Shopify Admin API Integration: Limits and Webhooks

View this page

The technical rules behind any Shopify integration or custom app: GraphQL cost limits by plan, quarterly API versions, signed webhooks, bulk operations and customer-data access.

Organisation
WavX Solutions
Telephone
+919310079927

Description

Integration Working with the Shopify Admin API: rate limits, versions and webhooks

Every custom Shopify app and integration reads and writes store data through the GraphQL Admin API. As of October 2026 the REST Admin API is legacy, GraphQL calls are metered in cost points (100 per second on standard plans, 1,000 on Plus), a new API version ships each quarter with at least 12 months of support, and webhooks must be verified and answered within five seconds.

Discuss an integration Last updated 2 October 2026

What the Admin API connects

The Admin API is how software outside Shopify reads and changes a store: orders, products, inventory, customers, fulfilments, refunds, metafields. Every integration on this site that touches Shopify, from Shopify to Tally to Shopify and Shiprocket , sits on it, and so does every custom Shopify app .

It works in two directions:

Your server calls Shopify to read or write data, using GraphQL.

Shopify calls your server by webhook when something happens: an order is created, paid, cancelled or refunded, a product changes, stock moves.

Data flow

┌──── webhook: orders/paid (signed X-Shopify-Hmac-SHA256) ────┐

│ ▼

Shopify store Your server: verify HMAC on raw body,

check X-Shopify-Webhook-Id not seen,

reply 200 within 5 s, queue the job

▲ │

└──── POST /admin/api/2026-10/graphql.json ◀── worker: fetch full order,

(read order, write tags/metafields, write to ERP / Tally / CRM,

create fulfilment) update Shopify

Nightly: GraphQL bulk query (JSONL) of orders updated since the last run

──▶ compare with the other system ──▶ fix or report differences

The webhook says something happened; the GraphQL call fetches the current truth. The nightly bulk query catches whatever the webhooks missed.

A small working example

Fetching orders updated since a date, fifty at a time, with the fields an accounting sync needs:

query OrdersSince($cursor: String) {

orders(first: 50, after: $cursor, query: "updated_at:>=2026-10-01") {

edges {

node {

id

name

createdAt

displayFinancialStatus

totalPriceSet { shopMoney { amount currencyCode } }

pageInfo { hasNextPage endCursor }

The request goes to https://{store}.myshopify.com/admin/api/2026-10/graphql.json with the access token in the X-Shopify-Access-Token header. The response's extensions.cost block reports the requested and actual cost and the throttleStatus (maximum available, currently available, restore rate), which is what the integration uses to pace itself.

Field mapping: a Shopify order for a downstream system

Shopify field

Meaning

Use downstream

Global ID, such as gid://shopify/Order/…

The permanent key for de-duplication

The order number staff see, such as #1042

Voucher or invoice reference

createdAt , processedAt

When placed and processed

Voucher date: agree which one with the accountant

Paid, pending, refunded, partially refunded

Decides whether to post a sale, wait, or post a credit note

totalPriceSet.shopMoney

Total in the store's currency

Control total for reconciliation

Line items: SKU, quantity, price, discounts, tax lines

What was sold and how it was taxed

Stock items, ledgers and tax mapping

Shipping lines

Shipping charged

Shipping income ledger

Shipping address province

Delivery state

Intra-state or inter-state tax

Refunds

Amounts and lines refunded

Credit notes

Limits Shopify documents

Rule

As read on 2 October 2026

GraphQL rate limit (restore rate)

Standard plans 100 points/second; Advanced 200; Plus 1,000; Enterprise 2,000

Query cost

Objects 1 point, scalars and enums 0, mutations 10; connections sized by first / last

Single query cap

1,000 points, on any plan

Array inputs

At most 250 items, on every Shopify API

Over the limit

Throttled; 429 Too Many Requests

Versions

New version each quarter, 5pm UTC on the first day; each supported for at least 12 months; latest stable is 2026-10

Retired version requested

Shopify answers with the oldest supported version; the X-Shopify-Api-Version header shows which

REST Admin API

Legacy since 1 October 2024; new public apps GraphQL-only since 1 April 2025

Webhook timeouts

1-second connection timeout, 5 seconds for the whole request; anything but 2xx is a failure

Webhook retries

Up to eight times in four hours

Duplicate webhooks

Detect with X-Shopify-Webhook-Id

Bulk queries

Results as JSONL; up to five concurrent bulk queries per shop from version 2026-01; result URLs expire after one week; the bulk run itself is not rate-limited

Client credentials tokens

Expire after 24 hours; app and store must be in the same Shopify organisation

Common failure modes

Slow webhook handlers. Doing the ERP write before replying takes longer than five seconds, Shopify records a failure and retries, and the order is posted twice. Reply first, then work.

