Connect a Shopify store to Qoren
Connect your Shopify store with a Dev Dashboard app so agents wake on orders, refunds and customers, and can look up and tag orders. Refunds always ask.
On this page
Connect your Shopify store once and your agents can wake when an order is placed, paid, cancelled, fulfilled or refunded, when a customer signs up, when a checkout starts or when a product changes. Qoren subscribes to those events in Shopify itself, so there is no webhook URL to copy. Agents you give access to can also find orders and customers, add notes and tags to orders, and propose cancellations and refunds for you to approve.
Shopify does not hand out a plain API key for this. Instead you make a small app for your store in Shopify's Dev Dashboard and paste its client ID and client secret. Qoren keeps them encrypted and never sends them to an agent. For how connections work in general, see connect your tools with Integrations.
Before you start#
- You are the owner of your Qoren organization. Only the owner connects tools, gives agents access and disconnects.
- You can use the store's Shopify admin, including Settings, Apps and the Dev Dashboard.
- An older custom app works too. If your store already has a custom app made in the admin before Shopify stopped allowing new ones (from January 1, 2026), you can paste its Admin API access token, which starts with
shpat_, and its API secret key instead. - Integrations is on for your account. It is still rolling out: if your sidebar has no Integrations under Capabilities, it is not on your account yet.
Make the app#
- In the store's Shopify admin, open Settings, then Apps, then Develop apps, choose Build apps in Dev Dashboard, then Create app. Name it Qoren.
- In the app's version, add read scopes for what your agents should see and wake on. Each event needs its own:
read_ordersfor orders, refunds and checkouts,read_customersfor customers andread_productsfor products. - Add
write_ordersonly if agents should add notes and tags to orders, or propose cancellations and refunds (those always wait for your approval). Then release the version. - Install the app on this store from the Dev Dashboard.
- In the app's settings, copy the Client ID and the Client secret.
Connect it in Qoren#
- In the sidebar, under Capabilities, click Integrations.
- Under Add a tool, click Shopify. The Connect Shopify dialog shows the same steps as above.
- If your account works for clients, choose who it is for under Which client is this for?. A client's connection can only be used by that client's agents.
- In Store address, enter the store's myshopify.com address, for example
your-store.myshopify.com. The store name alone, or a link to its admin, works too. - Paste the Client ID and the Client secret. For an older custom app, leave Client ID empty, paste the
shpat_token into Admin API access token (older custom apps only), and paste the app's API secret key into Client secret: Shopify signs its events with it. - Click Check key. Key checked shows the store's name, whether the app can read and write, and a note that Qoren refreshes its access itself.
- Under What agents may do, choose Read only or Read and write.
- Click Connect.
Screenshots of the dialog are in connect a tool.
What Qoren checks#
- The store address. It must be a myshopify.com address. Qoren never calls any other address you type.
- That the app may sign in to this store. With a client ID and secret, Qoren signs in the way Shopify allows apps in the same organization to. If Shopify says the store is not permitted, the check explains that the app has to be made from this store's admin. Wrong credentials are refused. With an older custom app, the token must start with
shpat_. - The store and the app's scopes, in one read: the store's name, the scopes the app was granted (read when it has any
read_scope, write when it has anywrite_scope) and how many webhook subscriptions the app already has. If it has some, the check says Qoren adds its own and never changes them.
Whether the app has the scope a particular event needs is checked when you add a trigger for it, with a message naming the missing scope.
Give an agent access#
No agent can use the connection until you give it access. Open the connection under Connected, pick the agent in Give access to…, choose its level and click Give access. See give an agent access.
Events#
| Event | What it means |
|---|---|
Order placed (orders/create) | A new order is created, online or in the admin. |
Order paid (orders/paid) | An order's payment is captured in full. |
Order cancelled (orders/cancelled) | An order is cancelled. |
Order fulfilled (orders/fulfilled) | Every item of an order has shipped. |
Refund issued (refunds/create) | A refund is created on an order. |
Customer created (customers/create) | A new customer account or record is created. |
Checkout started (checkouts/create) | A shopper starts a checkout. |
Product updated (products/update) | A product changes: title, price, a variant, or its stock. |
Shopify has no event for an abandoned checkout. To follow up on one, have the agent wake on Checkout started and check later whether the order was placed.
To have one of these wake an agent, open the agent's Triggers tab and add it under From your connected tools. See wake an agent from a connected tool. Checkouts and product updates can be busy, since every stock change counts, so a digest suits them. When you pick an event, Qoren estimates how often it happens from your store's counts for the last 30 days.
