# shopify_get_customer

Get Shopify customer details.

Agent View of the PolicyLayer registry record for `shopify_get_customer`. HTML page: https://policylayer.com/tools/0800tim-aiva-mcp/shopify-get-customer

## Facts

- Tool: `shopify_get_customer`
- Server: AIVA MCP Server (`0800tim/aiva-mcp`) — https://policylayer.com/tools/0800tim-aiva-mcp.md
- Homepage: https://github.com/0800tim/aiva-mcp
- Risk category: Read (Low risk)
- Registry record: grade A, identity unverified
- Server rate-limited: no
- Parameters: 0
- Recommended policy verdict: Allowed

## Example call (MCP tools/call, JSON-RPC 2.0)

```json
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tools/call",
  "params": {
    "name": "shopify_get_customer",
    "arguments": {}
  }
}
```

## Why shopify_get_customer is rated Low

This tool retrieves customer data from Shopify without modifying, deleting, or executing operations. It is a Read operation. Severity is medium because customer details may include PII (email, address, phone, purchase history) that could be misused if an AI agent retrieves and exfiltrates data without proper authorization or context, though the tool itself performs no destructive or financial action.

From the tool's own definition: "Tool name is 'shopify_get_customer' and description states 'Get Shopify customer details.' The verb 'Get' and lack of any modification language indicate a retrieval operation with no side effects."

## Use case

AI agents call shopify_get_customer to retrieve information from AIVA MCP Server without modifying anything. It is typically the context-gathering step in research, monitoring, and reporting workflows, before the agent takes action elsewhere.

## Recommended policy (PolicyLayer)

Verdict: **Allowed**. Enforced by the PolicyLayer MCP gateway (https://policylayer.com/mcp-gateway) before a call reaches AIVA MCP Server:

```json
{
  "version": "1",
  "default": "deny",
  "tools": {
    "shopify_get_customer": {}
  }
}
```

## Other tools on AIVA MCP Server (14)

- `aiva_get_affiliate` — Read — https://policylayer.com/tools/0800tim-aiva-mcp/aiva-get-affiliate.md
- `aiva_get_churn_risk` — Read — https://policylayer.com/tools/0800tim-aiva-mcp/aiva-get-churn-risk.md
- `aiva_get_customer` — Read — https://policylayer.com/tools/0800tim-aiva-mcp/aiva-get-customer.md
- `aiva_get_delivery_schedule` — Read — https://policylayer.com/tools/0800tim-aiva-mcp/aiva-get-delivery-schedule.md
- `aiva_get_referrals` — Read — https://policylayer.com/tools/0800tim-aiva-mcp/aiva-get-referrals.md
- `aiva_get_rfm_segments` — Read — https://policylayer.com/tools/0800tim-aiva-mcp/aiva-get-rfm-segments.md
- `aiva_get_subscription` — Read — https://policylayer.com/tools/0800tim-aiva-mcp/aiva-get-subscription.md
- `aiva_list_affiliates` — Read — https://policylayer.com/tools/0800tim-aiva-mcp/aiva-list-affiliates.md
- `aiva_list_subscriptions` — Read — https://policylayer.com/tools/0800tim-aiva-mcp/aiva-list-subscriptions.md
- `aiva_search_customers` — Read — https://policylayer.com/tools/0800tim-aiva-mcp/aiva-search-customers.md
- `shopify_get_orders` — Read — https://policylayer.com/tools/0800tim-aiva-mcp/shopify-get-orders.md
- `shopify_get_product` — Read — https://policylayer.com/tools/0800tim-aiva-mcp/shopify-get-product.md
- `shopify_get_products` — Read — https://policylayer.com/tools/0800tim-aiva-mcp/shopify-get-products.md
- `aiva_subscription_actions` — Write — https://policylayer.com/tools/0800tim-aiva-mcp/aiva-subscription-actions.md

## For agents

This record is a snapshot. Live verdicts and the full registry:

- Check every server in your MCP config at once: `npx -y policylayer stack`
- Vet a server before you add it: install the mcp-precheck skill — `npx skills add https://policylayer.com` (skill text: https://policylayer.com/skill.md)
- Query the registry over MCP: endpoint `https://api.policylayer.com/mcp` — tools `check_mcp_server`, `check_mcp_stack`, `check_tool`, `search_registry`, `get_change_events`

---

Source: the PolicyLayer MCP registry — one continuously verified record per MCP server. Full record: https://policylayer.com/registry?q=0800tim-aiva-mcp · API: https://policylayer.com/registry/api · Policy library: https://policylayer.com/policies/0800tim-aiva-mcp
