Shopify agents that handle the orders that need a person

Create a small app from your store's admin and paste its client ID and secret. Qoren registers the webhooks, wakes an agent on orders, refunds, customers and products, and lets it look up, note and tag orders.

Request early accessSee pricing

Integrations is in early access: Qoren is turning it on account by account. Already have access? Open Integrations

How do I connect Shopify to an AI agent?

In your store's Shopify admin, open Settings > Apps > Develop apps and build an app in the Dev Dashboard with read scopes such as read_orders. Install it on the store and paste the store address, client ID and client secret in Qoren. Qoren signs in with them and refreshes access itself. Cancelling or refunding an order always waits for a person's approval.

What agents do with Shopify

Example jobs, each built only from the events and tools listed further down. Write the agent's rules in plain words; these are starting points, not presets.

For agencies running it for clients

  • Flag the orders that need a look

    When an order is placed, the agent reads it and tags the unusual ones, such as a large order or one shipping abroad, with needs-review and a note on why.

    Wakes on
    Order placed
    Uses
    Read an order
    Tag an order
    Add an order note
  • Refund requests, prepared for the client

    When a customer asks for a refund, the agent finds the order, checks what was paid and prepares the refund, which waits for the client's approval.

    Uses
    Find an order
    Read an order
    Refund an order

For founders running it for themselves

  • "Where is my order?" answered

    When a customer emails the agent's mailbox with an order number, it looks the order up and answers with its payment and fulfillment status.

    Uses
    Find an order
    Read an order
  • Follow up on checkouts that stall

    When a shopper starts a checkout, the agent checks later whether the order was placed and, if not, drafts a follow-up. Shopify has no abandoned checkout event, so this is how it is done.

    Wakes on
    Checkout started
    Uses
    Find an order
    List a customer's orders

The path one event takes

8 Shopify events that can wake an agent

Pick one on an agent's Triggers tab. Each event can arrive on its own, as a digest, or as the latest state of a record, and events that do not match your conditions are logged as Filtered, with no turn and no charge.

EventWhen it fires
Order placedA new order is created, online or in the admin.
Order paidAn order's payment is captured in full.
Order cancelledAn order is cancelled.
Order fulfilledEvery item of an order has shipped.
Refund issuedA refund is created on an order.
Customer createdA new customer account or record is created.
Checkout startedA shopper starts a checkout. Shopify has no event for an abandoned checkout: to follow up on one, have the agent check later whether the order was placed.
Product updatedA product changes: title, price, a variant, or its stock.

8 tools agents can use

Curated Shopify tools, not a raw API: each returns only the fields the job needs. A read only grant never gets a write tool, and tools marked Always asks wait for a person's approval whatever the agent's autonomy setting.

ToolWhat it doesAccessApproval
Find an orderFind Shopify orders by order number (for example #1042) or by the customer's email. Returns number, date, totals, payment and fulfillment status.ReadNone
Find a customerFind Shopify customers by email or name. Returns id, name, email, number of orders and amount spent.ReadNone
Read an orderRead one Shopify order: items, totals, payment and fulfillment status, note, tags and where it ships (city and country).ReadNone
List a customer's ordersList one customer's orders, newest first, at most 20.ReadNone
Add an order noteAdd a line to a Shopify order's staff note (it is appended, never replaced).WritePer autonomy setting
Tag an orderAdd tags to a Shopify order, for example needs-review. Existing tags stay.WritePer autonomy setting
Cancel an orderCancel a Shopify order, optionally refunding it to the original payment method and restocking. Always asks a person to approve first.WriteAlways asks
Refund an orderRefund an amount of a paid Shopify order to its original payment. Always asks a person to approve first.WriteAlways asks

How connecting Shopify works

  1. 01Make a Shopify key with the least access it needs, following the guide below. Only the account owner can connect a tool.
  2. 02Paste it in Qoren. Qoren checks it before saving: which account it belongs to, what it can do and, where Shopify says, when it expires.
  3. 03Give an agent access, read only or read and write. An agent cannot use a tool it was not given.
  4. 04Pick the events that should wake the agent. Qoren registers the Shopify webhook itself, so there is no URL or signing secret to copy.

Making the Shopify key

  1. 1

    Make the app from THIS store's admin

    Shopify only lets an app sign in this way to stores in the app's own organization. So start from the store you are connecting: in its Shopify admin, open Settings > Apps > Develop apps, choose Build apps in Dev Dashboard, then Create app. Name it Qoren.

