Agent skill

Shopify Install Auth

by jeremylongshore in jeremylongshore/tons-of-skills-marketplace

Install and configure Shopify app authentication with OAuth, session tokens, and the @shopify/shopify-api SDK.

MITAuto-check: notesBackend & APIs

Install Shopify Install Auth

skills CLI
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill shopify-install-auth -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install jeremylongshore/tons-of-skills-marketplace shopify-install-auth --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/.curated/shopify-install-auth .claude/skills/shopify-install-auth && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
shopify-install-auth
GitHub stars
2.8k
Token cost
~1.6k tokens
SKILL.md length
364 words
Files
4 (incl. references)
Skills in repo
3,342
Repo updated
First seen
Licence
MIT

At a glance

Install and configure Shopify app authentication with OAuth, session tokens, and the @shopify/shopify-api SDK.

  • Works in 7 steps: Install the Shopify API Library → Configure Environment Variables → Initialize the Shopify API Library → …
  • Setting up a new Shopify app
  • SKILL.md covers Overview, Prerequisites, Instructions and Output, plus 3 more sections
  • Calls npm; needs SHOPIFY_API_KEY and SHOPIFY_API_SECRET

What it does

Shopify Install Auth is an agent skill from jeremylongshore/tons-of-skills-marketplace. Install and configure Shopify app authentication with OAuth, session tokens, and the @shopify/shopify-api SDK. Use when setting up a new Shopify app, configuring API credentials, or initializing authentication for Admin or Storefront API access. Trigger with phrases like "install shopify", "setup shopify", "shopify auth", "shopify OAuth", "configure shopify API".

Its SKILL.md is about 1.6k tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files, including reference files (for example `references/custom-app-auth.md`, `references/oauth-flow.md` and `references/storefront-api-access.md`). Compatibility notes: Designed for Claude Code

It sits in Backend & APIs, covering OAuth and OpenID Connect and Authentication. It works with Shopify. The repository describes itself as: Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com. The licence is MIT.

When your agent uses it

  • Setting up a new Shopify app
  • Configuring API credentials
  • Initializing authentication for Admin
  • Storefront API access

Example prompts

  • “install shopify”
  • “setup shopify”
  • “shopify auth”
  • “/shopify-install-auth”

Requirements

  • Node.js
  • A credential in SHOPIFY_API_KEY
  • A credential in SHOPIFY_API_SECRET
  • Compatibility (from SKILL.md): Designed for Claude Code
  • Pre-approved tools (allowed-tools): Read, Write, Edit, Bash(npm:*), Bash(pnpm:*), Bash(npx:*), Grep

Workflow steps

7 steps, taken from the step headings in SKILL.md.

  1. Install the Shopify API Library
  2. Configure Environment Variables
  3. Initialize the Shopify API Library
  4. Implement OAuth Flow (Public Apps)
  5. Token Exchange (Embedded Apps)
  6. Custom App / Private App Auth
  7. Verify Auth is Working

What it can do on your machine

Read from SKILL.md and the folder at commit cfae287. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Write
    • Edit
    • Bash(npm:*)
    • Bash(pnpm:*)
    • Bash(npx:*)
    • Grep

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • npm

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • shopify.dev
    • partners.shopify.com
    • npmjs.com
    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • SHOPIFY_API_KEY
    • SHOPIFY_API_SECRET
    • SHOPIFY_ACCESS_TOKEN

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Designed for Claude Code

    From compatibility in the SKILL.md frontmatter.

Context cost

Shopify Install Auth loads about 1.6k tokens when it runs, and up to ~2.4k if it reads all its reference files. Until then it costs about 97 tokens; SKILL.md has 364 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~97
When it runs · the whole SKILL.md, loaded when a task matches
~1.6k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~2.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:54
    Create a `.env` file (add to `.gitignore` immediately):
  • NoteMentions a .env fileSKILL.md:57
    # .env — NEVER commit this file
  • NoteMentions a .env fileSKILL.md:74
    .env
  • NoteMentions a .env fileSKILL.md:75
    .env.local
  • NoteMentions a .env fileSKILL.md:76
    .env.*.local

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from jeremylongshore/tons-of-skills-marketplace at commit cfae287, republished under its MIT licence (© jeremylongshore). 364 words, ~1,636 tokens.

