Agent skill

Shopify Prod Checklist

by jeremylongshore in jeremylongshore/tons-of-skills-marketplace

Execute Shopify app production deployment checklist covering App Store requirements, mandatory webhooks, API versioning, and rollback procedures.

MITAuto-check passedBackend & APIs

Install Shopify Prod Checklist

skills CLI
$ npx skills add jeremylongshore/tons-of-skills-marketplace --skill shopify-prod-checklist -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install jeremylongshore/tons-of-skills-marketplace shopify-prod-checklist --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/jeremylongshore/tons-of-skills-marketplace.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/.curated/shopify-prod-checklist .claude/skills/shopify-prod-checklist && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
shopify-prod-checklist
GitHub stars
2.8k
Token cost
~1.2k tokens
SKILL.md length
453 words
Files
3 (incl. references)
Skills in repo
3,342
Repo updated
First seen
Licence
MIT

At a glance

Execute Shopify app production deployment checklist covering App Store requirements, mandatory webhooks, API versioning, and rollback procedures.

  • Works in 8 steps: API and Authentication → Mandatory GDPR Compliance → Webhook Security → …
  • Preparing a Shopify app for production launch
  • SKILL.md covers Overview, Prerequisites, Instructions and Output, plus 3 more sections
  • Calls curl and jq; reaches admin.shopify.com

What it does

Shopify Prod Checklist is an agent skill from jeremylongshore/tons-of-skills-marketplace. Execute Shopify app production deployment checklist covering App Store requirements, mandatory webhooks, API versioning, and rollback procedures. Use when preparing a Shopify app for production launch, submitting to the App Store, or auditing an existing deployment for compliance gaps. Trigger with phrases like "shopify production", "deploy shopify", "shopify go-live", "shopify launch checklist", "shopify app store submit".

Its SKILL.md is about 1.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 3 other files, including reference files (for example `references/health-check-endpoint.md` and `references/pre-deploy-smoke-test.md`). Compatibility notes: Designed for Claude Code

It sits in Backend & APIs, covering Webhooks, App store release and Deployment. It works with Shopify. The repository describes itself as: Model-agnostic agent-skills platform with a harness-free canonical layer, verified adapters, and the ccpi package manager. Explore at tonsofskills.com. The licence is MIT.

When your agent uses it

  • Preparing a Shopify app for production launch
  • Submitting to the App Store
  • Auditing an existing deployment for compliance gaps
  • With phrases like shopify production

Example prompts

  • “shopify production”
  • “deploy shopify”
  • “shopify go-live”
  • “/shopify-prod-checklist”

Requirements

  • Compatibility (from SKILL.md): Designed for Claude Code
  • Pre-approved tools (allowed-tools): Read, Bash(curl:*), Grep

Workflow steps

8 steps, taken from the step headings in SKILL.md.

  1. API and Authentication
  2. Mandatory GDPR Compliance
  3. Webhook Security
  4. Rate Limit Resilience
  5. Error Handling
  6. App Store Submission Requirements
  7. API Version Management
  8. Health Check Endpoint

What it can do on your machine

Read from SKILL.md and the folder at commit cfae287. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Bash(curl:*)
    • Grep

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • curl
    • jq

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • admin.shopify.com

    Also links to:

    • shopify.dev
    • shopifystatus.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Designed for Claude Code

    From compatibility in the SKILL.md frontmatter.

Context cost

Shopify Prod Checklist loads about 1.2k tokens when it runs, and up to ~1.7k if it reads all its reference files. Until then it costs about 113 tokens; SKILL.md has 453 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~113
When it runs · the whole SKILL.md, loaded when a task matches
~1.2k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~1.7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from jeremylongshore/tons-of-skills-marketplace at commit cfae287, republished under its MIT licence (© jeremylongshore). 453 words, ~1,249 tokens.

