StoreMCP
Documentation menu

Revoke AI Access or Disconnect a Store

Revoking a client, disconnecting a store and deleting a workspace have different effects.

Prerequisites

Sign in as the workspace owner. Identify the exact client or key before revocation. Revocation does not undo an already completed provider change.

Steps

  1. In Connect AI, revoke the selected client grant or API key. Remove the client’s local connection configuration if it is no longer needed.
  2. Verify that the revoked credential cannot read stores. A different still-authorized client may continue to work.
  3. To stop all Store MCP use of one store, request store disconnection and approve the exact disconnect in the owner’s browser.
  4. Check that the store is disconnected. Revoke the app/key at the provider separately if you also want to end its provider-side grant.

Safe example

The example uses synthetic names. Select your own authorized store and verify every identifier before a write.

Show which stores this client can access and identify the grant I should revoke. Do not disconnect any store.

You’re done when…

Expect the revoked credential to fail authentication or authorization; a disconnected store no longer has saved usable provider credentials. Reconnection requires provider authorization again.

Limitations

Disconnect does not delete marketplace products or orders and does not itself revoke the provider-side app grant. Account deletion is a separate Settings action that disables access promptly and follows the published deletion policy.

Next steps and troubleshooting