# Leaked Shopify Access Token? Revoke It, Check App Scopes

> Shopify Admin API token exposed on GitHub? Cut off the app, review its scopes and store changes, and handle customer data. Step-by-step guide.

Source: https://leakwatch.net/secrets/shopify-access-token

---

[LeakWatch](/)

[Product](/product)[Live feed](/leaks)[Guides](/secrets)[Blog](/blog)[Free scan](/)

1.  [Home](/)
2.  [Secrets](/secrets)
3.  Shopify Access Token

Payments · Secret guide

# Leaked Shopify Access Token: what to do in the first hour

Critical severityDetected onlyLast verified October 2, 2026 · 5 min read

A Shopify Admin API access token gives an app programmatic access to a store, within the permissions (scopes) that app was granted. Depending on those scopes, the holder can read orders, customers and addresses, change products and prices, edit discounts, and create webhooks. There is no password and no second factor: the token alone is the credential. Cut the app’s access first, then work out what it could see and change.

[Check your GitHub account for leaked secrets — free](/)

Provider

Shopify

Severity

Critical

Impact

Payments and customer data

Checked live by LeakWatch

No

## What a Shopify access token looks like

Admin API access tokens begin with `shpat_` followed by hexadecimal characters:

```text
shpat_…XXXX   Shopify Admin API access token (masked)
```

The same format is used whether the token belongs to a custom app you built for one store or to a public app that was installed on it. The prefix does not say which scopes were granted; you find that in the app’s configuration.

Several nearby values are different. An app’s **API key and API secret key** are the app’s own credentials, used to sign the installation flow, and are rotated separately from any one store’s access token. A **storefront access token** is meant to be used from public front-end code with a narrow set of permissions. And a **webhook secret** only verifies that webhook calls come from Shopify.

## How Shopify access tokens get leaked

-   **Custom app scripts.** Import scripts, inventory syncs and order exports written for one store, with the token pasted in to make them run.
-   **Theme and app repositories.** A `.env` file, `shopify.app.toml` neighbour or deployment file committed with the token.
-   **Agency and freelancer handovers.** A token sent over chat or email, then stored in a shared repository or a ticket.
-   **Integration glue.** Zapier-style scripts, ERP and shipping connectors, and cron jobs that call the Admin API.
-   **Logs and screenshots.** A failed API call printed with its headers, or a screenshot of the app’s credentials page shared for support.

## What to do in the first hour

1.  **Cut off the app.** In the Shopify admin go to *Settings* → *Apps and sales channels*. For a custom app, open *Develop apps*, select the app and uninstall or delete it so its token stops working. Check the Shopify documentation for the exact behavior of your app type. For a public app, remove it from the store’s installed apps and contact its developer.
2.  **Issue a fresh credential.** Create or reinstall the app with the minimum scopes it needs: if a script only reads products, do not grant order or customer access. Store the new token in a secret manager.
3.  **Work out what the old token could reach.** Open the app’s configuration and read its Admin API access scopes. Orders and customer scopes mean personal data was readable; write scopes mean content could be changed.
4.  **Look for changes in the store.** Review recent edits to products, prices, discount codes, shipping rates, payment settings, checkout customizations and theme code. Check the list of webhooks and other installed apps for entries you do not recognize, and the staff accounts for unfamiliar users.
5.  **Check for exfiltration signs.** Bulk customer or order exports around the time of the exposure, or unexplained traffic to your webhook endpoints, are things to note.

Not sure what else leaked? [Run a free scan](/).

6.  **Decide whether customer data needs a notification.** If the token could read customer or order data and you cannot rule out access, you may have obligations under privacy law such as GDPR. Speak to a qualified adviser rather than guessing.
7.  **Then clean the repository**: remove the value and rewrite history if you want to. See [I accidentally pushed an API key to GitHub](/blog/i-accidentally-pushed-an-api-key-to-github).

[Not sure what else leaked? Run a free scan.](/)

## Revoke it at Shopify

There is no single console for every token, because it depends on how the token was created. For a custom app, sign in to the store admin, open *Settings* → *Apps and sales channels* → *Develop apps*, choose the app and review its API credentials; removing or uninstalling the app ends its access. For an app from the Shopify App Store or your own Partner account, uninstall it from *Apps and sales channels* and manage the app’s credentials with its developer or in your Partner dashboard. If you manage several stores, check each one: a token only works on the store it was issued for.

## How LeakWatch detects it

The rule is called Shopify Access Token. It recognizes the `shpat_` prefix followed by 32 hexadecimal characters, a shape specific enough to need no surrounding keyword. LeakWatch detects this format but does not check it live: it can tell you the token is exposed, not whether it still works. Assume it does until you have revoked it.

LeakWatch detects this format but does **not** check it live: it can tell you the key is exposed, not whether it still works. Assume it does until you have revoked it.

## FAQ

Is a Shopify token the same as my admin password?

No. It cannot log in to the admin interface or change your account email. It acts through the API, within the scopes the app was given. That can still be enough to read your customers and change your catalogue.

Does the token work on other stores?

No, a token is tied to the store where the app was installed. Check every store where the same app or script was used.

Do I have to tell my customers?

Only if customer data could have been accessed, and the answer depends on where you operate. Check the scopes and store history, then get advice before deciding.

## Related

-   [Stripe secret key](/secrets/stripe-secret-key)
-   [Razorpay API Key](/secrets/razorpay-key)
-   [AWS access key](/secrets/aws-access-key)
-   [I accidentally pushed an API key to GitHub](/blog/i-accidentally-pushed-an-api-key-to-github)
-   [Which vendors leak most this week](/leaks/trends)
-   [All secret guides](/secrets)

[Get alerted next time a secret leaks — create a free account](/)

LeakWatch is not affiliated with Shopify.

![Gabriel Diyan, founder of LeakWatch](/brand/Photo-Gabriel-Diyan.webp)

Gabriel Diyan (0xCr0c0)

Cybersecurity student, founder of LeakWatch. I built and run the scanner described here — the detection patterns, the false-positive classifier and the provider validators are mine. [More about who I am](/about).

[GitHub](https://github.com/Leakwatch-Scan) · [X](https://x.com/LeakwatchScan) · [LinkedIn](https://www.linkedin.com/in/gabriel-diyan-80a378375) · [GitHub (personal)](https://github.com/crocogab)

LeakWatch

Secrets leak into public commits every minute. This watches the forges for yours. Built and run by [Gabriel Diyan](/about), a cybersecurity student — [why LeakWatch exists](/about).

Scan

-   [Product](/product)
-   [Live feed](/leaks)
-   [Trends](/leaks/trends)
-   [API docs](/docs)
-   [CI/CD](/docs?tab=ci)

Read

-   [Blog](/blog)
-   [Secret guides](/secrets)
-   [Changelog](/changelog)
-   [About](/about)

Verify

-   [Security](/security)
-   [Privacy](/privacy)
-   [Terms](/terms)
-   [Legal](/legal)
-   [Contact](/contact)
-   [Status](https://status.leakwatch.net)

© 2026 LeakWatch

[GitHub](https://github.com/Leakwatch-Scan)[X](https://x.com/LeakwatchScan)
