Shopify app security / Developer guide
Shopify App Security Review: What Security Issues Can Cause Problems?
Shopify app security problems can include broken access control, cross-store data exposure, exposed secrets, unsafe inputs and weak integration validation. Shopify’s developer guidance discusses these risks, while its App Store requirements address additional controls. A weakness is not an automatic prediction of removal; the notice and Shopify’s review determine the action in an individual case.
Cross-store access and server-side authorization
Multi-merchant apps must decide which store and resources a request may access using trusted authenticated context. A shop identifier, object ID or GraphQL ID supplied in a request is not sufficient proof of ownership. Test whether one authorized tenant can read or change another tenant’s resource by altering identifiers under controlled conditions.
Shopify’s security guidance explicitly highlights broken access control and tenant isolation. The same underlying assumption can affect exports, background jobs, support tools and alternate API versions. Review those sibling paths rather than fixing only the endpoint used in the original report. A UI that hides a button does not enforce authorization on the backend.
Authentication, installation and credential exposure
Review session validation, OAuth handling, installation callbacks, token storage and privilege boundaries. Shopify’s App Store requirements specify session-token authentication for embedded apps. Confirm that the implementation associates authenticated identity with the correct store and does not trust an unsigned parameter or client claim to choose the tenant.
Keep access tokens and secrets out of code shipped to browsers, public repositories, error messages and logs. Limit access and prepare safe rotation. A leaked token may create exposure even when the visible application behaves correctly. Assess the source of the leak and the permissions of the token, not only whether replacing the string stops a particular reproduction.
Webhooks, asynchronous workflows and untrusted inputs
A webhook endpoint is a security boundary. Use Shopify’s webhook documentation to implement verification appropriately for the delivery mechanism, and ensure the handler associates events with the correct store. Consider duplicate delivery, idempotency and data changes triggered by asynchronous jobs. Do not assume an endpoint is trusted just because its URL is difficult to guess.
Validate file handling, rendered content and inputs that reach database queries or external requests. Escape untrusted output in the correct context. Test relevant injection, script execution and unsafe fetch paths within authorization. Shopify’s guidance says to treat external input as untrusted, including input from integrations; labels such as “internal job” do not make a data source inherently safe.
Customer data and privacy-related controls
Inventory what merchant and customer data your app stores and why it needs that data. Limit collection and access, and assess whether logs, exports and support tools disclose unnecessary information. Privacy obligations and security controls overlap but are not interchangeable: encrypting a database does not justify retaining information the app no longer needs.
Shopify’s privacy-law compliance documentation requires App Store apps to subscribe to customers/data_request, customers/redact and shop/redact compliance topics. Review current platform requirements for your distribution and functionality. Do not treat compliance webhook configuration as proof that tenant isolation or the wider security of the app has been validated.
Prioritize evidence instead of an assumed delisting formula
Rank confirmed findings by exploitability, exposure and business impact, then address the most urgent risks while investigation continues. Preserve the original report and verify related paths. If a notice cites a specific control or event, show how the remediation and assessment address it rather than submitting an unrelated checklist.
This article identifies technical review areas, not an official list of automatic delisting triggers. Shopify may consider facts and requirements beyond the particular issue discussed here. An independent VAPT can help validate scoped risks and fixes; an Incident Report explains the event. Neither gives an assessor authority to guarantee Shopify’s governance decision.
A control-to-evidence review matrix
For each relevant surface, write the intended security boundary, test identity, permitted action, denied action and evidence location. For a resource API, for example, the boundary is the requesting tenant and object ownership; the denied action is access by another authorized test tenant. Use similar rows for roles, tokens, webhooks and sensitive workflows according to the app. Keep this as a scoping and engineering aid rather than a claim that every row has been independently assessed. Mark not-tested items clearly. If a vulnerability is found in one row, examine other rows relying on the same control. The matrix can help coordinate developers and testers while preserving the distinction between planned coverage, actual test evidence and historical incident conclusions.
Your working checklist
- Derive tenant access from authenticated context.
- Enforce object ownership on every backend path.
- Validate sessions and installation flows.
- Protect and rotate access tokens.
- Verify webhook handling using current documentation.
- Review uploads, outputs and unsafe fetches.
- Test exports, jobs and administrative tools.
- Minimize data and verify compliance workflows.
Sources and scope of this guidance
Platform requirements below come from Shopify’s documentation. Response trackers and checklists are Scantra’s practical guidance, not an official Shopify workflow. Review current requirements and your own notice; this is not legal advice or an acceptance guarantee.
- Shopify: Protect against common vulnerabilities
App security boundaries, incident contact and developer security practices.
- Shopify App Store requirements
Current app requirements, including embedded-app authentication.
- Shopify: Privacy law compliance
Mandatory compliance webhook topics and implementation guidance.
Where mentioned, the past relisting example is based on anonymised owner-supplied correspondence published with permission. Private client identities and incident evidence are not reproduced.
