Shopify Admin API Integration: Limits and Webhooks
The technical rules behind any Shopify integration or custom app: GraphQL cost limits by plan, quarterly API versions, signed webhooks, bulk operations and customer-data access.
- Organisation
- WavX Solutions
- Telephone
- +919310079927
Description
Integration Working with the Shopify Admin API: rate limits, versions and webhooks
Every custom Shopify app and integration reads and writes store data through the GraphQL Admin API. As of October 2026 the REST Admin API is legacy, GraphQL calls are metered in cost points (100 per second on standard plans, 1,000 on Plus), a new API version ships each quarter with at least 12 months of support, and webhooks must be verified and answered within five seconds.
Discuss an integration Last updated 2 October 2026
What the Admin API connects
The Admin API is how software outside Shopify reads and changes a store: orders, products, inventory, customers, fulfilments, refunds, metafields. Every integration on this site that touches Shopify, from Shopify to Tally to Shopify and Shiprocket , sits on it, and so does every custom Shopify app .
It works in two directions:
Your server calls Shopify to read or write data, using GraphQL.
Shopify calls your server by webhook when something happens: an order is created, paid, cancelled or refunded, a product changes, stock moves.
Data flow
┌──── webhook: orders/paid (signed X-Shopify-Hmac-SHA256) ────┐
│ ▼
Shopify store Your server: verify HMAC on raw body,
check X-Shopify-Webhook-Id not seen,
reply 200 within 5 s, queue the job
▲ │
└──── POST /admin/api/2026-10/graphql.json ◀── worker: fetch full order,
(read order, write tags/metafields, write to ERP / Tally / CRM,
create fulfilment) update Shopify
Nightly: GraphQL bulk query (JSONL) of orders updated since the last run
──▶ compare with the other system ──▶ fix or report differences
The webhook says something happened; the GraphQL call fetches the current truth. The nightly bulk query catches whatever the webhooks missed.
A small working example
Fetching orders updated since a date, fifty at a time, with the fields an accounting sync needs:
query OrdersSince($cursor: String) {
orders(first: 50, after: $cursor, query: "updated_at:>=2026-10-01") {
edges {
node {
id
name
createdAt
displayFinancialStatus
totalPriceSet { shopMoney { amount currencyCode } }
pageInfo { hasNextPage endCursor }
The request goes to https://{store}.myshopify.com/admin/api/2026-10/graphql.json with the access token in the X-Shopify-Access-Token header. The response's extensions.cost block reports the requested and actual cost and the throttleStatus (maximum available, currently available, restore rate), which is what the integration uses to pace itself.
Field mapping: a Shopify order for a downstream system
Shopify field
Meaning
Use downstream
Global ID, such as gid://shopify/Order/…
The permanent key for de-duplication
The order number staff see, such as #1042
Voucher or invoice reference
createdAt , processedAt
When placed and processed
Voucher date: agree which one with the accountant
Paid, pending, refunded, partially refunded
Decides whether to post a sale, wait, or post a credit note
totalPriceSet.shopMoney
Total in the store's currency
Control total for reconciliation
Line items: SKU, quantity, price, discounts, tax lines
What was sold and how it was taxed
Stock items, ledgers and tax mapping
Shipping lines
Shipping charged
Shipping income ledger
Shipping address province
Delivery state
Intra-state or inter-state tax
Refunds
Amounts and lines refunded
Credit notes
Limits Shopify documents
Rule
As read on 2 October 2026
GraphQL rate limit (restore rate)
Standard plans 100 points/second; Advanced 200; Plus 1,000; Enterprise 2,000
Query cost
Objects 1 point, scalars and enums 0, mutations 10; connections sized by first / last
Single query cap
1,000 points, on any plan
Array inputs
At most 250 items, on every Shopify API
Over the limit
Throttled; 429 Too Many Requests
Versions
New version each quarter, 5pm UTC on the first day; each supported for at least 12 months; latest stable is 2026-10
Retired version requested
Shopify answers with the oldest supported version; the X-Shopify-Api-Version header shows which
REST Admin API
Legacy since 1 October 2024; new public apps GraphQL-only since 1 April 2025
Webhook timeouts
1-second connection timeout, 5 seconds for the whole request; anything but 2xx is a failure
Webhook retries
Up to eight times in four hours
Duplicate webhooks
Detect with X-Shopify-Webhook-Id
Bulk queries
Results as JSONL; up to five concurrent bulk queries per shop from version 2026-01; result URLs expire after one week; the bulk run itself is not rate-limited
Client credentials tokens
Expire after 24 hours; app and store must be in the same Shopify organisation
Common failure modes
Slow webhook handlers. Doing the ERP write before replying takes longer than five seconds, Shopify records a failure and retries, and the order is posted twice. Reply first, then work.
No HMAC check. Without it, anyone who finds the URL can post fake orders into your accounts.
Treating the webhook as complete data. Fetch the order again before acting; a later edit or refund may already exist.
Paging with large first values. A query asking for 250 orders with nested line items can exceed the 1,000-point cap. Smaller pages, or a bulk query, fix it.
Pinned to an old version. Nothing is wrong until the version retires, then fields change shape. Put the version upgrade in the maintenance calendar each quarter.
Expired client-credentials token. Works for a day, then every call fails. Renewal must be automatic.
These are also the usual reasons behind orders not syncing to Tally or your ERP .
What WavX builds
WavX builds custom Shopify apps and integrations on the GraphQL Admin API: verified webhook receivers with a queue, cost-aware paging that reads throttleStatus , bulk-query reconciliation, token renewal, and a quarterly version check as part of maintenance. The app is created in the merchant's own Shopify organisation and the code is handed over. Whether a custom app is the right choice at all is covered in Shopify custom app vs App Store app.
Effort band
Integration work is quoted after scoping. For planning, the software cost estimator carries third-party integrations as a ₹60,000 line item inside a larger build; the worked range for a standalone integration is on API and system integration services .
When the API is the wrong tool
If an App Store app already does the job and its rules fit, install it. If the need is an automation inside Shopify itself, such as tagging orders or sending an internal alert, Shopify Flow, a free Shopify app on the Basic, Grow, Advanced and Plus plans, may do it without any external server. Build on the Admin API when data must move between Shopify and a system no app connects, or when the rules are your own.
Frequently asked questions
Should a new integration use the REST or GraphQL Admin API?
GraphQL. Shopify's documentation says the REST Admin API has been legacy since 1 October 2024 and that new public apps must use GraphQL only from 1 April 2025. A private integration for one store can still call REST, but new work there would be building on an API Shopify is moving away from.
How do we get an API token for our own store?
Custom apps are now created and managed in Shopify's Dev Dashboard; legacy custom apps made in the admin before 1 January 2026 can still be managed there. A server-side app in the same Shopify organisation as the store can use the client credentials grant, whose tokens expire after 24 hours, so the integration renews them automatically.
Why does our integration need updating every year?
Because Shopify releases a new API version every quarter and supports each one for a minimum of 12 months. When a version is retired, Shopify answers with the oldest version still supported, and fields may have changed shape. Someone has to move the integration forward before that happens.
Can a custom app read customer names, phones and addresses?
Yes, with limits. Shopify treats name, address, email and phone as protected customer data. Custom apps can access it, but Shopify's help centre says the store must be on the Grow plan or higher for custom apps that use this level of personal data.
Sources
Shopify developer docs: GraphQL Admin API rate limits · read 2 October 2026
Shopify developer docs: API versioning · read 2 October 2026
Shopify developer docs: REST Admin API (legacy notice) · read 2 October 2026
Shopify developer docs: Deliver webhooks through HTTPS · read 2 October 2026
Shopify developer docs: Troubleshooting webhooks · read 2 October 2026
Shopify developer docs: Bulk operation queries · read 2 October 2026
Shopify developer docs: Protected customer data · read 2 October 2026
Shopify developer docs: Client credentials grant · read 2 October 2026
Shopify Help Center: Custom apps · read 2 October 2026
Shopify Help Center: Shopify Flow · read 2 October 2026
Related
Custom Shopify app development
Shopify to Tally integration
Shopify integrations
What is a webhook?
Build your own software — your way, your pricing.
WavX Solutions is here to create your own software in a fully custom way, built exactly how you work — with a pricing model that fits your business. Connect now and let's build it.
Contact Now helpwavx@gmail.com