Authentication

EasyStore Apps authenticate with OAuth 2.0 (Authorization Code Grant). When a merchant installs your app, your app gets an access token for that store, and sends it with every API request.

📖 This page is a quick reference. For the full step-by-step guide with diagrams, code and test values, see Develop app: App installation.

Credentials

Create an app in the Partner Dashboard to get its Client ID and Client secret. Keep the Client secret on your server only. It is used to get access tokens and to verify every request EasyStore sends you.

OAuth flow at a glance

Step Request Details
1. EasyStore opens your App URL GET {App URL}?shop=...&host_url=...&timestamp=...&hmac=... Installation steps 1–3
2. Your app asks for permission {host_url}/oauth/authorize?client_id=...&scope=...&redirect_uri=... Installation step 4, scopes
3. EasyStore redirects back GET {redirect_uri}?code=...&shop=...&host_url=...&timestamp=...&hmac=... Installation step 6
4. Your app gets the access token POST https://{shop}/api/3.0/oauth/access_token.json with code, client_id, client_secret (JSON body) Installation steps 7–8

The authorization code is valid for 5 minutes and can be exchanged only once. The access token stays valid until the merchant uninstalls your app.

Making authenticated requests

Send the access token in the EasyStore-Access-Token header with every API request:

curl 'https://{shop}/api/3.0/products.json' \
--header 'EasyStore-Access-Token: {access_token}'

The token can only access the scopes the merchant approved. See Calling the API and Popular APIs.

Security checks

Before trusting any request from EasyStore, your app must:

  • Verify the hmac parameter (or the Easystore-Hmac-Sha256 header for webhooks). See Request HMAC verification and Webhook HMAC verification.
  • Check that shop is a valid hostname ending with .easy.co. Your app sends its Client secret to https://{shop}, so never trust an unchecked value.
  • Reject requests whose timestamp is too old, to prevent replays.
icon-accounticon-add-newicon-add-storeicon-appicon-appleicon-archiveicon-arrowdownicon-ascicon-bookicon-cancelicon-cart-addonicon-checkouticon-cherryicon-collectionicon-comfirmicon-confirmicon-couponicon-creditsicon-currencyicon-dashboardicon-discounticon-disintegrateicon-domainicon-dscicon-duplicateicon-editicon-emailicon-exclamation-triangleicon-exporticon-eyeicon-eye-slashicon-fullscreenicon-fullscreen-closeicon-generalicon-gifticon-gridicon-hddicon-helpicon-importicon-infoicon-integrationicon-invoiceicon-likeicon-listicon-locationicon-logouticon-new-tabicon-not-secureicon-optionicon-ordericon-outline-arrowdownicon-pageicon-paymenticon-plusicon-posicon-pricingicon-printericon-producticon-product-sumicon-product-sum-xicon-redirecticon-reporticon-reseticon-searchicon-secureicon-settingicon-shippingicon-staricon-storeicon-switch-storeicon-tagicon-taxesicon-templateicon-themeicon-tickicon-trashicon-unarchiveicon-uploadicon-user-tagicon-usersicon-weighticon-wholesale