Download SKILL.mdSave it as .claude/skills/shopify-prod-checklist/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.
name
shopify-prod-checklist
description
Execute Shopify app production deployment checklist covering App Store requirements, mandatory webhooks, API versioning, and rollback procedures. Use when preparing a Shopify app for production launch, submitting to the App Store, or auditing an existing deployment for compliance gaps. Trigger with phrases like "shopify production", "deploy shopify", "shopify go-live", "shopify launch checklist", "shopify app store submit".
allowed-tools
Read, Bash(curl:*), Grep
compatibility
Designed for Claude Code
version
2.7.0
license
MIT
author
Jeremy Longshore <jeremy@intentsolutions.io>
tags
saas, ecommerce, shopify

Shopify Production Checklist

Overview

Complete pre-launch checklist for deploying Shopify apps to production and submitting to the Shopify App Store.

Prerequisites

  • Staging environment tested and verified
  • Shopify Partner account with app configured
  • All development and staging tests passing

Instructions

Step 1: API and Authentication
  • Using a recent stable API version (e.g., 2025-04), not unstable
  • Access token stored in secure environment variables (never in code)
  • API secret stored securely for webhook HMAC verification
  • OAuth flow tested with a fresh install on a clean dev store
  • Session persistence implemented (database or Redis, not in-memory)
  • Token refresh/re-auth handled for expired sessions
  • APP_UNINSTALLED webhook handler cleans up sessions
Step 2: Mandatory GDPR Compliance
  • customers/data_request webhook handler implemented
  • customers/redact webhook handler implemented
  • shop/redact webhook handler implemented (fires 48h after uninstall)
  • All three configured in shopify.app.toml
  • Handlers respond with HTTP 200 within 5 seconds
  • Customer data deletion actually works (test it!)
Step 3: Webhook Security
  • All webhooks verify X-Shopify-Hmac-Sha256 using HMAC-SHA256
  • Using crypto.timingSafeEqual() for signature comparison
  • Webhook endpoints use raw body parsing (not JSON middleware)
  • Idempotency: duplicate webhook deliveries handled gracefully
Step 4: Rate Limit Resilience
  • GraphQL queries optimized (check requestedQueryCost with debug header)
  • Retry logic with exponential backoff for 429 / THROTTLED responses
  • Bulk operations used for large data exports instead of paginated queries
  • No unbounded loops that could exhaust rate limits
Step 5: Error Handling
  • All GraphQL mutations check userErrors array (200 with errors!)
  • HTTP 4xx/5xx errors caught and logged with X-Request-Id
  • Graceful degradation when Shopify is unavailable
  • No PII logged (customer emails, addresses, phone numbers)
Show full SKILL.md (202 more words)Show less
Step 6: App Store Submission Requirements
  • App listing has clear name, description, and screenshots
  • Privacy policy URL provided
  • App has proper onboarding flow for new merchants
  • Embedded app uses App Bridge for navigation (no full-page redirects)
  • CSP headers set: frame-ancestors https://*.myshopify.com https://admin.shopify.com
  • App works on both desktop and mobile admin
  • Loading states shown during API calls (no blank screens)
Step 7: API Version Management
bash
# Check which API versions your store supports
curl -s -H "X-Shopify-Access-Token: $TOKEN" \
  "https://$STORE/admin/api/versions.json" \
  | jq '.supported_versions[] | select(.supported == true) | .handle'

# Shopify deprecates versions ~12 months after release
# Set a calendar reminder to upgrade quarterly
Step 8: Health Check Endpoint

Express endpoint that tests Shopify API connectivity and database availability, returning structured status with latency metrics.

See Health Check Endpoint for the complete implementation.

Output

  • All checklist items verified
  • Health check endpoint operational
  • GDPR compliance webhooks functional
  • App ready for production traffic or App Store submission

Error Handling

AlertConditionSeverity
Shopify API down5xx errors > 5/minP1 - Critical
Auth failures401 errors > 0P1 - Token may be revoked
Rate limitedTHROTTLED > 5/minP2 - Reduce query cost
High latencyp95 > 3000msP2 - Check query complexity
Webhook failuresDelivery success < 95%P2 - Check endpoint health

Examples

Pre-Deploy Smoke Test

Bash script that validates Shopify auth and API scopes before deploying to production.

