enterprise-application-connectors · prepared

Shopify Admin GraphQL API connector boundary

Official-source merchant authorization, read/write access-scope, GraphQL field/mutation, protected-data, and revocation boundaries for Shopify connectors.

version 1.0.0freshness currentobserved 2026-08-27T01:30:00Z

resource.connector.shopify-admin-graphql-api
sha256:ad9e743440f942787340559ec32c9e2bf91542c6265cfead4b10cc056365629b

Open canonical machine JSON →

Evidence-backed facts

  1. Shopify apps request resource-specific read scopes, and GraphQL fields document the access needed for store, customer, order, product, or other data. informative
  2. Write scopes authorize both write and read for a resource, so an app should request write only when mutations are required. informative
  3. Merchants approve declared scopes during installation, and some protected resources require additional Partner Dashboard permission before the scope can be requested. informative
  4. Granted scope state can change through uninstall or revocation, and authorization does not establish mutation success, payment, order acceptance, or merchant intent. informative