Create an app
To use the Shop APIs and SDKs, you need an app in the Dev Dashboard. This guide covers creating an app, configuring scopes, and retrieving your credentials.
Anchor to What you'll learnWhat you'll learn
- Create an app in the Dev Dashboard.
- Release a version with the appropriate scopes.
- Retrieve your client ID and client secret.
Anchor to RequirementsRequirements
- A Shopify Partner account
Anchor to Use an existing appUse an existing app
If you don't have an app yet, then continue with Step 1.
If you already have an app in the Dev Dashboard, then you don't need to create another one. To use it with the Shop APIs and SDKs, add the shop_app:oauth scope and release a new version:
- Follow Step 3: Release a version and select
shop_app:oauthfrom the Shop App scopes. - Retrieve your credentials from the app's Settings page.
Anchor to Apps that use the legacy installation flowApps that use the legacy installation flow
If your app uses the legacy installation flow, then add the scope to your app configuration file instead of the Dev Dashboard, and release a new version:
shopify.app.toml
Keep use_legacy_install_flow = true so that your app stays on its current installation flow. The legacy flow passes its access scopes as a parameter on each authorization request, so it doesn't use the scopes value from your configuration file. Releasing the version creates everything that the Shop APIs need, and doesn't change anything for merchants.
shop_app:oauth isn't an Admin API access scope. It provisions your Shop client when you release a version, so keep it out of the scope parameter that your app sends, including the SCOPES environment variable that some apps build that parameter from. Authorization fails with invalid_scope if you send it.
Apps on the legacy installation flow usually leave scopes unset, because the flow ignores it. If your app does set it, then add shop_app:oauth to the existing list rather than replacing the list, and confirm which installation flow your app uses before you set use_legacy_install_flow. Under Shopify managed installation, merchants are prompted to grant every scope in this field, so changing it changes what they see.
Apps on the legacy installation flow usually leave scopes unset, because the flow ignores it. If your app does set it, then add shop_app:oauth to the existing list rather than replacing the list, and confirm which installation flow your app uses before you set use_legacy_install_flow. Under Shopify managed installation, merchants are prompted to grant every scope in this field, so changing it changes what they see.
Anchor to Step 1: Log in to the Dev DashboardStep 1: Log in to the Dev Dashboard
Go to the Dev Dashboard and log in with your Partner account.
Anchor to Step 2: Create an appStep 2: Create an app
- From the Dev Dashboard, create a new app.
- Enter a name and description for your app.
Anchor to Step 3: Release a versionStep 3: Release a version
After you've created your app, you need to release a version. Versions let you configure the scopes and redirect URLs for your app.
- In the sidebar on the left, click Versions.
- Click Release in the top right.
- Under the Access section, click the first Select scopes, then use the dropdown menu to choose Shop App.
- Select the scopes you need from the list. Selecting
shop_app:oauthenables your app to request basic profile information from shop users. - In the Redirect URLs section, add the URLs that you want to redirect back to after authentication. Only fully-qualified
httpsURLs are supported. - Click Release.
Anchor to Step 4: Retrieve your credentialsStep 4: Retrieve your credentials
After you've released a version, you can find your credentials on the app's Settings page. You'll need the following values to authenticate with Shop APIs:
- Client ID: Used as the username for Shop Partners API Basic authentication, and as the
apiKeyattribute on Shop SDK components. - Client secret: Used as the password for Shop Partners API Basic authentication.
Store your client secret securely. You'll need it to authenticate with the Shop Partners API.
Store your client secret securely. You'll need it to authenticate with the Shop Partners API.
Anchor to Next stepsNext steps
- Set up the Shop SDK on your storefront.
- Sign in with Shop using the Shop SDK
loginfeature and OpenID Connect. - Sign in with a third-party identity provider using OpenID Connect.
- Get Shop user information by exchanging a Sign in with Shop consent token for a user access token.
- Capture leads on your storefront and collect email addresses from Shop users.
- Store metafields on Shop users and read them from Shopify Functions and Checkout UI extensions.