Each permission is requested for a specific operational reason. Shopify can accept the app installation while a missing or revoked grant still prevents a later import, inventory refresh, or fulfilment update, so treat the connection health result as the final check.
Check before approving
- Confirm the permanent .myshopify.com store domain and the intended client record.
- Open the released Shopify app version; do not review an unpublished draft.
- Have a Warehouse Admin ready to check StoreFulfil connection health after installation.
Required scopes and what they allow
| State | What it means | Safe next step |
|---|---|---|
| read_orders | Reads Shopify order information that StoreFulfil needs to import and display fulfilment work. | Confirm the app can read the intended store's current order data. |
| read_returns | Reads Shopify's provider-native expected-return information. StoreFulfil remains the physical receipt authority and does not resolve customer refunds, exchanges, or store credit. | Confirm expected-return information is visible only after the connection becomes healthy. |
| write_returns | Records a permitted Shopify-native return disposition after StoreFulfil has completed its warehouse-side verification. It does not approve returns, issue refunds, exchanges or store credit. | Use only the verified return workflow; do not treat this permission as authority to change the customer-side return. |
| read_locations | Reads warehouse locations so StoreFulfil can map the client to the correct operational owner. | Confirm the intended warehouse location can be selected and reviewed. |
| read_products | Reads product context needed to recognise client work accurately. | Confirm the expected product context is present after a healthy sync. |
| read_merchant_managed_fulfillment_orders | Reads the merchant-managed fulfilment work assigned to the warehouse. | Use the normal order workflow; do not create fulfilment work manually. |
| write_merchant_managed_fulfillment_orders | Records a permitted fulfilment result through Shopify's merchant-managed fulfilment orders API. | Use only the normal shipment flow; do not attempt an unsupported manual write. |
| read_inventory | Reads current Shopify inventory for the mapped location. | Check the mapped location before interpreting local inventory. |
| write_inventory | Supports permitted inventory changes from StoreFulfil. | Verify the mapped location before an inventory action. |
If the connection does not become healthy
If A required scope is not visible in the released Shopify app version.
Have a Shopify user with app development permissions add the exact scope, select Release, and repeat the approved connection path.
Owner: Shopify user with app development permissions
If The scope list is correct but StoreFulfil still reports a connection failure.
Use the visible health result to decide whether reauthorisation or connection support is needed; do not expand scopes speculatively.
Owner: Warehouse Admin
If A person asks for a new or broader permission that is not listed here.
Pause and seek an authorised product or integration decision before changing the app.
Owner: Warehouse Admin
Safe boundary
Escalation evidence
- Permanent .myshopify.com store domain
- Released app version and the missing or expected scope
- StoreFulfil connection health result and time checked
- The affected capability, such as orders, inventory, or fulfilment
What this is and when to use it
Use this Admin reference when approving or checking Shopify access for a connected store. It explains the exact supported access without asking for broader permissions.
Check the released access
- Open the released Shopify app version and compare its requested scopes with the list in this guide.
- Confirm the store domain and intended client before approving.
- After approval, check StoreFulfil connection health and run one client sync.
- Treat the store as ready only when the health and sync results are visible.
Questions and hand-off
If A scope is missing
Have the Shopify App developer add the exact supported scope, release it, and repeat the approved connection path.
If All scopes are present but health still fails
Stop dependent work and give the store domain, app version, and displayed health result to the Warehouse Admin or support owner.
If Someone asks for an unlisted permission
Do not add it as a workaround; pause for an authorised integration decision.
What StoreFulfil handles
StoreFulfil checks the connected grant and reports the health and sync result. It does not approve Shopify permissions or issue customer refunds.