Shopify agents that handle the orders that need a person
Create a small app from your store's admin and paste its client ID and secret. Qoren registers the webhooks, wakes an agent on orders, refunds, customers and products, and lets it look up, note and tag orders.
Integrations is in early access: Qoren is turning it on account by account. Already have access? Open Integrations
How do I connect Shopify to an AI agent?
In your store's Shopify admin, open Settings > Apps > Develop apps and build an app in the Dev Dashboard with read scopes such as read_orders. Install it on the store and paste the store address, client ID and client secret in Qoren. Qoren signs in with them and refreshes access itself. Cancelling or refunding an order always waits for a person's approval.
What agents do with Shopify
Example jobs, each built only from the events and tools listed further down. Write the agent's rules in plain words; these are starting points, not presets.
For agencies running it for clients
Flag the orders that need a look
When an order is placed, the agent reads it and tags the unusual ones, such as a large order or one shipping abroad, with needs-review and a note on why.
- Wakes on
- Order placed
- Uses
- Read an order
- Tag an order
- Add an order note
Refund requests, prepared for the client
When a customer asks for a refund, the agent finds the order, checks what was paid and prepares the refund, which waits for the client's approval.
- Uses
- Find an order
- Read an order
- Refund an order
For founders running it for themselves
"Where is my order?" answered
When a customer emails the agent's mailbox with an order number, it looks the order up and answers with its payment and fulfillment status.
- Uses
- Find an order
- Read an order
Follow up on checkouts that stall
When a shopper starts a checkout, the agent checks later whether the order was placed and, if not, drafts a follow-up. Shopify has no abandoned checkout event, so this is how it is done.
- Wakes on
- Checkout started
- Uses
- Find an order
- List a customer's orders
The path one event takes
8 Shopify events that can wake an agent
Pick one on an agent's Triggers tab. Each event can arrive on its own, as a digest, or as the latest state of a record, and events that do not match your conditions are logged as Filtered, with no turn and no charge.
| Event | When it fires |
|---|---|
| Order placed | A new order is created, online or in the admin. |
| Order paid | An order's payment is captured in full. |
| Order cancelled | An order is cancelled. |
| Order fulfilled | Every item of an order has shipped. |
| Refund issued | A refund is created on an order. |
| Customer created | A new customer account or record is created. |
| Checkout started | A shopper starts a checkout. Shopify has no event for an abandoned checkout: to follow up on one, have the agent check later whether the order was placed. |
| Product updated | A product changes: title, price, a variant, or its stock. |
8 tools agents can use
Curated Shopify tools, not a raw API: each returns only the fields the job needs. A read only grant never gets a write tool, and tools marked Always asks wait for a person's approval whatever the agent's autonomy setting.
| Tool | What it does | Access | Approval |
|---|---|---|---|
| Find an order | Find Shopify orders by order number (for example #1042) or by the customer's email. Returns number, date, totals, payment and fulfillment status. | Read | None |
| Find a customer | Find Shopify customers by email or name. Returns id, name, email, number of orders and amount spent. | Read | None |
| Read an order | Read one Shopify order: items, totals, payment and fulfillment status, note, tags and where it ships (city and country). | Read | None |
| List a customer's orders | List one customer's orders, newest first, at most 20. | Read | None |
| Add an order note | Add a line to a Shopify order's staff note (it is appended, never replaced). | Write | Per autonomy setting |
| Tag an order | Add tags to a Shopify order, for example needs-review. Existing tags stay. | Write | Per autonomy setting |
| Cancel an order | Cancel a Shopify order, optionally refunding it to the original payment method and restocking. Always asks a person to approve first. | Write | Always asks |
| Refund an order | Refund an amount of a paid Shopify order to its original payment. Always asks a person to approve first. | Write | Always asks |
How connecting Shopify works
- 01Make a Shopify key with the least access it needs, following the guide below. Only the account owner can connect a tool.
- 02Paste it in Qoren. Qoren checks it before saving: which account it belongs to, what it can do and, where Shopify says, when it expires.
- 03Give an agent access, read only or read and write. An agent cannot use a tool it was not given.
- 04Pick the events that should wake the agent. Qoren registers the Shopify webhook itself, so there is no URL or signing secret to copy.
Making the Shopify key
- 1
Make the app from THIS store's admin
Shopify only lets an app sign in this way to stores in the app's own organization. So start from the store you are connecting: in its Shopify admin, open Settings > Apps > Develop apps, choose Build apps in Dev Dashboard, then Create app. Name it Qoren.
