Payments · Secret guide

Leaked Shopify Access Token: what to do in the first hour

Critical severityDetected onlyLast verified · 5 min read

A Shopify Admin API access token gives an app programmatic access to a store, within the permissions (scopes) that app was granted. Depending on those scopes, the holder can read orders, customers and addresses, change products and prices, edit discounts, and create webhooks. There is no password and no second factor: the token alone is the credential. Cut the app’s access first, then work out what it could see and change.

Check your GitHub account for leaked secrets — free

Provider
Shopify
Severity
Critical
Impact
Payments and customer data
Checked live by LeakWatch
No

What a Shopify access token looks like

Admin API access tokens begin with shpat_ followed by hexadecimal characters:

shpat_…XXXX   Shopify Admin API access token (masked)

The same format is used whether the token belongs to a custom app you built for one store or to a public app that was installed on it. The prefix does not say which scopes were granted; you find that in the app’s configuration.

Several nearby values are different. An app’s API key and API secret key are the app’s own credentials, used to sign the installation flow, and are rotated separately from any one store’s access token. A storefront access token is meant to be used from public front-end code with a narrow set of permissions. And a webhook secret only verifies that webhook calls come from Shopify.

How Shopify access tokens get leaked

  • Custom app scripts. Import scripts, inventory syncs and order exports written for one store, with the token pasted in to make them run.
  • Theme and app repositories. A .env file, shopify.app.toml neighbour or deployment file committed with the token.
  • Agency and freelancer handovers. A token sent over chat or email, then stored in a shared repository or a ticket.
  • Integration glue. Zapier-style scripts, ERP and shipping connectors, and cron jobs that call the Admin API.
  • Logs and screenshots. A failed API call printed with its headers, or a screenshot of the app’s credentials page shared for support.

What to do in the first hour

  1. Cut off the app. In the Shopify admin go to Settings → Apps and sales channels. For a custom app, open Develop apps, select the app and uninstall or delete it so its token stops working. Check the Shopify documentation for the exact behavior of your app type. For a public app, remove it from the store’s installed apps and contact its developer.
  2. Issue a fresh credential. Create or reinstall the app with the minimum scopes it needs: if a script only reads products, do not grant order or customer access. Store the new token in a secret manager.
  3. Work out what the old token could reach. Open the app’s configuration and read its Admin API access scopes. Orders and customer scopes mean personal data was readable; write scopes mean content could be changed.
  4. Look for changes in the store. Review recent edits to products, prices, discount codes, shipping rates, payment settings, checkout customizations and theme code. Check the list of webhooks and other installed apps for entries you do not recognize, and the staff accounts for unfamiliar users.
  5. Check for exfiltration signs. Bulk customer or order exports around the time of the exposure, or unexplained traffic to your webhook endpoints, are things to note.

Not sure what else leaked? Run a free scan.

  1. Decide whether customer data needs a notification. If the token could read customer or order data and you cannot rule out access, you may have obligations under privacy law such as GDPR. Speak to a qualified adviser rather than guessing.
  2. Then clean the repository: remove the value and rewrite history if you want to. See I accidentally pushed an API key to GitHub.

Not sure what else leaked? Run a free scan.

Revoke it at Shopify

There is no single console for every token, because it depends on how the token was created. For a custom app, sign in to the store admin, open Settings → Apps and sales channels → Develop apps, choose the app and review its API credentials; removing or uninstalling the app ends its access. For an app from the Shopify App Store or your own Partner account, uninstall it from Apps and sales channels and manage the app’s credentials with its developer or in your Partner dashboard. If you manage several stores, check each one: a token only works on the store it was issued for.

How LeakWatch detects it

The rule is called Shopify Access Token. It recognizes the shpat_ prefix followed by 32 hexadecimal characters, a shape specific enough to need no surrounding keyword. LeakWatch detects this format but does not check it live: it can tell you the token is exposed, not whether it still works. Assume it does until you have revoked it.

LeakWatch detects this format but does not check it live: it can tell you the key is exposed, not whether it still works. Assume it does until you have revoked it.

FAQ

Is a Shopify token the same as my admin password?

No. It cannot log in to the admin interface or change your account email. It acts through the API, within the scopes the app was given. That can still be enough to read your customers and change your catalogue.

Does the token work on other stores?

No, a token is tied to the store where the app was installed. Check every store where the same app or script was used.

Do I have to tell my customers?

Only if customer data could have been accessed, and the answer depends on where you operate. Check the scopes and store history, then get advice before deciding.

Get alerted next time a secret leaks — create a free account

LeakWatch is not affiliated with Shopify.