Skip to content
Skillv1.0.0

shopify-prod-checklist

Execute Shopify app production deployment checklist covering App Store requirements, mandatory webhooks, API versioning, and rollback procedures. Use when preparing a Shopify app for production launch

by jeremylongshore(0) 0 installs
Free
Sign in to install

Free account. Installing gives you the manifest plus copy-paste snippets.

See reviews

About

Imported from jeremylongshore/tons-of-skills-marketplace (plugins/saas-packs/shopify-pack/skills/shopify-prod-checklist/SKILL.md). Install upstream with npx skills add jeremylongshore/tons-of-skills-marketplace --skill shopify-prod-checklist. Copyright stays with the author (MIT).

Shopify Production Checklist

Overview

Complete pre-launch checklist for deploying Shopify apps to production and submitting to the Shopify App Store.

Prerequisites

  • Staging environment tested and verified
  • Shopify Partner account with app configured
  • All development and staging tests passing

Instructions

Step 1: API and Authentication

  • Using a recent stable API version (e.g., 2025-04), not unstable
  • Access token stored in secure environment variables (never in code)
  • API secret stored securely for webhook HMAC verification
  • OAuth flow tested with a fresh install on a clean dev store
  • Session persistence implemented (database or Redis, not in-memory)
  • Token refresh/re-auth handled for expired sessions
  • APP_UNINSTALLED webhook handler cleans up sessions

Step 2: Mandatory GDPR Compliance

  • customers/data_request webhook handler implemented
  • customers/redact webhook handler implemented
  • shop/redact webhook handler implemented (fires 48h after uninstall)
  • All three configured in shopify.app.toml
  • Handlers respond with HTTP 200 within 5 seconds
  • Customer data deletion actually works (test it!)

Step 3: Webhook Security

  • All webhooks verify X-Shopify-Hmac-Sha256 using HMAC-SHA256
  • Using crypto.timingSafeEqual() for signature comparison
  • Webhook endpoints use raw body parsing (not JSON middleware)
  • Idempotency: duplicate webhook deliveries handled gracefully

Step 4: Rate Limit Resilience

  • GraphQL queries optimized (check requestedQueryCost with debug header)
  • Retry logic with exponential backoff for 429 / THROTTLED responses
  • Bulk operations used for large data exports instead of paginated queries
  • No unbounded loops that could exhaust rate limits

Step 5: Error Handling

  • All GraphQL mutations check userErrors array (200 with errors!)
  • HTTP 4xx/5xx errors caught and logged with X-Request-Id
  • Graceful degradation when Shopify is unavailable
  • No PII logged (customer emails, addresses, phone numbers)

Step 6: App Store Submission Requirements

  • App listing has clear name, description, and screenshots
  • Privacy policy URL provided
  • App has proper onboarding flow for new merchants
  • Embedded app uses App Bridge for navigation (no full-page redirects)
  • CSP headers set: frame-ancestors https://*.myshopify.com https://admin.shopify.com
  • App works on both desktop and mobile admin
  • Loading states shown during API calls (no blank screens)

Step 7: API Version Management

# Check which API versions your store supports
curl -s -H "X-Shopify-Access-Token: $TOKEN" \
  "https://$STORE/admin/api/versions.json" \
  | jq '.supported_versions[] | select(.supported == true) | .handle'

# Shopify deprecates versions ~12 months after release
# Set a calendar reminder to upgrade quarterly

Step 8: Health Check Endpoint

Express endpoint that tests Shopify API connectivity and database availability, returning structured status with latency metrics.

See Health Check Endpoint for the complete implementation.

Output

  • All checklist items verified
  • Health check endpoint operational
  • GDPR compliance webhooks functional
  • App ready for production traffic or App Store submission

Error Handling

Alert Condition Severity
Shopify API down 5xx errors > 5/min P1 - Critical
Auth failures 401 errors > 0 P1 - Token may be revoked
Rate limited THROTTLED > 5/min P2 - Reduce query cost
High latency p95 > 3000ms P2 - Check query complexity
Webhook failures Delivery success < 95% P2 - Check endpoint health

Examples

Pre-Deploy Smoke Test

Bash script that validates Shopify auth and API scopes before deploying to production.

