Giving a Shopify app access to your store is only as safe as the permissions (OAuth scopes) you grant it. Whenever you approve scopes like write_themes, write_products, or read_customers, any bug, database failure, or security breach on the developer's server can directly delete your store collections or compromise customer records. For tasks like designing notification email templates, granting store access is unnecessary and dangerous—zero-permission tools offer complete immunity by keeping your store database untouched.
When evaluating an application in the Shopify App Store, merchants frequently overlook the permission prompt, treating it like routine software terms of service. In cloud architecture, however, every granted scope represents an authorized programmatic API bridge.
Understanding Shopify OAuth Scopes
Shopify categorizes permissions into granular read and write privileges. Here is what the most common scopes actually allow an external vendor to do:
write_themes: Allows external servers to read, overwrite, and delete Liquid template files in your active theme. A single software bug in an app holding this scope can take your entire storefront offline or delete product collection templates.read_products&write_products: Allows an app to query catalog data, modify inventory counts, update descriptions, and alter or erase collections.read_customers&read_orders: Grants access to sensitive personally identifiable information (PII), including customer names, physical shipping addresses, email addresses, and purchase histories.read_analytics: Exposes gross revenue figures, average order value (AOV), and conversion telemetry to third-party databases.
If an application provides real-time warehouse logistics or multicarrier shipping label generation, reading orders and inventory is functionally required. But when an email design tool asks for these same privileges, it introduces an unnecessary operational liability.
The Principle of Least Privilege in E-commerce
Security engineers universally follow the Principle of Least Privilege: software should only be granted the absolute minimum permissions necessary to complete its function.
Notification emails in Shopify (order confirmation, shipping confirmation, out for delivery, refunds) are parsed and dispatched natively by Shopify's core Liquid engine. Because Shopify itself compiles these emails using order data at checkout, an email styling app does not need to read your customers or access your active theme code.
The Zero-Scope Standard
Zero-permission apps (configured with scopes = "") generate safe, static Liquid markup directly in your browser. You copy and paste the generated code into Shopify's native notification settings, eliminating external API bridges completely.
How to Audit Your Active Shopify App Permissions
To review which applications currently hold read and write access to your store:
- In your Shopify Admin, navigate to Settings > Apps and sales channels.
- Click on any installed application to review its App details.
- Inspect the Privacy and permissions breakdown.
- If an app requests permissions unrelated to its core service (such as an email design editor asking for
write_themes), consider uninstalling it or switching to a sovereign alternative.
By minimizing the number of third-party apps holding administrative keys to your store, you safeguard your customer trust, maintain your organic search rankings, and protect your store against unexpected vendor outages.
No OAuth scopes, no theme modifications, 100% store safe