a record outside the workspace. A handler can return a business error even when the argument schema is valid. Read MCP overview and Help.