← All integrations
Theme app extension

Shopify, openly documented.

Installs the Saazly widget in your store theme. This version does not read orders or request order permissions.

Development installation

Technical candidate ready for verification in a development store.

Platform review

Submitted to Shopify and awaiting approval.

Public listing

Not published. Availability will only be claimed once Shopify has approved it.

01 / From zero to widget

Installation

Install the app in a Shopify development store or use the installation link provided by Saazly.

Open the embedded app in Shopify Admin. The Shopify session is verified and the installation's offline token is created or rotated.

Select Connect studio. A new first-party Saazly window requires a signed-in administrator and only shows active widgets in the selected studio.

Select a widget and approve the connection.

Open the theme editor from the activation link, enable Saazly Chat and save the theme.

02 / Minimum access

Permissions and scopes

Admin API scopes

None in the widget version. The configuration uses an empty scope list.

Order data

No order data is read or written. Order permissions are not included.

Store identity

The Shopify session token identifies the store and user session. On its own, it never grants the right to select a Saazly studio.

03 / Data contract

Data read and written

Read from Shopify

Store domain and signed session claims. On the storefront, the widget reads a browser-reported cart from the store's own cart.js.

Written to Shopify

No business data. The merchant enables the app embed and saves the Widget ID in the theme settings.

Written to Saazly

Store domain, encrypted offline access token, encrypted refresh token, expiry time, studio id and widget id. Every connection is scoped to a studio.

04 / Events

Webhooks

app/uninstalled

Removes active token access and marks the installation as uninstalled.

customers/data_request

Verified and logged. The widget installation does not store a Shopify customer profile.

customers/redact

Verified and logged. The widget installation has no Shopify customer profile to delete.

shop/redact

Deletes the installation record and any future Shopify catalogue data for the connected studio.

05 / Secrets

Token storage

At rest

The access token and refresh token are encrypted with AES 256 GCM before being written to the database. Clients never receive token values.

Rotation

Expiring offline tokens are rotated with the refresh token five minutes before expiry. The database's updated_at is used as an optimistic rotation lock.

Revocation

Shopify revokes access when the app is uninstalled. The webhook then clears both encrypted token fields and active local access.

06 / Clean removal

Uninstallation

Uninstall Saazly Chat in Shopify Admin.

Shopify revokes the app's access and sends app/uninstalled.

Saazly clears encrypted tokens and marks the installation as uninstalled.

Remove or disable Saazly Chat under App embeds if the theme still shows a saved embed.

07 / When something goes wrong

Troubleshooting

The app says the session is missing

Open the app again from Shopify Admin. Check that third-party scripts from cdn.shopify.com are not being blocked.

The widget does not appear

Check that an active widget is connected, the app embed is enabled and the theme has been saved.

The wrong studio appears

Close the connection window, select the correct studio in Saazly and open a new connection link from Shopify Admin.

Still stuck?

Send the store domain, time, and error message. Never send tokens or passwords.

Contact support
Shopify integration | Saazly documentation