See Pre-Deploy Smoke Test for the complete script.

Resources

Use it

Copy one of these into your project. Installing also returns the manifest and these snippets.

yaml
targets:
  - https://api.opensmartroute.ai/api/v1/registry/jeremylongshore-tons-of-skills-marketplace-shopify-prod-dbf3f3/manifest   # or paste the manifest below

Manifest

An Open Capability Manifest: the router reads it to know what this does, what it costs and when to pick it.

jeremylongshore-tons-of-skills-marketplace-shopify-prod-dbf3f3.ocm.jsonjson
{
  "ocm": "1",
  "id": "jeremylongshore-tons-of-skills-marketplace-shopify-prod-dbf3f3",
  "kind": "skill",
  "name": "shopify-prod-checklist",
  "description": "Execute Shopify app production deployment checklist covering App Store requirements, mandatory webhooks, API versioning, and rollback procedures. Use when preparing a Shopify app for production launch, submitting to the App Store, or auditing an existing deployment for compliance gaps. Trigger with phrases like \"shopify production\", \"deploy shopify\", \"shopify go-live\", \"shopify launch checklist\", \"shopify app store submit\".",
  "publisher": "jeremylongshore",
  "version": "1.0.0",
  "capabilities": {
    "domains": [
      "coding",
      "legal"
    ],
    "tags": [
      "skill-md",
      "saas",
      "ecommerce",
      "shopify",
      "skills-sh"
    ],
    "languages": [
      "en"
    ]
  },
  "quality_prior": 0.6,
  "examples": [
    "Execute Shopify app production deployment checklist covering App Store requirements, mandatory webhooks, API versioning, and rollback procedures. Use when preparing a Shopify app for production launch, submitting to the App Store, or auditing an existing deployment for compliance gaps. Trigger with phrases like \"shopify production\", \"deploy shopify\", \"shopify go-live\", \"shopify launch checklist\", \"shopify app store submit\"."
  ],
  "primary": false,
  "metadata": {
    "source": {
      "provider": "skills.sh",
      "repository": "https://github.com/jeremylongshore/tons-of-skills-marketplace",
      "path": "plugins/saas-packs/shopify-pack/skills/shopify-prod-checklist/SKILL.md",
      "ref": "HEAD",
      "url": "https://github.com/jeremylongshore/tons-of-skills-marketplace/blob/HEAD/plugins/saas-packs/shopify-pack/skills/shopify-prod-checklist/SKILL.md",
      "key": "jeremylongshore/tons-of-skills-marketplace/plugins/saas-packs/shopify-pack/skills/shopify-prod-checklist/SKILL.md"
    },
    "compatibility": "Designed for Claude Code",
    "allowed_tools": [
      "Read,",
      "Bash(curl:*),",
      "Grep"
    ],
    "license": "MIT"
  },
  "instructions": "# Shopify Production Checklist\n\n## Overview\n\nComplete pre-launch checklist for deploying Shopify apps to production and submitting to the Shopify App Store.\n\n## Prerequisites\n\n- Staging environment tested and verified\n- Shopify Partner account with app configured\n- All development and staging tests passing\n\n## Instructions\n\n### Step 1: API and Authentication\n\n- [ ] Using a recent stable API version (e.g., 2025-04), not `unstable`\n- [ ] Access token stored in secure environment variables (never in code)\n- [ ] API secret stored securely for webhook HMAC verification\n- [ ] OAuth flow tested with ",
  "cost": {
    "context_tokens": 1073
  }
}

Fetch it by URL: GET /api/v1/registry/jeremylongshore-tons-of-skills-marketplace-shopify-prod-dbf3f3/manifest?version=1.0.0

Reviews

Star ratings from people who tried it. One review per account; edit yours any time.

No reviews yet. Install it, try it, and be the first to rate it.