Download SKILL.mdSave it as .claude/skills/shopify-install-auth/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
shopify-install-auth
description
Install and configure Shopify app authentication with OAuth, session tokens, and the @shopify/shopify-api SDK. Use when setting up a new Shopify app, configuring API credentials, or initializing authentication for Admin or Storefront API access. Trigger with phrases like "install shopify", "setup shopify", "shopify auth", "shopify OAuth", "configure shopify API".
allowed-tools
Read, Write, Edit, Bash(npm:*), Bash(pnpm:*), Bash(npx:*), Grep
compatibility
Designed for Claude Code
version
2.7.0
license
MIT
author
Jeremy Longshore <jeremy@intentsolutions.io>
tags
saas, ecommerce, shopify

Shopify Install & Auth

Overview

Set up Shopify app authentication using the official @shopify/shopify-api library. Covers OAuth flow, session token exchange, custom app tokens, and Storefront API access.

Prerequisites

  • Node.js 18+ (the @shopify/shopify-api v9+ requires it)
  • A Shopify Partner account at https://partners.shopify.com
  • An app created in the Partner Dashboard with API credentials
  • A development store for testing

Instructions

Step 1: Install the Shopify API Library
bash
# Core library + Node.js runtime adapter
npm install @shopify/shopify-api @shopify/shopify-app-remix
# Or for standalone Node apps:
npm install @shopify/shopify-api @shopify/shopify-app-express

# For Remix (recommended by Shopify):
npm install @shopify/shopify-app-remix @shopify/app-bridge-react
Step 2: Configure Environment Variables

Create a .env file (add to .gitignore immediately):

bash
# .env — NEVER commit this file
SHOPIFY_API_KEY=your_app_api_key
SHOPIFY_API_SECRET=your_app_api_secret
SHOPIFY_SCOPES=read_products,write_products,read_orders,write_orders
SHOPIFY_APP_URL=https://your-app.example.com
SHOPIFY_HOST_NAME=your-app.example.com

# For custom/private apps only:
SHOPIFY_ACCESS_TOKEN=shpat_xxxxxxxxxxxxxxxxxxxxx

# API version — use a stable quarterly release
# Update quarterly — see shopify.dev/docs/api/usage/versioning
SHOPIFY_API_VERSION=2025-04
bash
# .gitignore — add these immediately
.env
.env.local
.env.*.local
Step 3: Initialize the Shopify API Library
typescript
// src/shopify.ts
import "@shopify/shopify-api/adapters/node";
import { shopifyApi, LATEST_API_VERSION, Session } from "@shopify/shopify-api";

const shopify = shopifyApi({
  apiKey: process.env.SHOPIFY_API_KEY!,
  apiSecretKey: process.env.SHOPIFY_API_SECRET!,
  scopes: process.env.SHOPIFY_SCOPES!.split(","),
  hostName: process.env.SHOPIFY_HOST_NAME!,
  apiVersion: LATEST_API_VERSION,
  isEmbeddedApp: true,
});

export default shopify;
Step 4: Implement OAuth Flow (Public Apps)

Express-based OAuth flow that redirects to Shopify and handles the callback token exchange.

See OAuth Flow for the complete Express route implementation.

Step 5: Token Exchange (Embedded Apps)

For embedded apps, use session token exchange instead of traditional OAuth:

typescript
// Token exchange — converts session token (JWT) to API access token
import shopify from "../shopify";

async function exchangeToken(
  shop: string,
  sessionToken: string
): Promise<Session> {
  const { session } = await shopify.auth.tokenExchange({
    sessionToken,
    shop,
    requestedTokenType: RequestedTokenType.OfflineAccessToken,
  });
  return session;
}
Step 6: Custom App / Private App Auth

For custom apps installed on a single store, use a permanent access token with no OAuth needed.

See Custom App Auth for the complete setup.