See Pre-Deploy Smoke Test for the complete script.

Resources

© jeremylongshore, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 2 other files (references) in skills/.curated/shopify-prod-checklist of jeremylongshore/tons-of-skills-marketplace.

  • SKILL.md
  • references/health-check-endpoint.md
  • references/pre-deploy-smoke-test.md

Open the folder on GitHubat commit cfae287

Compare with similar skills

Shopify Prod Checklist next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Shopify Prod Checklist compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Shopify Prod Checklist this skilljeremylongshore/tons-of-skills-marketplace2.8k—~1.2kAutomated safety check: PassMIT
App Promo Materialsglifxyz/glif-mcp-server213—~1.7kAutomated safety check: PassMIT
Golivemikehasa/golive-skill1.3k—~13kAutomated safety check: NotesMIT
ShopifyShopify/Shopify-AI-Toolkit592—~4.2kAutomated safety check: PassMIT
Ar Io Gateway Operatorar-io/ar-io-node127—~7.7kAutomated safety check: NotesAGPL-3.0
Channel Debug Corevercel-labs/vercel-openclaw-archived117—~2kAutomated safety check: NotesMIT

Similar skills

  • App Promo Materials

    glifxyz/glif-mcp-server

    Plan and make launch, store, ad and campaign graphics with Glif: real app screens turned into store listings and launch posts, or a coordinated set of product photos, ads, a short video and a jingle…

    213 GitHub stars~1.7k tokensUpdated 2 days ago
    Media & CreativeAuto-check passed
  • Golive

    mikehasa/golive-skill

    Take an agent-written app from repo to live production on the user's OWN accounts, with providers they choose (hosting, database, auth, payments, email, domain/DNS).

    1.3k GitHub stars~13k tokensUpdated 7 days ago
    Backend & APIsAuto-check: notes
  • Shopify

    Shopify/Shopify-AI-Toolkit

    Official

    Build anything on Shopify. An agent skill from Shopify/Shopify-AI-Toolkit.

    592 GitHub stars~4.2k tokensUpdated 3 days ago
    Backend & APIsAuto-check passed
  • Ar Io Gateway Operator

    ar-io/ar-io-node

    Operate any AR.IO node deployment — architecture, daily ops, diagnostics, and recurring pitfalls that apply to every operator.

    127 GitHub stars~7.7k tokensUpdated today
    Backend & APIsAuto-check: notes
  • Channel Debug Core

    vercel-labs/vercel-openclaw-archived

    Official

    Channel webhook triage for vercel-openclaw Slack/Telegram/Discord/WhatsApp issues: prove deployment state, collect admin readiness endpoints, build evidence-first handoff before fixes.

    117 GitHub stars~2k tokensUpdated 4 mo ago
    Backend & APIsAuto-check: notes
  • Shopify Development

    davila7/claude-code-templates

    Build Shopify apps, extensions, themes using GraphQL Admin API, Shopify CLI, Polaris UI, and Liquid.

    33k GitHub starsUsed in 7 repos~2.2k tokens
    Backend & APIsAuto-check passed

More from jeremylongshore/tons-of-skills-marketplace

All 3,342 skills in this repo
  • Performing Security Code Review

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to conduct a security-focused code review using the security-agent plugin.

    2.8k GitHub starsUsed in 2 repos~1.3k tokens
    Auto-check: notes
  • Adapting Transfer Learning Models

    jeremylongshore/tons-of-skills-marketplace

    Build this skill automates the adaptation of pre-trained machine learning models using transfer learning techniques.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Agent Context Loader

    jeremylongshore/tons-of-skills-marketplace

    Execute proactive auto-loading: automatically detects and loads agents.md files.

