Required Shopify Permissions

The precise OAuth scopes StoreFulfil requires from a Shopify store.

Reference
Updated Aug 2026
Owner: Technical Support
Area: Security

Before you begin

Explain why each Shopify scope exists and how an Admin verifies that the installed app has the access StoreFulfil needs.

Prerequisites

  • The target store is identified by its permanent .myshopify.com domain.
  • A Shopify user with app development permissions can review the app version and scopes; in a merchant organisation this is the App developer role.
  • The Warehouse Admin can view Client Detail health in StoreFulfil.

Stop and check

Do not broaden permissions or recreate an app to work around an unclear failure.

Each permission is requested for a specific operational reason. Shopify can accept the app installation while a missing or revoked grant still prevents a later import, inventory refresh, or fulfilment update, so treat the connection health result as the final check.

Check before approving

  1. Confirm the permanent .myshopify.com store domain and the intended client record.
  2. Open the released Shopify app version; do not review an unpublished draft.
  3. Have a Warehouse Admin ready to check StoreFulfil connection health after installation.

Required scopes and what they allow

StateWhat it meansSafe next step
read_ordersReads Shopify order information that StoreFulfil needs to import and display fulfilment work.Confirm the app can read the intended store's current order data.
read_returnsReads Shopify's provider-native expected-return information. StoreFulfil remains the physical receipt authority and does not resolve customer refunds, exchanges, or store credit.Confirm expected-return information is visible only after the connection becomes healthy.
read_locationsReads warehouse locations so StoreFulfil can map the client to the correct operational owner.Confirm the intended warehouse location can be selected and reviewed.
read_productsReads product context needed to recognise client work accurately.Confirm the expected product context is present after a healthy sync.
read_merchant_managed_fulfillment_ordersReads the merchant-managed fulfilment work assigned to the warehouse.Use the normal order workflow; do not create fulfilment work manually.
write_merchant_managed_fulfillment_ordersRecords a permitted fulfilment result through Shopify's merchant-managed fulfilment orders API.Use only the normal shipment flow; do not attempt an unsupported manual write.
read_inventoryReads current Shopify inventory for the mapped location.Check the mapped location before interpreting local inventory.
write_inventorySupports permitted inventory changes from StoreFulfil.Verify the mapped location before an inventory action.

If the connection does not become healthy

If A required scope is not visible in the released Shopify app version.

Have a Shopify user with app development permissions add the exact scope, select Release, and repeat the approved connection path.

Owner: Shopify user with app development permissions

If The scope list is correct but StoreFulfil still reports a connection failure.

Use the visible health result to decide whether reauthorisation or connection support is needed; do not expand scopes speculatively.

Owner: Warehouse Admin

If A person asks for a new or broader permission that is not listed here.

Pause and seek an authorised product or integration decision before changing the app.

Owner: Warehouse Admin

Safe boundary

Do not broaden permissions, recreate the app, or copy a client credential into a ticket to make a connection error disappear. A healthy StoreFulfil connection and a successful sync are required before the store is ready.

Escalation evidence

  1. Permanent .myshopify.com store domain
  2. Released app version and the missing or expected scope
  3. StoreFulfil connection health result and time checked
  4. The affected capability, such as orders, inventory, or fulfilment

Expected Outcome

The released Shopify app has the exact supported scopes, StoreFulfil reports a healthy connection, and the initial sync result is visible.

Runbook evidence

Use these signals to decide whether the work is ready to continue, complete, or needs an owner.

State checkpoints

Scopes requested

StoreFulfil is asking Shopify for the access needed to read work and write fulfilment or inventory updates.

Next: Compare the requested list with the released app version before approving.

Access accepted

Shopify accepted the scopes, but StoreFulfil still needs a successful health check.

Next: Check connection health and run a client sync before treating the store as ready.

Access incomplete

A missing scope or revoked grant can stop one or more sync actions.

Next: Stop dependent work and have an Admin correct the app grant.

Completion evidence

  • The exact scopes are visible in the released app and StoreFulfil reports a healthy connection.

Escalation evidence

  • Record the store domain, missing capability, app version, and visible health result.

Work safely

Who may take this action

Warehouse Admin

What you should see

StoreFulfil is asking Shopify for the access needed to read work and write fulfilment or inventory updates.

Safe next step

Compare the requested list with the released app version before approving.

What not to do

Do not broaden permissions or recreate an app to work around an unclear failure.

How to tell it is complete

The exact scopes are visible in the released app and StoreFulfil reports a healthy connection.