A Shopify connection reaches your store through a custom app you make in your own Shopify admin. Bizomate keeps the app's Admin API access token, and its API secret key if you add it, and calls your store's own address with them.

Who can do this

Workspace Admins and Editors, on any plan — Shopify is not a premium connection. Viewers see the connection but cannot add or change it.

On Shopify's side, the store owner, or a staff member allowed to develop apps.

Before you start

  • A custom app made in the Shopify admin. The connection takes the app's Admin API access token (it starts shpat_). Shopify stopped letting stores create new custom apps in the admin on 1 January 2026; a store that already has one can use it. An app made in Shopify's Dev Dashboard shows a Client ID and Client secret instead of a token, and this connection does not take those.
  • Your store's Shopify address — the part before .myshopify.com, such as northwind-store. Your own domain will not do; Shopify admin shows the .myshopify.com address under Settings › Domains.

Steps

In Shopify, get the token:

  1. Sign in to your Shopify admin and select Settings, then Apps, then Develop apps.

  2. Select your custom app. If Shopify still offers Create an app for your store, you can make one: give it a name such as Bizomate, and select Create app.

  3. On the app's Configuration tab, beside Admin API integration, select Configure (or Edit).

  4. Tick these permissions — the dialog in Bizomate lists them too:

    Area Tick
    Products write_products and read_products
    Orders write_orders and read_orders
    Customers write_customers and read_customers
    Inventory write_inventory and read_inventory
    Discounts write_discounts and read_discounts
  5. Select Save.

  6. On the API credentials tab, select Install app if the app is not installed yet, then Install.

  7. Under Admin API access token, select Reveal token once and copy it. Shopify shows it only once — keep it somewhere safe until you have pasted it.

  8. On the same tab, under API key and secret key, copy the API secret key. You need it for Shopify triggers.

In Bizomate, add the connection:

  1. Select Connections in the bar at the top, then + Add connection.
  2. Under Commerce, select Shopify. It reads "Stored credential".
  3. In Connection name, type a name — for example Northwind store.
  4. Read the note at the top: Permissions to tick — when you create the app in Shopify, tick read and write for products, orders, customers, inventory and discounts. The test says which are missing.
  5. In Store address, type the part before .myshopify.com — northwind-store. The box ends in .myshopify.com already. Pasting the whole address, such as https://northwind-store.myshopify.com/admin, works too.
  6. Paste the token in Admin API access token. It is hidden as you type.
  7. Paste the secret in API secret key (optional). Leave it empty only if you will never use a Shopify trigger.
  8. Leave Test the connection before saving ticked. Bizomate asks Shopify for the store before keeping the details.
  9. Select Save connection. The button reads Testing, then the dialog closes.

The toast "Connection added" says "“Northwind store” is ready. Every workflow in this workspace can use it."

Then check the permissions:

  1. Select the connection's row to open its panel, and select Test.
  2. The toast "“Northwind store” works" says what Bizomate reached — for example Reached Northwind Store (northwind-store.myshopify.com) · Shopify plan Basic · 10 of 10 permissions.
  3. If it ends Missing: …, see Missing permissions below.

What happens next

  • Shopify steps list it under Connection: products, inventory, orders, fulfilment, customers and discount codes.
  • Shopify triggers can use it: six events that start a run the moment they happen, and Inventory low, which checks every 5 or 15 minutes.
  • Every call goes to your store's own address, https://northwind-store.myshopify.com, on Shopify's Admin API version 2025-07.

Missing permissions

Test counts the ten permissions the steps use. A missing one does not stop the connection saving — it reads, for example:

Reached Northwind Store (northwind-store.myshopify.com) · Shopify plan Basic · 9 of 10 permissions. Missing: write_discounts. Steps that need them will say so; add them to the app in Shopify and press Test again.

To add it:

  1. In Shopify admin, open the app under Settings › Apps › Develop apps.
  2. On Configuration, select Configure beside Admin API integration, tick what is missing, and select Save.
  3. If Shopify asks, update or reinstall the app so the change takes effect.
  4. In Bizomate, select Test on the connection again.

A write permission brings its read one: with write_products ticked, read_products is not counted as missing.

Good to know

  • The API secret key is for triggers. Shopify signs every event it sends with it, and Bizomate checks each one. Without it, publishing a workflow with a Shopify trigger fails — see Start a workflow from Shopify store events. Steps work without it.
  • To add the API secret key later, or after a new token: open the connection's panel, select Revoke and Revoke connection, then Reconnect, fill in every field again and select Reconnect. With Test the connection before saving ticked, Reconnect tries the details first and changes nothing if Shopify refuses them.
  • Uninstalling the app in Shopify ends the token. Every Shopify step then fails until you reconnect with a new one.
  • Shopify's own limits apply — about two calls a second for each app. A workflow that changes many products one after another may meet them; see the table below.

If something goes wrong

What you see Why What to do
"Fill in Store address." / "Fill in Admin API access token." A box is empty. Fill it in.
Shopify refused it — "Store address “…” is not a Shopify store's address — it is the part before .myshopify.com. Nothing was saved." The address has spaces or other characters, or is your own domain. Type only the .myshopify.com name, such as northwind-store.
Shopify refused it — "Shopify refused: [API] Invalid API key or access token (unrecognized login or wrong password). Check the connection's details on Connections. Nothing was saved." The token is wrong, or the app was uninstalled. Copy the Admin API access token again — if it can no longer be revealed, reinstall the app for a new one.
Shopify refused it — "Shopify refused: Not Found. Nothing was saved." No store has that address. Check the address under Settings › Domains in Shopify admin.
Missing: … after Test The app does not have every permission. See Missing permissions above.
"Shopify refused: … Check the connection's details on Connections." in a run, naming a permission The step needs a permission the app does not have. Tick it on the app's Configuration tab, save, then run the step again.
"Shopify refused: Exceeded 2 calls per second for api client. …" Too many calls to the store at once. Run the step again. In a loop, add a Wait between items.
"Could not reach Shopify: …" or "Shopify did not answer within 30 seconds." Shopify could not be reached. Try again in a few minutes.