- 2
Give it the least scopes
In the app's version, add read scopes for what your agents should see and wake on, for example read_orders, read_customers and read_products. Add write_orders only if agents should add notes and tags or (always with your approval) cancel and refund orders. Release the version.
- 3
Install it on your store
Install the app on this store from the Dev Dashboard.
- 4
Paste the store address, client ID and client secret here
Copy the Client ID and Client secret from the app's settings and paste them here with your store's myshopify.com address. Qoren signs in with them and refreshes its access itself. If you have an older custom app, paste its shpat_ access token and its API secret key (in the Client secret field: Shopify signs events with it). Never send these by email or chat.
Connecting a client's account? Send a link
An agency does not need its client's key. Send a connect link instead: it shows your agency's name and the exact permissions to tick, works once, expires after 7 days and can be revoked. The client pastes the key on that page, Qoren encrypts it on arrival, and you only ever see its last four characters. A client's connection is used only by that client's agents. Connect links come with Clients, on the Ultimate, Business and Enterprise plans.
Client connect linksSecurity in plain words
Keys never reach the agent's machine
The Shopify key is encrypted at rest with AES-256-GCM and used only inside Qoren's own calls to Shopify. It is never written to the agent's environment, and after you connect only its last four characters are shown.
Read only until you say otherwise
Each agent gets read only or read and write access, granted one agent at a time. The Shopify key itself can be limited too, and the guide asks for the least it needs.
Risky actions always ask
In Shopify, these always wait for a person's approval, whatever the agent's autonomy setting: cancel an order and refund an order.
Capped reads and a full audit log
By default an agent reads at most 500 records an hour from one connection. Every call, read or write, lands in the audit log with the agent, the tool and the record ids.
Event data is treated as data
Events reach the agent fenced off as data, with a warning not to follow instructions inside them. For 30 minutes after an agent reads connected data, a Qoren tool that would send it outside your account waits for your approval.
Stored events expire
Qoren keeps event bodies for 7 days on Starter, 30 on Pro, 90 on Ultimate and 180 on Business, then removes them and keeps only the metadata.
Shopify limits worth knowing
When you disconnect, Qoren cannot revoke the key at Shopify, so it tells you where to delete it. In Shopify admin, open Settings > Apps, uninstall the Qoren app, and delete it in the Dev Dashboard (or rotate its client secret).
- Shopify only lets an app sign in this way to stores in the app's own organization, so create the app from the admin of the store you are connecting.
- Shopify has no event for an abandoned checkout. Use Checkout started and have the agent check later.
- Qoren refreshes Shopify's 24 hour access tokens itself. Older custom apps with an shpat_ token also work.
- Shopify deletes a webhook after repeated failed deliveries. Qoren's daily check creates it again.
Frequently asked questions
Why must the app be made from my store's admin?
Shopify only lets an app use this sign-in to stores in the app's own organization. Starting from the store's admin, under Settings > Apps > Develop apps, keeps the app and the store together.
I have an older custom app. Can I use it?
Yes. Paste its shpat_ Admin API access token and its API secret key, which Shopify uses to sign events. Shopify stopped creating these apps, but existing ones keep working.
Does my agent ever see the Shopify key?
No. Qoren encrypts the key as soon as it arrives and uses it only inside its own calls to Shopify. The key never reaches the agent's machine, is never shown again after you connect, and the agent only gets the results of the tools you allowed.
Can an agent cancel an order without asking?
No. In Shopify, these tools always wait for a person's approval, whatever the agent's autonomy setting: cancel an order and refund an order. The approval shows the exact details the agent wants to send.
ApprovalsWhat happens when I disconnect Shopify?
Qoren deletes the webhooks it registered, deletes the stored key, pauses the triggers that used it and removes stored event bodies. It cannot revoke a key at Shopify, so it shows you where to delete it: In Shopify admin, open Settings > Apps, uninstall the Qoren app, and delete it in the Dev Dashboard (or rotate its client secret).
What does the Shopify integration cost?
Connecting tools comes with every Qoren plan, with no limit on connections, once Integrations is on for your account. It is in early access for now, turned on account by account. An event that wakes an agent uses credits like any other agent turn, and each trigger has an hourly cap.
Qoren pricingConnect Shopify once. Let agents handle the rest.
Integrations is in early access, turned on account by account. Request it and tell us how your agents should use Shopify.