Get Authorization URL
GET/api/shopify/:integrationInstance/authorization-url
Returns the Shopify OAuth authorization URL for an integration instance. The caller redirects the merchant's browser to this URL to begin authorization.
This endpoint currently requires session authentication; Personal Access Token scope support is in progress.
Authentication: Requires Bearer token.
Path params:
- integrationInstance (int, required): the integration instance id.
Notes:
- Requires connection_settings.url (or legacy shop_url) to be set on the instance; a 422 is returned when it is missing.
- The stored shop address is normalized before use. A full admin address such as https://admin.shopify.com/store/my-store resolves to my-store.myshopify.com.
- The store is proven to exist before a URL is handed back. Because *.myshopify.com resolves for any handle, a mistyped handle would otherwise produce a valid-looking URL that Shopify answers with an unrecoverable error page. A domain that cannot be a store (for example admin.shopify.com or a value with no dot) is rejected without contacting Shopify, and a domain with no store behind it returns a 422 naming the shop.
- The existence check fails open: if Shopify cannot be reached, the URL is still returned.
- Uses per-instance credentials in custom-app mode, otherwise SKU.io's central public-app Client ID.
- A tenant-aware state is generated so the central-domain callback can rehydrate tenancy.
Request
Responses
- 200
- 401
- 403
- 404
- 422
- 429
OK
Response Headers
Unauthenticated — the bearer token is missing, revoked, expired, or malformed. Never retry automatically; fix the credential. See the Errors guide.
Forbidden — the token lacks a required scope, the endpoint is not available to API tokens, or the user behind the token lacks the permission. A human must adjust the token scopes or user permissions; do not retry.
Not found — no record with the given identifier (or the route does not exist). Verify the ID before retrying.
Unprocessable Entity
Response Headers
Rate limited — platform limit is 1,000 requests/min; individual tokens may carry lower limits. Honor the Retry-After header before retrying. See the Rate Limits guide.