Shopify

Connect a Shopify store so its storefront SDK points at the right organization and environment automatically.

Improve's Shopify connection is a lightweight link between a Shopify store and an Improve organization/environment. It's not a full OAuth app install: Improve never requests or stores a Shopify Admin API access token, and it never reads orders, customers, payment data, or products.

The connection is started from Shopify, not from the Improve dashboard. A merchant taps Connect inside the Obelism app in their Shopify admin. The Improve dashboard only shows already-connected stores, under Organization → Integrations, where an admin or developer can disconnect one.

How it works

  1. A merchant taps Connect inside the Obelism app in their Shopify admin, which redirects their browser to Improve with a signed link (shop domain, a callback URL, and a state token).
  2. Improve verifies the link's signature, then asks the merchant to log in to their Improve account if they aren't already.
  3. The merchant picks which organization (if they belong to more than one) and which environment (production, staging, or develop) the store should connect to, then confirms. Only Admin and Developer roles can do this.
  4. Improve redirects back to the Shopify app with a one-time code, and auto-whitelists the shop's origin for the chosen environment so the storefront SDK's config and analytics requests work without any manual CORS setup.
  5. The Shopify app exchanges that code, server-to-server, for the organization id, environment, and base URL: enough for it to point the storefront's Obelism SDK at the right place. No access token is ever part of this exchange.

Good to know

  • No order, customer, or payment data is touched. The connection is purely a mapping from a shop domain to an organization and environment, plus the CORS whitelist entry that comes with it.
  • The one-time code expires in 10 minutes and can only be exchanged once; a second attempt fails.
  • Disconnecting (from Organization → Integrations) revokes the connection and removes the whitelisted origin.

Managing a connection

Connected stores are listed under Organization → Integrations in the dashboard, alongside your other integrations. From there you can open a store's Shopify admin or disconnect it; there's no "Connect" button on this side, since the connection always starts from Shopify.

On this page