No HMAC check. Without it, anyone who finds the URL can post fake orders into your accounts.

Treating the webhook as complete data. Fetch the order again before acting; a later edit or refund may already exist.

Paging with large first values. A query asking for 250 orders with nested line items can exceed the 1,000-point cap. Smaller pages, or a bulk query, fix it.

Pinned to an old version. Nothing is wrong until the version retires, then fields change shape. Put the version upgrade in the maintenance calendar each quarter.

Expired client-credentials token. Works for a day, then every call fails. Renewal must be automatic.

These are also the usual reasons behind orders not syncing to Tally or your ERP .

What WavX builds

WavX builds custom Shopify apps and integrations on the GraphQL Admin API: verified webhook receivers with a queue, cost-aware paging that reads throttleStatus , bulk-query reconciliation, token renewal, and a quarterly version check as part of maintenance. The app is created in the merchant's own Shopify organisation and the code is handed over. Whether a custom app is the right choice at all is covered in Shopify custom app vs App Store app.

Effort band

Integration work is quoted after scoping. For planning, the software cost estimator carries third-party integrations as a ₹60,000 line item inside a larger build; the worked range for a standalone integration is on API and system integration services .

When the API is the wrong tool

If an App Store app already does the job and its rules fit, install it. If the need is an automation inside Shopify itself, such as tagging orders or sending an internal alert, Shopify Flow, a free Shopify app on the Basic, Grow, Advanced and Plus plans, may do it without any external server. Build on the Admin API when data must move between Shopify and a system no app connects, or when the rules are your own.

Frequently asked questions

Should a new integration use the REST or GraphQL Admin API?

GraphQL. Shopify's documentation says the REST Admin API has been legacy since 1 October 2024 and that new public apps must use GraphQL only from 1 April 2025. A private integration for one store can still call REST, but new work there would be building on an API Shopify is moving away from.

How do we get an API token for our own store?

Custom apps are now created and managed in Shopify's Dev Dashboard; legacy custom apps made in the admin before 1 January 2026 can still be managed there. A server-side app in the same Shopify organisation as the store can use the client credentials grant, whose tokens expire after 24 hours, so the integration renews them automatically.

Why does our integration need updating every year?

Because Shopify releases a new API version every quarter and supports each one for a minimum of 12 months. When a version is retired, Shopify answers with the oldest version still supported, and fields may have changed shape. Someone has to move the integration forward before that happens.

Can a custom app read customer names, phones and addresses?

Yes, with limits. Shopify treats name, address, email and phone as protected customer data. Custom apps can access it, but Shopify's help centre says the store must be on the Grow plan or higher for custom apps that use this level of personal data.

Sources

Shopify developer docs: GraphQL Admin API rate limits · read 2 October 2026

Shopify developer docs: API versioning · read 2 October 2026

Shopify developer docs: REST Admin API (legacy notice) · read 2 October 2026

Shopify developer docs: Deliver webhooks through HTTPS · read 2 October 2026

Shopify developer docs: Troubleshooting webhooks · read 2 October 2026

Shopify developer docs: Bulk operation queries · read 2 October 2026

Shopify developer docs: Protected customer data · read 2 October 2026

Shopify developer docs: Client credentials grant · read 2 October 2026

Shopify Help Center: Custom apps · read 2 October 2026

Shopify Help Center: Shopify Flow · read 2 October 2026

Related

Custom Shopify app development

Shopify to Tally integration

Shopify integrations

What is a webhook?

Build your own software — your way, your pricing.

WavX Solutions is here to create your own software in a fully custom way, built exactly how you work — with a pricing model that fits your business. Connect now and let's build it.

Contact Now helpwavx@gmail.com

Reference material from WavX Solutions

Related questions WavX has answered

We use HubSpot for B2B sales and Shopify for our online store, and the two don't share customer data. Marketing wants abandoned carts and order history inside HubSpot. Is the ready-made connector enough, or should we build a custom integration?

Start with the ready-made connector; it covers what marketing asked for. Standard connectors sync customers, orders, products and abandoned carts into HubSpot and are quick to switch on. Build a custom integration only when you hit their limits: mapping Shopify B2B companies to HubSpot companies, syncing metafields, custom deal stages per order, two-way updates, or strict rules for merging duplicate contacts. Run the connector for a month, list what is missing, and scope custom work from that list. HubSpot is among the integrations WavX names. Source

Our furniture store in Johannesburg runs on a custom PHP site built in 2019, about 1,200 products and 18,000 customers. The developer who hosts it is hard to reach; we have admin access and a database backup. We take PayFast and price in rand. What can actually be migrated to Shopify from that?

