medusajs.com
Medusa is a digital commerce platform and framework for building customizable ecommerce applications. It offers self-hosted or cloud-hosted commerce backends, admin/storefront APIs, and Medusa Cloud tooling for deployment and operations.
Medusa exposes two self-hosted REST APIs (Admin and Store, each with downloadable OpenAPI specs), a Medusa Cloud CLI (`mcloud`), and an authenticated remote Docs MCP server.
- Medusa Docs MCP Remote Serverdiscovered
- Medusa Store APIdiscovered
- Medusa Admin APIdiscovered
- Medusa Cloud CLIdiscovered
Create an access key in Access Keys. Medusa Cloud supports Organization Access Keys and Personal Access Keys for programmatic authentication. You can then provide the key to the CLI with mcloud login --token <key> or the MCLOUD_TOKEN environment variable.
Create a publishable API key in your Medusa application's admin using the API Keys functionality referenced in the docs and then use it when calling Store API routes that require a publishable key. The Store API reference documents publishable API key authentication under Store API. Because Medusa is self-hosted or tenant-hosted, key creation happens in your own Medusa admin instance rather than a shared medusajs.com console.
Create a customer account in your own Medusa store and obtain a JWT by calling the Store API authentication route described in Store API authentication. The docs state you obtain the JWT by sending the customer's email and password to the authentication route, then use the returned token as a bearer token. This is issued by your own Medusa application.
Create an admin user in your own Medusa application and authenticate through the Admin API auth routes referenced by the Admin API documentation at Admin API. Use the returned JWT as a bearer token for Admin API requests. Medusa issues this from each Medusa application instance, not from a shared medusajs.com account.
conventions · 1/7 published
- integrations.json——
- llms.txt✓https://medusajs.com/llms.txt
- API catalog✗
/.well-known/api-catalog - OpenAPI document✗
/api/schema/, /openapi.json, /swagger.json, /api/openapi.json, or /v1/openapi.json - MCP server card✗
/.well-known/mcp/server-card.json - OAuth protected resource✗
/.well-known/oauth-protected-resource - Agent card✗
/.well-known/agent-card.json - Agent skills✗
/.well-known/agent-skills/index.json
Publish these signals → /publishing