How the subscriptions are set up. Qoren creates one Shopify webhook subscription per event, the first time a trigger needs it, and triggers on the same event share it. Shopify signs every delivery with the app's client secret, and Qoren checks each one with it. Each delivery only reaches the triggers for the event its subscription is for.
What the agent receives. The event and the order, refund, customer, checkout or product, trimmed to the fields an agent needs. For orders that means the items, totals, payment and fulfillment status, note and tags, and where it ships as city and country only. It is labelled as data from outside; see how events reach the agent.
Tools agents can use#
| Tool | What it does | Changes records | Always asks |
|---|---|---|---|
| Find an order | Find orders by order number (for example #1042) or by the customer's email. | No | No |
| Find a customer | Find customers by email or name: name, email, number of orders and amount spent. | No | No |
| Read an order | Read one order: items, totals, payment and fulfillment status, note, tags and where it ships (city and country). | No | No |
| List a customer's orders | List one customer's orders, newest first, at most 20. | No | No |
| Add an order note | Add a line to an order's staff note. It is appended, never replaced. | Yes | No |
| Tag an order | Add tags to an order, for example needs-review. Existing tags stay. | Yes | No |
| Cancel an order | Cancel an order, optionally refunding it and restocking the items. | Yes | Yes |
| Refund an order | Refund an amount of a paid order to its original payment. | Yes | Yes |
Notes and tags only label an order for your staff: nothing is sent to the customer, and no money or stock moves. They still follow the agent's autonomy, so an agent that asks first on its work proposes them too. If automations in your store act on tags, give agents Read only. Cancelling and refunding always wait on the Approvals page with the exact order, amount and options. See how Qoren keeps connected tools safe.
Limits and gotchas#
- Same organization only. The client ID and secret only work for a store in the app's own Shopify organization. Make the app from the store's own admin, or use an older custom app's token.
- Access refreshes itself. Shopify's access from an app's credentials lasts 24 hours. Qoren signs in again shortly before it lapses, and again if Shopify refuses it, so you never paste anything new for that.
- Removed subscriptions. Shopify retries a failed delivery up to eight times over four hours, then removes the subscription. Qoren's daily check creates it again.
- A rotated client secret. If you rotate the app's client secret in the Dev Dashboard, use Replace key in Qoren with the new one. The daily check then checks events with the new secret too. Shopify can take up to an hour to start signing with it.
- Customer details may be hidden. Order and customer events count as protected customer data in Shopify. Depending on your plan and the app's settings, Shopify may leave out fields such as names, addresses, phone numbers or emails.
- An older custom app needs its secret for triggers. With only the
shpat_token, agents can use the tools, but adding a trigger fails until you replace the key with the app's API secret key in Client secret.
Troubleshooting#
- "Shopify only lets an app connect this way to stores in the app's own organization." The app was made outside this store's organization. Create it again from this store's admin (Settings, Apps, Develop apps).
- "Enter the store's myshopify.com address." Use the store's address ending in myshopify.com, not its custom domain.
- "Shopify did not accept this key." The client ID or secret is wrong, or the app is not installed on this store.
- Adding a trigger names a missing scope. Add that scope to the app's version in the Dev Dashboard, release it, approve it in the store, then add the trigger again.
- The connection says Needs a new key or Needs attention. Its triggers are paused and you got an email. Replace the key, or fix the app and click Check again. See when a connected tool stops working.
Disconnect and delete the app#
- Open the connection under Connected and click Disconnect.
- In Disconnect Shopify?, click Disconnect (or Keep it to back out).
Qoren deletes the stored credentials, removes the webhook subscriptions it created, removes every agent's access and pauses the triggers that used Shopify. It cannot revoke the app's access at Shopify, so do that too: in the Shopify admin, open Settings, Apps, uninstall the Qoren app, and delete it in the Dev Dashboard, or at least rotate its client secret.
Frequently asked questions#
Why can't I just paste an access token?
Shopify no longer lets stores create the older custom apps that hand out a token. The current way is an app whose client ID and secret Qoren uses to sign in, refreshing its access every day. If you already have an older custom app, its shpat_ token still works.
Can an agent refund or cancel an order on its own?
No. Both always wait for a person on the Approvals page, whatever the agent's settings or the connection's level.
Is there an event for abandoned checkouts?
Shopify has none. Wake the agent on Checkout started and have it check later whether an order was placed.
Will Qoren touch my other Shopify apps or webhooks?
No. It only creates subscriptions for its own app and never changes ones it did not create.