Shopify App Review: Let the Reviewer Get In, Understand It, and Finish the Test
Shopify App Review is not a check of listing copy. A reviewer starts at installation, completes authentication, enters the app, runs the core workflow, and verifies scopes, billing, and uninstall behavior. Any step that relies on a developer explaining it live, on a temporary account, or on a hidden redirect makes the outcome unpredictable.
This article was checked against Shopify's documentation on 2026-09-20. App Store requirements change, so re-read the current requirements and the checks the Dev Dashboard shows for your specific app before submitting.
Design the review path first
Write the reviewer's path as a flow someone can follow on their own:
install the app
→ Shopify authentication
→ land on the app home
→ if an external account is needed, reach the reviewer sign-in page
→ use the pre-provisioned account
→ complete the core workflow
→ see results and costs
→ uninstall or sign out
Every step needs a stated expected result and a recovery entry point if it fails. Shopify's pass app review guide requires testing your app URL, redirects, and the OAuth installation flow before submitting; an app that uses Shopify-managed installation should verify that flow rather than bolting on a second, legacy OAuth path.
Do not redirect the reviewer across domains immediately
If review accounts live in an external identity system, a dedicated /reviewer page is easier to follow than an instant redirect. The page needs only:
- A
Shopify App Review accessheading. - A note that this entry point exists for Shopify review.
- A
Continue to reviewer sign-inprimary button. - A secondary link back to normal sign-in.
- A short note on what the account is for and what it can access.
The external sign-in happens after the click. This is a usability recommendation, not a page structure Shopify mandates. Its value is that the reviewer can see what is about to happen, and has a stable page to return to when third-party cookies, popups, or an authentication error get in the way.
The reviewer page should not be indexed by search engines, should not display a real password, and should not bypass normal authentication. It explains and it lets the reviewer in — nothing else.
Test accounts and data
A review account should:
- Have been signed into and checked before submission.
- Require no SMS, no manual approval, and no verification code sent by a developer.
- Hold only the permissions needed to demonstrate the core feature.
- Use stable test data that will not expire during review.
- Return to a usable state after repeated testing.
If the app authorizes per organization or per member, say which organization the account enters, which test store to choose, and which actions write data. Do not leave the reviewer guessing at entry points or setting up complex prerequisite data.
Authentication and embedded apps
An embedded app has to use App Bridge and the current authentication method correctly. Shopify's ID token documentation explains that App Bridge issues an ID token to the frontend, that it expires one minute after issue, and that the backend validates its claims and then exchanges it for an access token. The ID token authenticates the user and cannot be used to call a Shopify API. See ID tokens.
Verify at least this much before review:
- Installation goes straight into the correct authentication flow.
- Authentication ends in the app UI, not a blank page or a redirect loop.
- Refreshing, opening a deep link directly, and an expired token all recover.
- The main task can still be completed on a narrow or mobile screen.
- When an ad blocker or browser restriction breaks authentication, there is a clear error and a way to retry.
Listing and demo material
The listing's feature description, screenshots, video, and testing instructions all have to point at the same real capability. Shopify's App Store best practices recommend clear desktop screenshots, contextual explanation, and material that demonstrates the app's value. See App Store best practices.
When preparing material:
- Screenshots show the real app UI, cropped free of browser chrome and sensitive information.
- The video starts at installation or sign-in and runs the whole main workflow.
- Testing instructions and test credentials go into the submission form, with exact entry points, accounts, steps, and expected results.
- The pricing description matches what each plan actually unlocks in the app.
- Screenshots contain no personal information, no real merchant data, and no claims about results you cannot back up.
Webhooks, privacy, and uninstall
An app distributed through the App Store must respond to data subject requests whether or not it collects personal data, which means three mandatory webhooks: customers/data_request, customers/redact, and shop/redact. A compliance request whose HMAC fails verification must get a 401 Unauthorized, and shop/redact arrives 48 hours after a store owner uninstalls the app. See Privacy law compliance.
Verify before review:
- All three mandatory webhooks are configured and accept JSON requests.
- Valid requests return success and invalid signatures return 401.
- After
app/uninstalled, tokens and access are invalidated. - A late
shop/redactis neither dropped by a bug nor allowed to delete data that belongs to another valid installation. - A reinstall does not pick up a session left over from the previous installation.
Pre-submission checklist
- The automated checks on the Shopify App Store review page have run, and you understand every item still failing.
- The app uses a currently supported API version and a released configuration.
- App URL, redirect URLs, webhook URLs, and TLS all point at the production environment.
- The review account, test store, and demo data survive repeated use.
- The core workflow needs no live help from a developer.
- Listing, pricing, privacy policy, support details, screenshots, and video are complete.
- Authentication, scopes, billing, failure states, uninstall, and reinstall have each been exercised for real.
- The submission contact address can receive mail from Shopify.
Shopify cautions that submitting an app with errors, a beta version, an app that does not meet the requirements, or an incomplete submission can delay review or cause the app not to be approved. See Submit an app for review.
The best preparation is not a longer explanation. It is that a stranger can complete one real run using nothing but the instructions.