Scopes
The 48 scopes across 75 operations, generated from the spec — a key carries scopes, and scopes are its whole permission.
A key holds scopes; scopes are the whole permission. Grant the smallest set that covers
the calls the integration makes — an operation outside them is a 403 insufficient_scope,
never a silent partial answer. See Authentication & keys for
who can grant what.
Every row below comes from the Requires scope sentence on the operation itself, so this
table says exactly what the API enforces. The reference pages repeat the scope per operation.
| Scope | Operations |
|---|---|
merchant-analytics-traffic-read | GET /analytics/traffic |
merchant-app-requirements-write | PUT /app/requirements |
merchant-app_alerts-create | POST /app/alerts |
merchant-app_setup-update | PUT /app/setup |
merchant-business_profile-read | GET /store |
merchant-collected-definitions-manage | GET /collected-definitionsPOST /collected-definitionsPATCH /collected-definitions/{definition} |
merchant-collected-records-submit | POST /records |
merchant-collections-create | POST /collections/bulk |
merchant-collections-read | GET /collections |
merchant-collections-update | POST /collections/{collection}/products/pinPOST /collections/{collection}/products/reorder |
merchant-coupons-create | POST /coupons |
merchant-coupons-read | GET /coupons |
merchant-customers-detail | GET /customers/{customer}GET /customers/{customer}/wishlist-items |
merchant-customers-read | GET /customersGET /customers/followers |
merchant-discounts-create | POST /discounts |
merchant-discounts-detail | GET /discounts/{discount} |
merchant-discounts-read | GET /discounts |
merchant-discounts-update | POST /discounts/{discount}/publishPOST /discounts/{discount}/unpublish |
merchant-inventory-detail | GET /inventory/products/{product}/history |
merchant-inventory-read | GET /inventoryGET /inventory/levels |
merchant-inventory-update | POST /inventory/levels/adjustmentsPOST /inventory/adjustments |
merchant-items-create | POST /products |
merchant-items-delete | DELETE /products/{product} |
merchant-items-detail | GET /products/{product}/imagesGET /products/{product}GET /products/{product}/variants |
merchant-items-read | GET /productsGET /storefront/search |
merchant-items-update | POST /products/{product}/imagesPATCH /products/{product}/images/{image}DELETE /products/{product}/images/{image}PUT /products/{product}POST /products/publishPOST /products/{product}/variantsPATCH /products/{product}/variants/{variant}DELETE /products/{product}/variants/{variant} |
merchant-locales-read | GET /locales |
merchant-locales-write | POST /localesPATCH /locales/{locale}DELETE /locales/{locale} |
merchant-media-create | POST /files |
merchant-media-read | GET /files |
merchant-metafields-create | POST /metafield-definitions |
merchant-metafields-read | GET /metafield-definitions |
merchant-metaobjects-create | POST /metaobject-definitionsPOST /metaobjects |
merchant-metaobjects-read | GET /metaobject-definitionsGET /metaobjects |
merchant-orders-import | POST /orders/import |
merchant-orders-read | GET /ordersGET /orders/{order} |
merchant-orders-status-update | POST /orders/{order}/statusPOST /orders/{order}/assign-rider |
merchant-orders-update | PATCH /orders/{order}PATCH /orders/{order}/shipment |
merchant-posts-read | GET /posts |
merchant-reviews-import | POST /reviews/import |
merchant-reviews-read | GET /reviews |
merchant-shipping-create | POST /shipping-zones |
merchant-shipping-read | GET /shipping-zones |
merchant-shipping-update | PUT /shipping-zones/{zone} |
merchant-stock_adjustments-read | GET /inventory/adjustments |
merchant-team-directory-read | GET /team-directory |
merchant-translations-read | GET /translatable-resourcesGET /translatable-resources/{type}/{id} |
merchant-translations-write | PUT /translations/{type}/{id}DELETE /translations/{type}/{id} |
A write scope also returns, in that write’s own response, the record it wrote — listing or reading records needs the matching read scope.