Get Auth Settings
GET/api/shopify/:integrationInstance/auth-settings
Returns the connection settings for an integration instance with secrets masked (only the last 4 characters are visible), plus the authorization state, current sync status and shop URL. Useful for showing connection state without exposing credentials.
This endpoint currently requires session authentication; Personal Access Token scope support is in progress.
Authentication: Requires Bearer token.
Response fields:
- connection_settings (object): stored settings; consumer_secret, client_secret and password are masked.
- is_authorized (boolean): true once Shopify has granted an access token for this instance (always true in legacy custom-app mode, which authenticates with stored credentials instead of OAuth). An instance that was created but never completed the handshake reports false.
- sync_status (string): Active or Inactive. This is independent of is_authorized — it says whether syncing is switched on, not whether the store is connected.
- shop_url (string|null): the stored store address.
- name (string): display name.
- is_automatic_sync_enabled (boolean).
Request
Responses
- 200
- 401
- 403
- 404
- 429
OK
Response Headers
Unauthenticated — the bearer token is missing, revoked, expired, or malformed. Never retry automatically; fix the credential. See the Errors guide.
Forbidden — the token lacks a required scope, the endpoint is not available to API tokens, or the user behind the token lacks the permission. A human must adjust the token scopes or user permissions; do not retry.
Not found — no record with the given identifier (or the route does not exist). Verify the ID before retrying.
Rate limited — platform limit is 1,000 requests/min; individual tokens may carry lower limits. Honor the Retry-After header before retrying. See the Rate Limits guide.