beta v2.2636.5
Theme Access

Shopify Theme Access Help: Safe Developer Access to Your Theme

Shopify Theme Access is Shopify's own free app for giving a developer theme-only access without making them a staff account. You create a password, Shopify emails it as a one-time link, and the developer uses it with Shopify CLI. Each password carries write access to themes only, and you can create as many as you need. See how Shopify lists it.

The app takes minutes. Merchants land here because they need the developer, not the password: someone to change or rebuild a theme, set up deployments from a code repository, or take over from a previous agency and tidy up who still has access.

When no profile below fits, the theme customization and maintenance specialists linked at the end of this page take on Theme Access work as well.

Tell a new developer your theme name and version, what should change, and whether they may touch the live theme or only a copy.

Theme work that starts with a Theme Access password

The password is the door. These are the jobs merchants open it for.

Code-level theme changes. New sections, templates and layout edits made in code and pushed with Shopify CLI. This is theme customization work, and usually the first job on the list.

Ground-up builds. A developer building a theme from scratch pushes it to your store with the same kind of password. That is custom theme development work.

Deploys from a repository. In CI/CD, the password goes into the SHOPIFY_CLI_THEME_TOKEN environment variable, so theme changes ship from version control instead of from someone's laptop.

Agency handover cleanup. Listing who holds a password, deleting old contractors' access and issuing fresh ones. A deleted password can't be brought back, only replaced.

Retiring Theme Kit. Theme Kit is deprecated, so a developer still on it should move to Shopify CLI. Passwords from the older Theme Kit Access app and from Theme Access are interchangeable.

Ongoing upkeep. Theme updates and fixes on a retainer, usually from store maintenance specialists working under their own password.

No outside help needed. If you already have a developer, install the app and send the password yourself. It takes less time than briefing someone else to do it.

Vetting a developer before you send a theme password

A Theme Access password lets someone write to your themes. Check how they work before you create one.

Ask where they'll make changes. A careful developer works on an unpublished copy and sends a preview link before anything goes live. The password itself doesn't enforce that, so it has to be agreed.

Ask how they'll connect. Expect Shopify CLI with the --password flag, or an environment variable in a pipeline. Anyone still on Theme Kit should explain why.

Ask about version control. Theme code kept in a Git repository makes every change traceable. Ask who owns that repository when the contract ends.

Ask what else they need. Theme Access covers themes only. Work on apps, products or settings means a staff or collaborator account, which deserves its own decision.

Be cautious when a developer asks for the store owner login instead. Theme Access gives them what theme work needs without it.

One section, one preview. A paid first task: change a single section on an unpublished theme and deliver it with a preview link and a short note on what changed in the code.

How Shopify Theme Access passwords behave

Who can issue them. The store owner, or staff and collaborators with the Themes permission under Online store.

The link is single-use. Shopify emails the password as a link that expires after 7 days or once it is viewed, and the developer can view the password only once. A resend from the Passwords page follows the same rules.

Scope stops at themes. Passwords carry the write_themes scope: write access to themes and nothing beyond it.

One per person. The listing allows unlimited passwords, so give each developer their own instead of sharing one. It makes revoking a single person clean.

Deleting is permanent. Removing a password ends that developer's theme access. Restoring it means a new password.

Pipelines hold a live credential. In CI/CD the password sits in the SHOPIFY_CLI_THEME_TOKEN variable. Store it as a secret and delete the password when the pipeline is retired.

The app reads staff details. On install it can see store owner and staff details and edit the online store theme.

Developer access projects to scope

Most jobs that begin with a Theme Access password fit one of these.

Developer onboarding

Password issued, unpublished theme copy set up, preview links agreed

Theme access audit

Old contractor passwords deleted and current holders listed

CLI deploy pipeline

Theme deploys from a repository using a stored token

Theme Kit retirement

A developer workflow moved over to Shopify CLI

Section and template edits

Changes coded on a copy and previewed before publishing

Theme upkeep retainer

Monthly fixes and updates under one named password

Shopify Theme Access questions from store owners

Is Shopify Theme Access free?

Yes. As of October 2026 the App Store lists it as free, and it allows unlimited passwords. What you pay for is the developer's time. Shopify built the app so theme developers can work on a store without anyone creating a staff account for them.

Can a developer with a theme password see my orders or customers?

Shopify scopes Theme Access passwords to write access to themes only, the write_themes scope. Orders, customers and settings aren't part of that. If a developer genuinely needs those areas, set up a staff or collaborator account with the permissions the job requires, and remove it when the work ends.

What if my developer missed the password email?

The emailed link expires after 7 days or as soon as it's viewed, and the password can be viewed only once. Open the Passwords page in the app, click Details, then Resend email. The new link follows the same rules, so ask the developer to save the password somewhere secure straight away.

How do I remove a developer's access?

Go to the Passwords page in the app, click Delete next to the developer and confirm. Their access to your themes ends there. If you work with them again, create a new password, because a deleted one can't be restored. Make this part of closing every theme contract.

Does my developer need Theme Access if they already have a collaborator account?

Not always. Theme Access is for developers without an account on your store. Someone with a staff or collaborator account and the Themes permission can install the app and create passwords too, which is useful for connecting a CI/CD pipeline that needs a token rather than a person's login.