All articles

Shopify app security / Developer guide

Shopify App Security Checklist for Developers

A Shopify app security checklist should start with the boundaries that protect merchants: authenticated tenant context, resource authorization, protected tokens and verified integration handling. Add secure data practices, dependency review and incident readiness. Use the current Shopify requirements for your app type. A completed checklist is not a substitute for independent testing or a guarantee of governance approval.

By Scantra SecurityUpdated 4 min read

Merchant isolation and permission checks

Derive the tenant from authenticated context and enforce ownership on every backend resource and action. Check reads, writes, exports, downloads and background jobs, not only the visible pages. Test at least two authorized tenants and relevant roles so denied cross-store and privilege-escalation cases become explicit regression coverage.

Never assume a structured object ID or a shop parameter proves permission. Shopify’s security guidance identifies broken access control and tenant isolation as important risks. Review any shared helper that decides which merchant data to access. If that helper trusts request input, enumerate all callers so the correction addresses the category of failure rather than one route.

Sessions, OAuth and secrets

Review installation and authentication using current Shopify documentation. Embedded apps have a session-token requirement in the App Store rules. Validate authenticated identity and its relationship to the merchant before allowing sensitive actions. Examine logout, token expiration, role changes and reinstall behaviour according to the implementation you actually use.

Keep access tokens out of client bundles, public repositories, diagnostics and logs. Limit secret access and practice safe revocation and rotation. Record where credentials are stored and which systems use them so incident response is not slowed by an incomplete inventory. Replacing an exposed secret is not sufficient if the same logging or deployment process will expose the replacement.

Webhooks, inputs and sensitive workflows

Implement webhook verification using current Shopify guidance for your delivery method. Confirm tenant association, duplicate handling and safe processing of sensitive events. Check inputs reaching file operations, database queries, rendered HTML or outbound requests. Escape untrusted content for its output context rather than relying on a single generic filter.

Review billing and plan enforcement, exports, uploads and administrative operations when those exist in your app. Test that a lower-privilege user cannot call backend actions hidden in the UI. Authorize all testing and use synthetic data. Third-party APIs and Shopify infrastructure are not automatically in scope because your app integrates with them.

Customer data, dependencies and infrastructure

Minimize data collection and access to what the app needs. Review logs, backups and support tools for unnecessary sensitive information. For App Store apps, Shopify’s privacy-law compliance documentation identifies customers/data_request, customers/redact and shop/redact compliance topics. Verify actual handling rather than only checking that an endpoint is registered.

Inventory dependencies, review updates and remove unnecessary exposure from infrastructure. Protect administration interfaces and separate privileges. Track where merchant data travels across services and whether retention and deletion behaviour matches the app’s commitments. Passing one platform configuration requirement does not establish that application authorization and all other security controls are effective.

Testing and incident readiness

Maintain regression tests for security boundaries and commission independent assessment where required by a notice or justified by risk. Give assessors representative tenants and roles with authorized access. Track findings to owners, deployed fixes and verification evidence. A scanner can help discover issues but cannot independently explain an incident or prove every business-logic control.

Prepare a response contact, logging and evidence-retention plan, credential inventory and containment procedures. Shopify’s security guidance lists security@shopify.com for incident contact. Follow applicable obligations and the governance notice, using appropriate professional advice. After changes, monitor and revisit the checklist; it is a living engineering tool, not a certification that guarantees relisting.

Make the checklist testable rather than decorative

For each checklist item, add an owner, expected behaviour, an authorized test and evidence of the result. “Tenant isolation” should become a concrete denied cross-store action, not a tick based on a developer’s intention. “Secrets protected” should include a reviewed storage and exposure path without recording the secret itself. “Compliance webhooks” should include configuration and observed handling appropriate to your implementation. Mark planned, implemented and verified states separately. Revisit rows after material changes and when a vulnerability reveals a shared assumption. A testable checklist helps engineering prioritize work, but it remains bounded by the actual tests and cannot replace incident investigation, independent assessment or Shopify’s decision on governance.

Store the checklist beside the relevant engineering evidence rather than as a disconnected marketing document. Assign periodic review to a named owner and revisit affected controls after substantial changes to authentication, tenancy, data flows or integrations. Keep historical results separate from the latest verification status.

Your working checklist

  • Trusted tenant context on every backend action.
  • Object and role authorization regression tests.
  • Session and installation validation.
  • Secret inventory and rotation readiness.
  • Verified webhook processing and input handling.
  • Data minimization and compliance workflows.
  • Independent findings linked to verified fixes.
  • Incident ownership, logs and containment procedures.

Sources and scope of this guidance

Platform requirements below come from Shopify’s documentation. Response trackers and checklists are Scantra’s practical guidance, not an official Shopify workflow. Review current requirements and your own notice; this is not legal advice or an acceptance guarantee.

Where mentioned, the past relisting example is based on anonymised owner-supplied correspondence published with permission. Private client identities and incident evidence are not reproduced.