    2.8k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Aggregating Performance Metrics

    jeremylongshore/tons-of-skills-marketplace

    Aggregate and centralize performance metrics from applications, systems, databases, caches, and services.

    2.8k GitHub stars~1.2k tokensUpdated today
    Auto-check passed
  • Analyzing Capacity Planning

    jeremylongshore/tons-of-skills-marketplace

    Execute this skill enables AI assistant to analyze capacity requirements and plan for future growth.

    2.8k GitHub stars~947 tokensUpdated today
    Auto-check passed
  • Analyzing Database Indexes

    jeremylongshore/tons-of-skills-marketplace

    Process use when you need to work with database indexing. An agent skill from jeremylongshore/tons-of-skills-marketplace.

    2.8k GitHub stars~2k tokensUpdated today
    Auto-check passed

Works with

Categories

Questions about Shopify Prod Checklist

What does Shopify Prod Checklist do?

Execute Shopify app production deployment checklist covering App Store requirements, mandatory webhooks, API versioning, and rollback procedures. Shopify Prod Checklist is an agent skill from jeremylongshore/tons-of-skills-marketplace. Execute Shopify app production deployment checklist covering App Store requirements, mandatory webhooks, API versioning, and rollback procedures.

When should I use Shopify Prod Checklist?

Shopify Prod Checklist fits situations like: preparing a Shopify app for production launch; submitting to the App Store; auditing an existing deployment for compliance gaps; with phrases like shopify production.

How do I install Shopify Prod Checklist in Claude Code?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill shopify-prod-checklist -a claude-code`. Or copy the skill folder (skills/.curated/shopify-prod-checklist in jeremylongshore/tons-of-skills-marketplace) into .claude/skills/shopify-prod-checklist in your project. Claude Code loads it when a task matches its description.

How do I install Shopify Prod Checklist in Codex?

Run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill shopify-prod-checklist -a codex`. Or copy the skill folder (skills/.curated/shopify-prod-checklist in jeremylongshore/tons-of-skills-marketplace) into .agents/skills/shopify-prod-checklist in your project. Codex loads it when a task matches its description.

Can I use Shopify Prod Checklist in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add jeremylongshore/tons-of-skills-marketplace --skill shopify-prod-checklist -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/shopify-prod-checklist, .gemini/skills/shopify-prod-checklist, .github/skills/shopify-prod-checklist and .opencode/skills/shopify-prod-checklist in your project.

What does Shopify Prod Checklist need to run?

Going by SKILL.md and its folder, Shopify Prod Checklist needs the command-line tools its instructions call (curl and jq). Its frontmatter pre-approves these tools: Read, Bash(curl:*), Grep. Compatibility (from SKILL.md): Designed for Claude Code.

Does Shopify Prod Checklist access the network?

SKILL.md names 3 domains. In commands or code: admin.shopify.com; the agent is likely to contact it when it follows the instructions. As links in the text: shopify.dev and shopifystatus.com. This is read from the text; nothing was executed.

Is Shopify Prod Checklist safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Shopify Prod Checklist use?

Shopify Prod Checklist is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Shopify Prod Checklist use?

About 1.2k tokens (SKILL.md is roughly 5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 490 tokens, read only when the agent opens those files.

What are the alternatives to Shopify Prod Checklist?

Skills that share tags, products or a category with Shopify Prod Checklist: App Promo Materials (glifxyz/glif-mcp-server, 213 stars), Golive (mikehasa/golive-skill, 1.3k stars), Shopify (Shopify/Shopify-AI-Toolkit, 592 stars) and Ar Io Gateway Operator (ar-io/ar-io-node, 127 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Shopify Prod Checklist?

jeremylongshore (a GitHub user) maintains it in jeremylongshore/tons-of-skills-marketplace, which has 2,827 GitHub stars. The repository holds 3,342 skills in this directory. The repository was last updated on October 10, 2026.

Source: jeremylongshore/tons-of-skills-marketplace on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.