beta v2.2636.5
Headless

Shopify Headless App Help: Storefront Tokens, Permissions and Setup

The Shopify Headless app is Shopify's own free sales channel for stores selling through a custom front end on the Storefront API. Once installed, it creates storefronts with public and private access tokens, sets API permissions and rotates private keys, all from the Shopify admin. A shop can hold up to 100 active storefronts and access tokens. View Headless on the App Store.

Installing the channel is the easy step. Problems come from the integration around it: a private token shipped in browser code, missing buyer IP headers that get real shoppers throttled, permissions wider than the build needs, and key rotations that knock the live site over.

When no profile below fits, the headless development and API integration specialists linked at the end of this page take on Headless app work as well.

Begin the brief with where your front end runs and how many storefronts you plan.

Headless channel jobs worth handing to a developer

The channel holds the keys. Most of the skill is in where those keys end up and what they are allowed to do.

Storefronts and their tokens. Creating a storefront generates its public and private tokens. More storefronts are added under Sales channels > Headless > Add storefront, and each one counts as its own channel for order attribution.

Putting each token in the right place. Public tokens are built for browser or mobile code, where buyers can see them. Private tokens belong on the server, sent in their own header, and never in client code.

Forwarding the shopper's IP. Server-side requests made for buyers should send the Shopify-Storefront-Buyer-IP header. Without it, Shopify can't tell buyers apart, which can mean throttling, weaker bot protection and unauthenticated checkout flows.

Scoping permissions. Installing the channel creates a default permission set you can edit. Shopify's advice is to request only the scopes the app needs.

Rotating a private key. Generate the new token, move every app and script onto it, then delete the old one. Deletion can't be undone.

Deciding what each storefront sells. The channel supports product publishing, scheduled publishing, analytics and sales reporting by channel.

The site on top. The front end calling the API is its own build. Headless development specialists handle that part.

Questions for a developer wiring the Headless channel

Any developer can install the channel. These questions show who has run a Storefront API integration under real traffic.

Which token goes where? Public token in the browser or app, private token only on the server. Anyone planning to put the private token in front-end code should not get the job.

How will you pass the buyer's IP? They should name the Shopify-Storefront-Buyer-IP header and know it is case-sensitive.

What happens when checkout creation is throttled? Shopify throttles it per minute and returns a 200 Throttled error. The answer you want is a request queue with exponential backoff, which is what Shopify suggests.

How do you treat bots? Bot and crawler traffic is rate limited, most strictly when unsigned, and Web Bot Auth signing raises the limits. Requests that look malicious get a 430 Shopify Security Rejection.

How do you rotate keys without downtime? New token first, every consumer updated, old token deleted last.

A first task worth paying for. One storefront with trimmed permissions, server requests carrying the buyer IP, and a one-page token map showing which key lives where. API integration specialists do this kind of work routinely.

Shopify Headless app limits and token rules

100 per shop. A shop can have up to 100 active storefronts and access tokens.

Permissions are shared. Storefront and Admin API permissions apply across all storefronts, so one storefront can't be scoped more narrowly than another.

Deletes are final. Deleting a storefront invalidates its Storefront API tokens and can't be undone. A rotated private token stays valid until you delete it.

Some data needs no token. Tokenless access covers products, collections, selling plans, search, pages, blogs and articles, and cart, with a query complexity limit of 1,000. Product tags, metaobjects, metafields, menus and customers need a token.

Who can set it up. Setup needs a staff account with Apps and channels permissions.

Rate limits target bots. Buyer traffic has no fixed requests-per-minute limit; bots and crawlers are limited.

Plus bot protection is narrow. On Shopify Plus it applies to the Cart object only, not Checkout.

Orders name the storefront. The Channel column on the Orders page shows which storefront made each sale.

Headless app projects to scope

Each of these is a contained job, separate from building the front end.

Headless storefront setup

Storefront created, tokens issued and stored where they belong

Permission trim

Scopes cut back to what the front end actually queries

Buyer IP header fix

Server requests forwarding each shopper's IP to avoid throttling

Private key rotation

New token rolled out, old one deleted once nothing uses it

Storefront-level attribution

One storefront per site or app, with orders tracked by name

Checkout throttle handling

Request queue with exponential backoff for checkout creation

Shopify Headless channel questions from merchants

Is the Shopify Headless app free?

Yes. As of October 2026 the App Store lists it as free, made by Shopify and launched in January 2023. Spending goes on the custom front end and the integration work, so budget for development rather than the channel. The headless commerce guide explains what that route involves.

Do I need the Headless app to use the Storefront API?

Not for everything. Tokenless access reads products, collections, search, pages and cart. Product tags, metaobjects, metafields, menus and customers need a token, and the Headless channel is where merchants create and manage tokens in the admin. Developers can also create public tokens through the Admin API.

Can one Shopify store run several headless storefronts?

Yes, up to 100 active storefronts and tokens per shop. Each storefront counts as its own channel for attribution, and the Orders page shows its name in the Channel column. The catch is that API permissions are shared across all of them, so plan scopes for the most demanding storefront.

Is it safe for a public token to be visible in the browser?

Yes, that is what it is for. Shopify describes public tokens as meant for browser or mobile use, where buyers can see them. Private tokens are the ones to protect: server-side only, sent in their own header, and rotated if they ever leak.

What should I send a developer setting up the Shopify Headless app?

Where your front end runs, how many storefronts you need, and which data it reads, especially metafields, metaobjects or customer data. Add your checkout flow, whether you are on Shopify Plus, and who on your team should hold the private keys after handover.