Integration · Shopify

Let your AI agent refund Shopify orders — safely.

Test order refunds and cancellations against a simulated Shopify store that fails on purpose. In production, COLVO holds the Admin API token, applies your limits and checks every result in your store.

How it works

Set it up in minutes

  1. Test without a store. In “Choose scenarios…”, pick Shopify: 10 scenarios run against a simulated store — orders like #1042, partial refunds, cancel + refund, another customer’s order, and lost responses.
  2. Create an app for COLVO in Shopify → Settings → Apps and sales channels → Develop apps, with only read_orders, write_orders and read_customers. Paste the store address and the Admin API token (shpat_…); COLVO checks the scopes without changing anything.
  3. Add two webhooks (refunds/create, orders/cancelled) with the URL COLVO shows and paste the signing secret. Refunds and cancellations made outside COLVO open an incident.
  4. Your agent proposes, COLVO executes. The agent never holds the token. Guard decides ALLOW, REVIEW, HOLD or DENY, reads the order first, refunds or cancels once, and re-reads Shopify to verify.

Actions on Shopify today

refund.create   payment_id = the order (#1042, numeric id or gid), amount_minor, currency   → a refund on the order (nothing restocked)
order.cancel    order_id, refund: true | false, restock?, reason?                         → cancels the order; with refund, what is left on it

Not on Shopify: subscription actions (subscriptions live in Shopify apps), plan changes, coupons

The agent never holds your payment keys — it proposes, COLVO decides and executes.

What you get

Shopify + COLVO

A mandate names the orders

Mandates list the orders this conversation may touch (subject.order_ids). An agent that names another customer’s order is denied before anything is sent.

Cancel + refund is one action

COLVO reads what is still refundable on the order before deciding, so the limit applies to the real amount — and the refund can’t be sent twice as a cancel plus a separate refund.

A retry never doubles a refund

Shopify takes no idempotency keys. COLVO marks every refund note with its operation id and looks for it before any retry, so a lost response can’t become a second refund.

Questions

Shopify FAQ

Does the agent need my Shopify token?

No — remove it. Only COLVO’s executor uses the token, encrypted per organisation.

Which scopes?

`read_orders`, `write_orders` and `read_customers`. COLVO warns about any other scope on the token.

Subscriptions on Shopify?

Not yet: Shopify subscriptions live in third-party apps (Recharge, Loop…). COLVO refuses subscription actions on a Shopify connection.

Development stores?

Yes — connect a development store first; a live store is a separate connection.

Reference: Mandates & connections · Webhooks

≠

Stop trusting the reply.

Test your agent before it ships — and guard every real action once it’s live. In a safe copy of your world first.

Shopify AI agent testing and guardrails — COLVO · COLVO