What you will set up
This guide starts before OpenNeko is installed. You will create a production deployment, connect a dedicated read-only Magento analytics account, install the built-in Magento pack, and verify that the connection is healthy.
- OpenNeko and its sandboxed AI runtime on infrastructure you control.
- A SELECT-only Magento database connection for analysis, briefings, and recurring checks.
- Eight Magento operating skills covering orders, fulfillment, inventory, catalog, promotions, and store health.
- Optional governed store changes through a separate least-privilege Magento Integration token.
Before you begin
- Docker Desktop on macOS, or Docker Engine with Docker Compose on Linux.
- An API key for one supported model provider.
- Magento Open Source or Adobe Commerce 2.4.6 through 2.4.x.
- MariaDB 10.6 or newer, or MySQL 8.0 or newer.
- Permission to create a dedicated database user with SELECT-only grants.
- Network access from the OpenNeko deployment to Magento and its database.
If you plan to run bulk catalog or inventory changes later, make sure Magento's asynchronous bulk consumers are running successfully.
1. Install OpenNeko
curl -fsSL https://openneko.app/install.sh | sh
mkdir -p ~/openneko && cd ~/openneko
openneko setup --mode prodThe setup wizard checks Docker and the required ports, starts the stack, and asks for the deployment database password and model provider. You can complete the prompts in the terminal or continue in the browser at http://localhost:3000.
Keep the default internal GraphJin URL unless your deployment uses a separate GraphJin service. The Magento pack adds its governed source in the next steps.
openneko status
openneko doctor2. Prepare Magento access
Create a dedicated analytics user in MariaDB or MySQL and grant it SELECT access only to the Magento tables required by the pack. The pack README includes a starter analytics-user.sql file; narrow its host and table grants for production.
| Where Magento runs | Database host to use |
|---|---|
| Same Docker or OrbStack network | Use the Magento database service name. |
| A separate local stack | Publish the database port and use host.docker.internal with host-gateway connectivity. |
| A remote host | Use the reachable database hostname and remote connectivity. |
3. Install the Magento pack
openneko pack install magentoThe installer asks for the Magento URL, database address and name, and the dedicated analytics username and password. Password input is hidden and the credential is saved in OpenNeko's local secret store.
OpenNeko discovers the database engine, table prefix, currency, timezone, and active store IDs. When installation finishes, it queues the first metric refresh.
4. Verify the connection
openneko pack status magento
openneko pack doctor magento
openneko pack manage magento- The Magento URL is reachable from the OpenNeko worker.
- The database account can read the required tables and cannot write to them.
- Magento and store configuration were discovered.
- The GraphJin catalog and installed operating skills are ready.
An analytics-only installation is healthy. Write-capable domains appear as view-only until you deliberately configure their token and access.
5. Put the read-only connection to work
Start with questions whose answers can be checked directly against Magento:
- Which paid or invoiced orders have waited more than 24 hours to ship?
- Which low-stock SKUs appear in currently unfulfilled orders?
- Did refunds or cancellations rise in a particular store, product, or time period?
- Are cron, indexers, and recent-order data healthy enough to trust today's briefing?
Turn a useful question into a watcher when the same condition should be checked repeatedly.
6. Add governed changes when ready
Create a Magento Integration with only the resources needed for the domains you intend to enable. Store its token separately, then apply it to the pack.
openneko secrets set pack.magento MAGENTO_INTEGRATION_TOKEN
openneko pack configure magento --integration-token-ref MAGENTO_INTEGRATION_TOKEN
openneko pack doctor magentoEnable catalog, inventory, orders, promotions, content, or customer access separately. A missing permission leaves that domain view-only without breaking the rest of the pack.