Evidence-backed facts
- Shopify apps request resource-specific read scopes, and GraphQL fields document the access needed for store, customer, order, product, or other data. informative
- Write scopes authorize both write and read for a resource, so an app should request write only when mutations are required. informative
- Merchants approve declared scopes during installation, and some protected resources require additional Partner Dashboard permission before the scope can be requested. informative
- Granted scope state can change through uninstall or revocation, and authorization does not establish mutation success, payment, order acceptance, or merchant intent. informative