| name | shopify-security-basics |
| description | Apply Shopify security best practices for API credentials, webhook HMAC validation,
and access scope management.
Use when securing API keys, validating webhook signatures,
or auditing Shopify security configuration.
Trigger with phrases like "shopify security", "shopify secrets",
"secure shopify", "shopify HMAC", "shopify webhook verify".
|
| allowed-tools | Read, Write, Grep |
| version | 2.7.0 |
| license | MIT |
| author | Jeremy Longshore <jeremy@intentsolutions.io> |
| tags | ["saas","ecommerce","shopify"] |
| compatibility | Designed for Claude Code |
Shopify Security Basics
Overview
Security essentials for Shopify apps: credential management, webhook HMAC validation, request verification, and least-privilege access scopes.
Prerequisites
- Shopify Partner account with app credentials
- Understanding of HMAC-SHA256 signatures
- Access to Shopify app configuration
Instructions
Step 1: Secure Credential Storage
SHOPIFY_API_KEY=your_api_key
SHOPIFY_API_SECRET=your_api_secret_key
SHOPIFY_ACCESS_TOKEN=shpat_xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
.env
.env.local
.env.*.local
*.pem
Token format reference:
| Token Type | Prefix | Length | Used For |
|---|
| Admin API access token | shpat_ | 38 chars | Server-side Admin API |
| Storefront API token | varies | varies | Client-safe storefront queries |
| API secret key | none | 32+ hex | Webhook HMAC, OAuth |
Step 2: Webhook HMAC Verification
Shopify signs every webhook with your app's API secret using HMAC-SHA256. The signature is in the X-Shopify-Hmac-Sha256 header. Use crypto.timingSafeEqual for comparison to prevent timing attacks. The middleware must use raw body parser (not JSON parser).
See Webhook HMAC Verification for the complete implementation.
Step 3: OAuth Request Verification
Verify that incoming OAuth requests from Shopify are authentic by checking the HMAC query parameter. The library handles this automatically, but the manual approach sorts params alphabetically, creates a query string, and compares HMAC hex digests.
See OAuth Request Verification for the complete implementation.
Step 4: Minimal Access Scopes
Only request the scopes your app actually needs: