Skip to content
AptoAir
Shopify integration

Connect Shopify with one custom-app token

Create a custom app in your Shopify admin, tick a few scopes, copy the access token. We register the order, checkout, customer and product webhooks and import your catalogue — including native abandoned-checkout recovery.
Native checkout webhooksWebhooks registered for youGrowth & Pro plans
Order placed
Order #1042 confirmed — ₹2,499
auto
COD confirmed
Customer tapped “Confirm” on WhatsApp
auto
Shipped
Delhivery · AWB 6721904455 · track link
auto
Delivered → review
“How was it?” with quick-reply buttons
auto

Why Shopify gets the best version of this

Shopify fires a webhook when a checkout is created and updated, not just when an order completes. That means genuine abandoned-cart recovery — reaching someone who entered their details and then hesitated, while they are still deciding. On Pro, that alone often pays for the subscription.

Setup

Create a custom app in Shopify

Shopify calls these “custom apps”. You are creating one for your own store, granting it read access to the data we need, and copying the token it gives you. No app store listing, no review, no waiting.

  • Shopify admin → Settings → Apps and sales channels → “Develop apps”
  • Create an app named “Xilot”, then Configuration → Admin API integration → Configure
  • Tick the scopes below and save
  • Click “Install app” and confirm
  • Open API credentials, reveal and copy the Admin API access token (it starts with shpat_)
Scopes to tick

Required: read_orders, read_products, read_customers, read_fulfillments

For abandoned-cart recovery: read_checkouts

Only if you want COD auto-cancel: write_orders

Only if the AI should create discount codes: write_discounts

Recommended

Copy the API secret key as well

On the same credentials page there is an API secret key. It is optional, but with it we can cryptographically verify that every webhook genuinely came from Shopify rather than trusting the shop domain alone. It takes one extra click and we recommend it.

  • Verifies every incoming webhook with an HMAC signature
  • Without it we fall back to matching the shop domain
  • Can be added later by reconnecting
The result

What your customers start receiving

Order and checkout events become WhatsApp messages, sent as approved templates when the customer is outside the 24-hour window.

  • Order confirmed, paid, shipped, delivered and cancelled updates — with the courier and tracking link
  • Cash-on-delivery confirmation with Confirm / Cancel buttons before you ship
  • Every buyer synced into your phonebook with spend, order count and automatic tags
  • Your AI able to answer “where is my order?” with real, live data (Pro)
  • Abandoned checkout followed up with the recovery link, and optionally a discount code (Pro)
Order placed
Order #1042 confirmed — ₹2,499
auto
COD confirmed
Customer tapped “Confirm” on WhatsApp
auto
Shipped
Delhivery · AWB 6721904455 · track link
auto
Delivered → review
“How was it?” with quick-reply buttons
auto
Step by step

The whole setup, in order

  1. 1

    Subscribe to Growth or Pro

    Growth connects your store. Pro adds cart recovery, AI store lookups and multiple stores.

  2. 2

    Create the custom app

    Settings → Apps and sales channels → Develop apps → create, configure scopes, install.

  3. 3

    Copy the access token

    API credentials tab. It starts with shpat_. Copy the API secret key too if you can.

  4. 4

    Paste into Settings → Integrations

    Your .myshopify.com domain plus the token. We verify, register webhooks and import.

  5. 5

    Map templates and test

    Point each event at an approved template, then fire a test order to see the real result.

Store integrations are part of the Growth plan. Abandoned-checkout recovery, AI store lookups and multiple stores are part of Pro.

See plans
Questions

Frequently asked

For WooCommerce and Shopify, no — it is copy and paste from your store's admin, and we register the webhooks for you. For a custom store, someone needs to POST us a webhook, which is a small job for whoever maintains your site.
We import your recent orders and products during setup, so the AI can answer questions about them straight away. Only new events after connection trigger messages — connecting will not blast your entire order history.
They are encrypted before they are stored, and they are only ever used to talk to your store. You can disconnect at any time, which also removes the webhooks we created.
Multiple stores are part of the Pro plan. Growth connects one.
The permanent .myshopify.com domain, not your custom one. Shopify signs its webhooks against that, so a custom domain will not match.
Not today — you create a custom app for your own store, which is faster and gives you full control of the scopes. A one-click App Store listing is on the roadmap.

Start answering customers properly

Connect your WhatsApp number and send your first automated reply today. 15 days free, no card needed.

No credit cardCancel anytimeYour data stays yours