Skip to main content

Create an app

To use the Shop APIs and SDKs, you need an app in the Dev Dashboard. This guide covers creating an app, configuring scopes, and retrieving your credentials.


  • Create an app in the Dev Dashboard.
  • Release a version with the appropriate scopes.
  • Retrieve your client ID and client secret.


If you don't have an app yet, then continue with Step 1.

If you already have an app in the Dev Dashboard, then you don't need to create another one. To use it with the Shop APIs and SDKs, add the shop_app:oauth scope and release a new version:

  1. Follow Step 3: Release a version and select shop_app:oauth from the Shop App scopes.
  2. Retrieve your credentials from the app's Settings page.

Anchor to Apps that use the legacy installation flowApps that use the legacy installation flow

If your app uses the legacy installation flow, then add the scope to your app configuration file instead of the Dev Dashboard, and release a new version:

shopify.app.toml

[access_scopes]
scopes = "shop_app:oauth"
use_legacy_install_flow = true

Keep use_legacy_install_flow = true so that your app stays on its current installation flow. The legacy flow passes its access scopes as a parameter on each authorization request, so it doesn't use the scopes value from your configuration file. Releasing the version creates everything that the Shop APIs need, and doesn't change anything for merchants.

shop_app:oauth isn't an Admin API access scope. It provisions your Shop client when you release a version, so keep it out of the scope parameter that your app sends, including the SCOPES environment variable that some apps build that parameter from. Authorization fails with invalid_scope if you send it.

If your app already sets scopes

Apps on the legacy installation flow usually leave scopes unset, because the flow ignores it. If your app does set it, then add shop_app:oauth to the existing list rather than replacing the list, and confirm which installation flow your app uses before you set use_legacy_install_flow. Under Shopify managed installation, merchants are prompted to grant every scope in this field, so changing it changes what they see.


Anchor to Step 1: Log in to the Dev DashboardStep 1: Log in to the Dev Dashboard

Go to the Dev Dashboard and log in with your Partner account.


Anchor to Step 2: Create an appStep 2: Create an app

  1. From the Dev Dashboard, create a new app.
  2. Enter a name and description for your app.

Anchor to Step 3: Release a versionStep 3: Release a version

After you've created your app, you need to release a version. Versions let you configure the scopes and redirect URLs for your app.

  1. In the sidebar on the left, click Versions.
  2. Click Release in the top right.
  3. Under the Access section, click the first Select scopes, then use the dropdown menu to choose Shop App.
  4. Select the scopes you need from the list. Selecting shop_app:oauth enables your app to request basic profile information from shop users.
  5. In the Redirect URLs section, add the URLs that you want to redirect back to after authentication. Only fully-qualified https URLs are supported.
  6. Click Release.

Anchor to Step 4: Retrieve your credentialsStep 4: Retrieve your credentials

After you've released a version, you can find your credentials on the app's Settings page. You'll need the following values to authenticate with Shop APIs:

  • Client ID: Used as the username for Shop Partners API Basic authentication, and as the apiKey attribute on Shop SDK components.
  • Client secret: Used as the password for Shop Partners API Basic authentication.
Keep your secret safe

Store your client secret securely. You'll need it to authenticate with the Shop Partners API.



Was this page helpful?