Documentation & trust

Product and API use

Shopify API and StoreAdOps

StoreAdOps is a hosted SaaS product and secure tool service that reads a merchant's Shopify catalog, inventory, and order economics through the Shopify Admin API to inform paid-media decisions. The Shopify integration is read-only.

Business model

StoreAdOps is currently offered as a free private-alpha SaaS product. Paid subscription plans and external billing are not active. StoreAdOps does not sell products, purchase media, or operate as an agency. Merchants remain responsible for their own Shopify store and their own advertising accounts.

Shopify access requested

When a merchant installs StoreAdOps, it requests the following read-only scopes through Shopify's OAuth consent screen:

No write scopes are requested. StoreAdOps cannot modify your store, create or edit products or orders, or change inventory, and it uses the Shopify GraphQL Admin API only.

How a merchant connects Shopify

  1. The merchant installs StoreAdOps from the Shopify App Store or Shopify Admin.
  2. Shopify hands off to StoreAdOps with a signed shop identity; the merchant never types their store domain.
  3. The merchant signs in to StoreAdOps and approves the read-only Shopify OAuth consent screen.
  4. StoreAdOps stores an encrypted access token scoped to that single store.
  5. The signed-in merchant creates a revocable, tenant-scoped API key for an MCP-compatible AI client, which can then read only that store.

Shopify use cases

Read workflows include store context, product listing and search, product detail and image metadata, inventory and stock-risk checks, collections, exact processed-order revenue summaries, product-margin estimates, product ad-readiness analysis, and product recommendations for paid media. Reporting queries do not request customer names, email addresses, phone numbers, or postal addresses.

There are no management or write workflows for Shopify; the integration cannot change your store.

Safety and authorization controls

Data handling

Shopify store data is retrieved live during tool execution and is not persisted as a catalog or order-data warehouse. StoreAdOps stores an encrypted Shopify OAuth token, connection metadata (including the basic installing-user account details Shopify returns), hashed API keys, OAuth state, idempotency records, and write audit records. StoreAdOps does not store your customers' personal data, and order data is read without customer PII.

Your Shopify data is not sold and is not used to train general AI models. You can revoke access at any time by uninstalling StoreAdOps from your Shopify admin, and request deletion through support@storeadops.ai.

Privacy compliance webhooks

StoreAdOps implements all three Shopify-mandatory privacy webhooks at a single HMAC-verified endpoint:

Shopify tools (10 tools)

StoreAdOps exposes the following read-only Shopify tools to connected AI clients: Ten shared tools serve all channels. Use get_capabilities to discover account-eligible operations and their input schemas. Reads do not change campaigns; report starts create explicit report jobs. Changes require a preview, confirmation and an idempotency key. Availability depends on connected accounts, permissions, assets and enabled features.

get_connections_status

    get_capabilities

      query

      • account.verifyRequires granted scopes: read_products.
      • shopify.collectionsRequires granted scopes: read_products.
      • shopify.ordersRequires granted scopes: read_orders.
      • shopify.productRequires granted scopes: read_products.
      • shopify.productsRequires granted scopes: read_products.
      • shopify.products.recommendRequires granted scopes: read_products.
      • shopify.storeRequires granted scopes: read_products.

      get_report

        prepare_change

          execute_change

            get_change_status

              get_merchant_profile

                record_recommendation

                  get_recommendation_history

                    Frequently asked questions

                    What can StoreAdOps do with my Shopify store?

                    After you install and authorize the app, connected AI clients can read your product catalog, inventory, and order economics to inform ad decisions. It cannot change your store.

                    Do you store my customers' data?

                    No. Order data is read without customer PII, and store data is fetched live during tool execution rather than warehoused.

                    Is this an embedded Shopify app?

                    No. StoreAdOps is a non-embedded, first-party app; installation begins from Shopify and continues in your StoreAdOps session after OAuth.

                    How do I disconnect or delete my data?

                    Uninstall StoreAdOps from your Shopify admin; the shop/redact webhook deletes your stored connection. You can also request deletion through support@storeadops.ai.