Back to Intelligence
Platform UpdatesGlobal

Shopify adds a seven-day recovery window for certain offline-token migrations

Apps migrating existing non-expiring offline tokens without a user session can retry a lost migration exchange, reducing the need for merchants to reopen the app when the retry remains eligible.

Ecomwith EditorialEcommerce intelligence desk

Published
Updated
Risk
low

Reported details

What happened

The Shopify Developer Changelog says an app migrating an existing non-expiring offline token to an expiring offline access token without a user session can retry the exchange with the original token and valid client credentials for up to seven days.

An eligible retry returns the same access-token and refresh-token pair as the initial exchange, and Shopify may extend the access token expiry when needed.

The refresh-token expiry is not extended, and the original non-expiring token remains invalid for GraphQL Admin API requests after migration.

Recovery ends after seven days, after the app successfully refreshes the issued pair, or after a later token acquisition for the same store replaces that pair.

Business relevance

Why it matters

A lost or unpersisted migration response no longer necessarily forces a merchant to reopen the app and complete authorization again, provided the original token, client credentials, and recovery window remain available.

The update targets a narrow migration scenario rather than every token exchange, so apps that do not migrate existing non-expiring offline tokens without a user session do not need to change their existing flows based on this announcement.

Because the refresh token does not receive an extended expiry, recovery improves response handling but does not remove the need to store and manage the returned token pair correctly.

Editorial perspective

Analysis & judgment

  1. The mechanism shifts some migration failures from an immediate authorization problem into a bounded idempotent-retry problem: repeating the same eligible exchange can recover the same pair instead of creating a new authorization path. That changes the engineering priority toward preserving the original token and client credentials, but the single supplied changelog claim does not establish how every failure mode is classified.

  2. For merchants using an affected app, the practical consequence is potentially less interruption when an app loses its migration response, because support may be able to recover access without asking the merchant to reopen the app. This benefit applies only to the stated migration flow and should not be treated as evidence that unrelated authentication failures can be resolved the same way.

  3. The decision rule is to retry only when the original-token exchange is still within seven days and no successful refresh or later token acquisition has ended recovery; otherwise, treat the case as outside this safeguard. The supplied evidence does not define additional retry limits or operational error signals, so teams should avoid inferring them.

Applicability

Seller impact

Affected merchants may see fewer requests to reopen an app solely because a migration response was lost, if the app can perform the eligible retry.

A migration incident can still become persistent if the app fails to save the returned access and refresh tokens, waits beyond the seven-day window, or attempts recovery after the issued pair has been replaced.

The regional scope supplied for this update is global, but the technical impact remains limited to apps using the specified token-migration flow.

Action plan

What to do now

  1. 1

    Use the eligible retry path for active incidents

    now

    If an affected app did not receive or persist its migration response, retry the same migration request with the original non-expiring token and valid client credentials within seven days of the initial exchange, then persist the returned access-token and refresh-token pair.

  2. 2

    Review migration response persistence

    this-week

    If your app performs this migration, review whether it records the original token, client credentials, and returned token pair well enough to support a bounded retry. This recommendation is conditional because the changelog does not describe your current storage or failure-handling design.

  3. 3

    Track when recovery eligibility ends

    monitor

    Monitor migration cases for the three stated boundaries: seven days after the initial exchange, a successful refresh of the issued pair, or a later token acquisition that replaces it. Do not assume the recovery path remains available after any of those events.

What not to do yet

  • Do not require a merchant to reopen the app solely because a migration response was lost when the app can still perform the eligible retry; do not apply that assumption to other authentication failures or to migrations outside the stated scenario.

Sources & context

Evidence and sources

A source may provide only a headline or summary. Read the evidence scope below. Links and workflow checks are not independent fact verification. Internal confidence values are workflow signals, not probabilities of factual correctness.

  1. 01

    More resilient token exchanges when migrating to expiring offline access tokens When you migrate an app from non-expiring offline tokens to expiring offline access tokens without a user session, you can now recover a lost migration response by retrying the exchange with the original non-expiring token for up to seven days. This reduces how often you need a merchant to reopen the app to restore access, but you don’t need to change existing flows to keep them working. What changed When you migrate an existing non-expiring offline token to an expiring offline access token without a user session, an eligible retry using the same original token and client credentials returns the same access-token and refresh-token pair as the initial exchange. On an eligible retry: Shopify returns the same access token and refresh token. Shopify extends the access token’s expiry when needed. Shopify doesn’t extend the refresh token’s expiry. Recovery for a particular store and app ends when any of the following is true: Seven days have passed since the initial exchange for that original token. Your app successfully refreshes the issued pair. A later token acquisition for the same store replaces that pai

    Shopify Developer Changelog · Workflow status: single-source

    Source link

    Retrieved: September 29, 2026 at 04:07 p.m. UTC

    Claim is bounded to the ingested title or summary; no source body or quotation is retained.