Step 7: Verify Auth is Working
typescript
// Quick connectivity test
async function verifyShopifyAuth(session: Session): Promise<void> {
  const client = new shopify.clients.Graphql({ session });

  const response = await client.request(`{
    shop {
      name
      email
      plan {
        displayName
      }
      primaryDomain {
        url
      }
    }
  }`);

  console.log("Connected to:", response.data.shop.name);
  console.log("Plan:", response.data.shop.plan.displayName);
  console.log("Domain:", response.data.shop.primaryDomain.url);
}

Output

  • @shopify/shopify-api installed and configured
  • OAuth flow or custom app auth operational
  • Session with valid access token persisted
  • Verified connection to the Shopify Admin API
Show full SKILL.md (171 more words)Show less

Error Handling

ErrorCauseSolution
InvalidApiKeyErrorWrong SHOPIFY_API_KEYVerify in Partner Dashboard > App > API credentials
InvalidHmacError during callbackSecret mismatch or URL tamperingCheck SHOPIFY_API_SECRET matches Partner Dashboard
SessionNotFoundSession not persistedImplement SessionStorage (DB, Redis, or file)
HttpResponseError: 401Token expired or revokedMerchant uninstalled app — trigger re-auth
InvalidScopeErrorRequested scope not approvedOnly use scopes from the approved list in your app config
ShopifyErrors.InvalidShopMalformed shop domainMust be *.myshopify.com — use sanitizeShop()

Examples

Shopify API Access Scopes Reference
ScopeGrants Access To
read_products / write_productsProducts, variants, collections, images
read_orders / write_ordersOrders, transactions, fulfillments
read_customers / write_customersCustomer data, addresses, metafields
read_inventory / write_inventoryInventory levels across locations
read_content / write_contentPages, blogs, articles
read_themes / write_themesTheme files and assets
read_shipping / write_shippingShipping zones, carrier services
read_fulfillments / write_fulfillmentsFulfillment orders and services
Storefront API Access

The Storefront API uses a separate token with its own higher rate limits.

See Storefront API Access for the complete client setup.

Resources

© jeremylongshore, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files (references) in skills/.curated/shopify-install-auth of jeremylongshore/tons-of-skills-marketplace.

  • SKILL.md
  • references/custom-app-auth.md
  • references/oauth-flow.md
  • references/storefront-api-access.md

Open the folder on GitHubat commit cfae287

Compare with similar skills

Shopify Install Auth next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Shopify Install Auth compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Shopify Install Auth this skilljeremylongshore/tons-of-skills-marketplace2.8k—~1.6kAutomated safety check: NotesMIT
Shopify APIMicrock/ordinary-claude-skills404—~4.3kAutomated safety check: PassCustom licence
Fortify Developmentcoollabsio/coolify63k4 repos~1.9kAutomated safety check: PassMIT
Cognitoitsmostafa/aws-agent-skills1.2k1 repos~2.3kAutomated safety check: PassMIT
Security Reviewdoorkeeper-gem/doorkeeper5.5k—~1.4kAutomated safety check: PassMIT
OAuth Account Setupspinabot/brigade11k—~878Automated safety check: PassMIT

Similar skills

  • Shopify API

    Microck/ordinary-claude-skills

    Complete API integration guide for Shopify including GraphQL Admin API, REST Admin API, Storefront API, Ajax API, OAuth authentication, rate limiting, and webhooks.

    404 GitHub stars~4.3k tokensUpdated 1 mo ago
    Backend & APIsAuto-check passed
  • Fortify Development

    coollabsio/coolify

    ACTIVATE when the user works on authentication in Laravel. An agent skill from coollabsio/coolify.

    63k GitHub starsUsed in 4 repos~1.9k tokens
    Backend & APIsAuto-check passed
  • Cognito

    itsmostafa/aws-agent-skills

    AWS Cognito user authentication and authorization service. An agent skill from itsmostafa/aws-agent-skills.

    1.2k GitHub starsUsed in 1 repo~2.3k tokens
    Backend & APIsAuto-check passed
  • Security Review

    doorkeeper-gem/doorkeeper

    Verify that code changes do not introduce OAuth security vulnerabilities.

    5.5k GitHub stars~1.4k tokensUpdated yesterday
    Backend & APIsAuto-check passed
  • OAuth Account Setup

    spinabot/brigade

    Connects an OAuth 2.0 account such as Gmail with the built-in oauth_authorize tool: an authorization link, automatic code capture and sealed token storage.

    11k GitHub stars~878 tokensUpdated yesterday
    Backend & APIsAuto-check passed
  • Auth Implementation Patterns

    ynulihao/AgentSkillOS

    Master authentication and authorization patterns including JWT, OAuth2, session management, and RBAC to build secure, scalable access control systems.

