Each permission is requested for a specific operational reason. Shopify can accept the app installation while a missing or revoked grant still prevents a later import, inventory refresh, or fulfilment update, so treat the connection health result as the final check.
Check before approving
- Confirm the permanent .myshopify.com store domain and the intended client record.
- Open the released Shopify app version; do not review an unpublished draft.
- Have a Warehouse Admin ready to check StoreFulfil connection health after installation.
Required scopes and what they allow
| State | What it means | Safe next step |
|---|---|---|
| read_orders | Reads Shopify order information that StoreFulfil needs to import and display fulfilment work. | Confirm the app can read the intended store's current order data. |
| read_returns | Reads Shopify's provider-native expected-return information. StoreFulfil remains the physical receipt authority and does not resolve customer refunds, exchanges, or store credit. | Confirm expected-return information is visible only after the connection becomes healthy. |
| read_locations | Reads warehouse locations so StoreFulfil can map the client to the correct operational owner. | Confirm the intended warehouse location can be selected and reviewed. |
| read_products | Reads product context needed to recognise client work accurately. | Confirm the expected product context is present after a healthy sync. |
| read_merchant_managed_fulfillment_orders | Reads the merchant-managed fulfilment work assigned to the warehouse. | Use the normal order workflow; do not create fulfilment work manually. |
| write_merchant_managed_fulfillment_orders | Records a permitted fulfilment result through Shopify's merchant-managed fulfilment orders API. | Use only the normal shipment flow; do not attempt an unsupported manual write. |
| read_inventory | Reads current Shopify inventory for the mapped location. | Check the mapped location before interpreting local inventory. |
| write_inventory | Supports permitted inventory changes from StoreFulfil. | Verify the mapped location before an inventory action. |
If the connection does not become healthy
If A required scope is not visible in the released Shopify app version.
Have a Shopify user with app development permissions add the exact scope, select Release, and repeat the approved connection path.
Owner: Shopify user with app development permissions
If The scope list is correct but StoreFulfil still reports a connection failure.
Use the visible health result to decide whether reauthorisation or connection support is needed; do not expand scopes speculatively.
Owner: Warehouse Admin
If A person asks for a new or broader permission that is not listed here.
Pause and seek an authorised product or integration decision before changing the app.
Owner: Warehouse Admin
Safe boundary
Escalation evidence
- Permanent .myshopify.com store domain
- Released app version and the missing or expected scope
- StoreFulfil connection health result and time checked
- The affected capability, such as orders, inventory, or fulfilment