Documentation
Shop
shop.locations
REST
ShippingPOST /api/v1/shop/locationsMCP tool
Liveshop.locationsExposed on: REST API · Shop MCP server · Claude connector · Dash (in-app copilot) · Zapier. Part of the Shop domain.
Operating contract
Every live location the organization runs, with where each one is, its own storefront address and whether it takes bookings.
current: true MARKS THE LOCATION THIS CALL IS ACTING IN, and it is the field that prevents the most confusing possible mistake in a multi-location shop: every other capability in this registry is scoped to ONE location, and reading a number from here about a sibling and reporting it as 'the shop' is wrong.
SIBLING LOCATIONS ARE SEPARATE TENANTS. Their customers, jobs and money are not readable through this registry from here — this list is the organization's shape, not a way around the boundary.
plan_locked: true is a location that is dark because the organization's plan no longer covers it. It is not deleted and it is nobody's decision but billing's, so say so that way.
booking_enabled and storefront_url are per location. A customer looking for the shop nearest them wants the sibling's own address, not this one's.
This returns every live location in the organization, so nothing is truncated.
Who may call it
- Permission
shop.manageThe caller must hold shop.manage at the ACT level. A read-only dashboard grant on the same section is refused.- Plan
- Every planNo plan gate. Available on every Service VIN plan.
- Retries
naturalNaturally idempotent — running it twice leaves the same world as running it once. A retrying integration needs no key.- Rate class
readCounted against the read budget — the widest of the four.
Input
This capability takes no arguments.
Output
| Field | Type | Description |
|---|---|---|
| items | object[] | — |
| items[].id | string | — |
| items[].name | string | — |
| items[].slug | string | — |
| items[].locality | string | null | — |
| items[].address | string | null | — |
| items[].phone | string | null | — |
| items[].timezone | string | — |
| items[].booking_enabled | boolean | — |
| items[].storefront_url | string | null | — |
| items[].plan_locked | boolean | — |
| items[].current | boolean | — |
| total | number | — |
Examples
Built from this capability's own schema — required fields and the ones carrying a default, and nothing invented. Paste one and it validates.
export SERVICEVIN_API_KEY=svk_live_…
curl -X POST https://www.servicevin.com/api/v1/shop/locations \
-H "Authorization: Bearer $SERVICEVIN_API_KEY" \
-H "Content-Type: application/json" \
-d '{}'const res = await fetch("https://www.servicevin.com/api/v1/shop/locations", {
method: "POST",
headers: {
Authorization: `Bearer ${process.env.SERVICEVIN_API_KEY}`,
"Content-Type": "application/json",
},
body: JSON.stringify({}),
});
// Success and failure are both envelopes. Switch on error.code, never
// on error.message — the codes are stable, the messages are for people.
const payload = await res.json();
if (!res.ok) throw new Error(payload.error.code);
const data = payload.data;import os, requests
res = requests.post(
"https://www.servicevin.com/api/v1/shop/locations",
headers={"Authorization": f"Bearer {os.environ['SERVICEVIN_API_KEY']}"},
json={},
timeout=30,
)
payload = res.json()
if not res.ok:
raise RuntimeError(payload["error"]["code"])
data = payload["data"]{
"jsonrpc": "2.0",
"id": 1,
"method": "tools/call",
"params": {
"name": "shop.locations",
"arguments": {}
}
}Refusals
The four gates run in this order on every surface, and the order is not arbitrary — see Authentication.
| Status | Code | When |
|---|---|---|
| 404 | not_found | The id is unknown, or the feature is not enabled for this account. Deliberately the same answer for both. |
| 403 | forbidden | This login does not hold shop.manage. |
| 422 | validation_error | An argument was wrong. The message names the field. |
| 429 | rate_limited | Too many read calls. Back off and retry. |
| 500 | internal_error | Something failed on our side. Nothing was changed. |