    618 GitHub starsUsed in 10 repos~4.4k tokens
    Backend & APIsAuto-check passed

More from jeremylongshore/tons-of-skills-marketplace

All 3,342 skills in this repo
  • Performing Security Code Review

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to conduct a security-focused code review using the security-agent plugin.

    2.8k GitHub starsUsed in 2 repos~1.3k tokens
    Auto-check: notes
  • Adapting Transfer Learning Models

    jeremylongshore/tons-of-skills-marketplace

    Build this skill automates the adaptation of pre-trained machine learning models using transfer learning techniques.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Agent Context Loader

    jeremylongshore/tons-of-skills-marketplace

    Execute proactive auto-loading: automatically detects and loads agents.md files.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Aggregating Performance Metrics

    jeremylongshore/tons-of-skills-marketplace

    Aggregate and centralize performance metrics from applications, systems, databases, caches, and services.

    2.8k GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Analyzing Capacity Planning

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to analyze capacity requirements and plan for future growth.

    2.8k GitHub stars~947 tokensUpdated today
    Auto-check passed
  • Analyzing Database Indexes

    jeremylongshore/tons-of-skills-marketplace

    Process use when you need to work with database indexing. An agent skill from jeremylongshore/tons-of-skills-marketplace.

    2.8k GitHub stars~2k tokensUpdated today
    Auto-check passed

Works with

Categories

Questions about Shopify Install Auth

What does Shopify Install Auth do?

Install and configure Shopify app authentication with OAuth, session tokens, and the @shopify/shopify-api SDK. Shopify Install Auth is an agent skill from jeremylongshore/tons-of-skills-marketplace. Install and configure Shopify app authentication with OAuth, session tokens, and the @shopify/shopify-api SDK.

When should I use Shopify Install Auth?

Shopify Install Auth fits situations like: setting up a new Shopify app; configuring API credentials; initializing authentication for Admin; storefront API access.

How do I install Shopify Install Auth in Claude Code?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill shopify-install-auth -a claude-code`. Or copy the skill folder (skills/.curated/shopify-install-auth in jeremylongshore/tons-of-skills-marketplace) into .claude/skills/shopify-install-auth in your project. Claude Code loads it when a task matches its description.

How do I install Shopify Install Auth in Codex?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill shopify-install-auth -a codex`. Or copy the skill folder (skills/.curated/shopify-install-auth in jeremylongshore/tons-of-skills-marketplace) into .agents/skills/shopify-install-auth in your project. Codex loads it when a task matches its description.

Can I use Shopify Install Auth in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill shopify-install-auth -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/shopify-install-auth, .gemini/skills/shopify-install-auth, .github/skills/shopify-install-auth and .opencode/skills/shopify-install-auth in your project.

What does Shopify Install Auth need to run?

Going by SKILL.md and its folder, Shopify Install Auth needs the command-line tools its instructions call (npm) and credentials named SHOPIFY_API_KEY, SHOPIFY_API_SECRET and SHOPIFY_ACCESS_TOKEN. Our summary lists: Node.js; A credential in SHOPIFY_API_KEY; A credential in SHOPIFY_API_SECRET. Its frontmatter pre-approves these tools: Read, Write, Edit, Bash(npm:*), Bash(pnpm:*), Bash(npx:*), Grep. Compatibility (from SKILL.md): Designed for Claude Code.

Does Shopify Install Auth access the network?

SKILL.md names 4 domains. As links in the text: shopify.dev, partners.shopify.com, npmjs.com and github.com. This is read from the text; nothing was executed.

Is Shopify Install Auth safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Shopify Install Auth use?

Shopify Install Auth is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Shopify Install Auth use?

About 1.6k tokens (SKILL.md is roughly 6.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 734 tokens, read only when the agent opens those files.

What are the alternatives to Shopify Install Auth?

Skills that share tags, products or a category with Shopify Install Auth: Shopify API (Microck/ordinary-claude-skills, 404 stars), Fortify Development (coollabsio/coolify, 63k stars), Cognito (itsmostafa/aws-agent-skills, 1.2k stars) and Security Review (doorkeeper-gem/doorkeeper, 5.5k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Shopify Install Auth?

jeremylongshore (a GitHub user) maintains it in jeremylongshore/tons-of-skills-marketplace, which has 2,827 GitHub stars. The repository holds 3,342 skills in this directory. The repository was last updated on October 10, 2026.

Source: jeremylongshore/tons-of-skills-marketplace on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.