getting started

Connect Shopify

A Dev Dashboard app with Client ID and Client secret. We publish to your blog through the GraphQL Admin API.

Quibo publishes to your Shopify blog through the GraphQL Admin API (version 2026-07). You create a small app for your store in the Shopify Dev Dashboard, give it the two content scopes, install it on the store and paste its Client ID and Client secret into Quibo. From those two values Quibo requests short-lived Admin API tokens on its own and renews them automatically.

info

Shopify retired admin-created custom apps on 1 January 2026. Custom apps created in the Shopify admin before that date keep working (see "Custom app created before 2026" below), but new ones can only be created in the Dev Dashboard. The steps below are current as of September 2026.

What you'll need

  • A Shopify store with at least one blog. Every store starts with a "News" blog, so most stores already have one.
  • Access to the Shopify Dev Dashboard with the same account that owns the store. The store and the app must belong to the same organization, otherwise the app cannot be installed on the store.
  • About ten minutes.

Create the app in the Dev Dashboard

  1. Open dev.shopify.com/dashboard and sign in with the account that owns the store. If Shopify asks you to pick an organization, choose the one that contains the store.
  2. In the left navigation click Apps.
  3. Top right, click Create app.
  4. Choose Start from Dev Dashboard.
  5. Name the app Quibo and click Create.

Configure and release a version

Open the Versions tab of the new app. Shopify apps are versioned: the scopes live on a version, and only a released version can be installed.

  1. App URL can stay the default, https://shopify.dev/apps/default-app-home. Quibo never opens an admin page for this app, so it does not need a URL of its own.
  2. In the webhooks section pick the latest API version offered. Quibo does not subscribe to webhooks, but the field is required.
  3. Under the access scopes add read_content and write_content. These two are all Quibo needs: they cover blogs and blog posts and nothing else.
  4. Click Release. An app needs at least one released version before it can be installed on a store. If you change the scopes later, release a new version and reinstall the app on the store; Shopify does not push scope changes to an installed store by itself.

Copy the credentials

Open the Settings tab of the app.

  • Copy the Client ID.
  • Copy the Client secret. Keep both at hand for the Quibo form.

Install the app on your store

  1. Open the Home tab of the app and scroll down.
  2. Click Install app.
  3. Choose the store and click Install. Shopify lists the two content scopes; confirm.

Until this step is done the store does not know the app, and the token request from Quibo fails with invalid_client.

Find the Blog ID (optional)

Leave the Blog ID empty and Quibo publishes to the first blog of the store, which is right for almost every store. If you run several blogs and want a specific one:

  1. In the Shopify admin open Content, then Blog posts.
  2. Click Manage blogs and open the blog you want.
  3. The number at the end of the browser URL is the Blog ID, for example the 1234567890 in .../blogs/1234567890.

Both the plain number and the gid://shopify/Blog/1234567890 form are accepted.

Plug it into Quibo

From Sites, then Connect a site pick Shopify and fill in:

  • Site name (e.g. Acme Blog)
  • Site URL: the public URL of your storefront (a custom domain is fine here). Used to extract your brand voice.
  • Output language
  • Shop domain: always the *.myshopify.com form, e.g. acme.myshopify.com, never your custom domain. You find it in the Shopify admin under Settings, Domains.
  • Client ID
  • Client secret
  • Blog ID (optional): leave empty to use the first blog.

Click Connect site. Quibo requests a token from the store before saving anything, so a wrong secret or a missing install shows up in the wizard right away: if the check fails, nothing is stored and the error is shown there. Test connection on the site page stays available to re-check them later.

How the token works

With a Dev Dashboard app Quibo stores only the Client ID and the Client secret, never an access token. Whenever it needs one it calls the store's token endpoint with the client credentials grant (POST /admin/oauth/access_token with grant_type=client_credentials, the Client ID and the Client secret). Shopify answers with a token that is valid for 24 hours. Quibo keeps it in memory until shortly before it expires and then requests a new one. If Shopify ever rejects a token early, Quibo requests a fresh one and retries the call once. There is nothing to renew by hand. If you paste a legacy shpat_ token instead (see below), that token is stored encrypted and used directly.

The Client secret is encrypted at rest, is never returned to the browser after you save it, is never logged and is never sent to a third party.

Rotate the secret

  1. In the Dev Dashboard open the app, then Settings, and rotate the client secret. The old secret stops minting tokens once the rotation completes, so do the next step right away.
  2. Paste the new Client secret into Quibo: open the site page, Update credentials, enter the Client ID and the new secret, and save. The values are verified against the store before they replace the old ones. The Client ID does not change.
  3. Click Test connection on the site page to confirm that Quibo can mint a token again.

Custom app created before 2026

If your store still has a custom app that was created from the Shopify admin (Settings, Apps and sales channels, Develop apps) before 1 January 2026, it keeps working and you can use it instead of a Dev Dashboard app:

  1. Open the app in the Shopify admin and check under Configuration that the Admin API scopes include read_content and write_content.
  2. Open the API credentials tab and copy the Admin API access token. It starts with shpat_. Shopify shows it only once; if you have lost it, uninstall and reinstall the app to get a new one.
  3. In the Quibo form leave Client ID and Client secret empty and paste the token into Legacy Admin API token.

Legacy tokens do not expire, so there is nothing to renew. To revoke access, uninstall the app in the Shopify admin.

What we publish

For each article Quibo runs the articleCreate mutation on your blog with:

  • title: the article title.
  • handle: the article slug, which becomes the last part of the URL.
  • body: the article HTML rendered from the editor, with the JSON-LD structured data appended at the end as a <script type="application/ld+json"> block. Shopify keeps script tags in article bodies, so search engines see the structured data on the storefront page.
  • summary: the meta description as plain text. Most themes show it as the excerpt on the blog index.
  • author: the Default author picked in the brand profile, else the free-text byline of the site, else the shop owner. The Default author dropdown is filled with the shop owner and every byline already used on the blog's existing articles.
  • image: the cover image URL and its alt text. Shopify downloads the image from that URL and stores it on its own CDN.
  • isPublished: true, so the article is live on the storefront right away.

When Quibo refreshes an article later it runs articleUpdate on the same article: title, body, summary, author and cover are replaced, the handle is kept so the URL does not change, and the original publish date stays.

What we do not publish

  • Tags: Quibo has no tag model yet. New articles are created without tags, and a refresh leaves any tags your editors added in Shopify untouched.
  • Metafields: article metafield definitions are discovered and listed in the site's schema for reference, but no values are written.
  • AI-generated image marking: on WordPress and other CMSs where Quibo uploads the cover itself, it embeds an XMP marker in the image before uploading. Shopify only accepts the cover as a URL and fetches it on its side, so the bytes never pass through Quibo and cannot be marked on this path.

Test the connection

On Sites, then your site click Test connection. Quibo mints a token and runs a tiny GraphQL query (shop { name } plus the first blog). A 401 or 403 means the credentials or the scopes are wrong; a 404 means the shop domain is wrong. See Shopify troubleshooting for the fixes.

Security

  • The Client secret, or the legacy token, is encrypted at rest.
  • It is never returned to the browser, never logged, never sent to a third party.
  • The app only has the two content scopes. It cannot read orders, customers, products or payouts.
  • Revoke access any time by uninstalling the app from the store (Shopify admin, Settings, Apps and sales channels) or by deleting the app in the Dev Dashboard.