  2. 2

    Give it the least scopes

    In the app's version, add read scopes for what your agents should see and wake on, for example read_orders, read_customers and read_products. Add write_orders only if agents should add notes and tags or (always with your approval) cancel and refund orders. Release the version.

  3. 3

    Install it on your store

    Install the app on this store from the Dev Dashboard.

  4. 4

    Paste the store address, client ID and client secret here

    Copy the Client ID and Client secret from the app's settings and paste them here with your store's myshopify.com address. Qoren signs in with them and refreshes its access itself. If you have an older custom app, paste its shpat_ access token and its API secret key (in the Client secret field: Shopify signs events with it). Never send these by email or chat.

Shopify setup guide, with screenshots

Connecting a client's account? Send a link

An agency does not need its client's key. Send a connect link instead: it shows your agency's name and the exact permissions to tick, works once, expires after 7 days and can be revoked. The client pastes the key on that page, Qoren encrypts it on arrival, and you only ever see its last four characters. A client's connection is used only by that client's agents. Connect links come with Clients, on the Ultimate, Business and Enterprise plans.

Client connect links

Security in plain words

  • Keys never reach the agent's machine

    The Shopify key is encrypted at rest with AES-256-GCM and used only inside Qoren's own calls to Shopify. It is never written to the agent's environment, and after you connect only its last four characters are shown.

  • Read only until you say otherwise

    Each agent gets read only or read and write access, granted one agent at a time. The Shopify key itself can be limited too, and the guide asks for the least it needs.

  • Risky actions always ask

    In Shopify, these always wait for a person's approval, whatever the agent's autonomy setting: cancel an order and refund an order.

  • Capped reads and a full audit log

    By default an agent reads at most 500 records an hour from one connection. Every call, read or write, lands in the audit log with the agent, the tool and the record ids.

  • Event data is treated as data

    Events reach the agent fenced off as data, with a warning not to follow instructions inside them. For 30 minutes after an agent reads connected data, a Qoren tool that would send it outside your account waits for your approval.

  • Stored events expire

    Qoren keeps event bodies for 7 days on Starter, 30 on Pro, 90 on Ultimate and 180 on Business, then removes them and keeps only the metadata.

Shopify limits worth knowing

When you disconnect, Qoren cannot revoke the key at Shopify, so it tells you where to delete it. In Shopify admin, open Settings > Apps, uninstall the Qoren app, and delete it in the Dev Dashboard (or rotate its client secret).

  • Shopify only lets an app sign in this way to stores in the app's own organization, so create the app from the admin of the store you are connecting.
  • Shopify has no event for an abandoned checkout. Use Checkout started and have the agent check later.
  • Qoren refreshes Shopify's 24 hour access tokens itself. Older custom apps with an shpat_ token also work.
  • Shopify deletes a webhook after repeated failed deliveries. Qoren's daily check creates it again.

Frequently asked questions

Why must the app be made from my store's admin?

Shopify only lets an app use this sign-in to stores in the app's own organization. Starting from the store's admin, under Settings > Apps > Develop apps, keeps the app and the store together.

I have an older custom app. Can I use it?

Yes. Paste its shpat_ Admin API access token and its API secret key, which Shopify uses to sign events. Shopify stopped creating these apps, but existing ones keep working.

Does my agent ever see the Shopify key?

No. Qoren encrypts the key as soon as it arrives and uses it only inside its own calls to Shopify. The key never reaches the agent's machine, is never shown again after you connect, and the agent only gets the results of the tools you allowed.

Can an agent cancel an order without asking?

No. In Shopify, these tools always wait for a person's approval, whatever the agent's autonomy setting: cancel an order and refund an order. The approval shows the exact details the agent wants to send.

Approvals
What happens when I disconnect Shopify?

Qoren deletes the webhooks it registered, deletes the stored key, pauses the triggers that used it and removes stored event bodies. It cannot revoke a key at Shopify, so it shows you where to delete it: In Shopify admin, open Settings > Apps, uninstall the Qoren app, and delete it in the Dev Dashboard (or rotate its client secret).

What does the Shopify integration cost?

Connecting tools comes with every Qoren plan, with no limit on connections, once Integrations is on for your account. It is in early access for now, turned on account by account. An event that wakes an agent uses credits like any other agent turn, and each trigger has an hourly cap.

Qoren pricing

Connect Shopify once. Let agents handle the rest.

Integrations is in early access, turned on account by account. Request it and tell us how your agents should use Shopify.