A database backup is enough to move almost everything: products, variants, customers, addresses and order history can be extracted by script and loaded into Shopify. Images come from the live site if you have no server access. Passwords do not transfer, and URLs must be crawled now, while the site is up, to build redirects. Before anything else, confirm the domain is registered in your name. Rand pricing and a South African gateway are set up fresh. WavX's hours are 6:30 AM–3:30 PM SAST, covering your working day. Source

Shopify app store app vs custom app when to build your own?

Use an App Store app when the need is common, such as reviews, email or basic upsells, and build your own when the logic is specific to your business. Signs that a custom app is due: you pay for several apps that overlap, an app slows the storefront, you bend your process to fit the app's settings, data must flow into your own systems, or no app does the job. A custom app runs only on your store and its code can belong to you. Source

What are the hard limits of Shopify that custom development cannot work around?

A few limits are fixed whatever a developer does. The checkout engine is Shopify's and cannot be replaced or self-hosted, only extended within what each plan allows. URL patterns such as /products/ and /collections/ cannot be changed. There is no direct database access, so everything goes through throttled APIs. Theme code cannot run server-side logic of its own, and there is a cap on variants per product. Most other gaps can be closed with a custom app, Shopify Functions or a headless front end. Source

Where is a custom Shopify app built by WavX Solutions hosted, and who controls it?

A custom Shopify app's server code is not hosted by Shopify; it runs on a cloud account, and WavX deploys on AWS, Google Cloud or Azure with CI/CD, monitoring and backups. The client owns 100% of the source code and IP, so the repository and cloud account can sit under the client's own name, with the app installed only on the client's store. That arrangement means another developer can take over the app later without WavX's involvement. Source

Do I need the WhatsApp Business API for my Shopify store or is the normal WhatsApp Business app enough?

The WhatsApp Business app is enough while one person answers chats by hand; you need the API once messages should send themselves. The API is what allows automatic order confirmations, shipping updates, COD confirmation, abandoned-cart reminders, several agents on one number and chatbots. It works through an approved provider, uses pre-approved message templates and requires customer opt-in. For an Indian store where many buyers prefer WhatsApp to email, order updates over the API are usually the first automation worth adding. Source

Mera skincare brand Shopify pe hai aur mahine ke 300 orders aate hain. Ab subscription aur loyalty points add karna chahta hoon. Yeh Shopify app se ho jayega ya custom banwana padega?

300 orders ke level pe pehle ready Shopify apps aazmaiye; subscription aur points dono ke liye apps milte hain aur jaldi lag jate hain. Custom tab banwaiye jab app ke rules aapke kaam ke na hon, jaise points ka online aur offline dono jagah chalna, apne hisaab ki expiry, ya app ki monthly fees orders ke saath bahut badh rahi ho. Custom private app mein rules aapke hote hain aur data aapke paas rehta hai. WavX private Shopify apps aur loyalty systems dono banata hai. Source

My freelancer built a custom app for my Shopify store two years ago and has now stopped responding. The app still runs, but I have no idea where the code lives or who pays for the server. How do I find out what I have and get control of it?

Start in your Shopify admin: the apps section shows the custom app, its permissions and the URL it calls, and that URL reveals where it is hosted. Then check your own card and email for a cloud or hosting bill; if there is none, the freelancer's account is paying and the app can stop without warning. Ask in writing for the repository and hosting to be transferred. If nothing comes back, a developer can document what the app does from its behaviour and rebuild it under your accounts. Source

WavX starting prices (base scope, before add-on features)

From the cost model behind the WavX calculators. A quote follows a scoping call; features, integrations and scale move these figures. Annual maintenance is typically 15–25% of the build cost.

BuildStarting priceTypical timeline
Landing pagefrom ₹40,0003–6 weeks
Business websitefrom ₹50,0003–6 weeks
E-commerce storefrom ₹1,50,0003–6 weeks
Internal tool / dashboardfrom ₹2,00,0003–6 weeks
Custom web applicationfrom ₹4,50,0006–10 weeks
SaaS productfrom ₹7,00,00010–16 weeks
ERP / CRM systemfrom ₹9,00,00010–16 weeks
AI chatbotfrom ₹1,50,0003–6 weeks
RAG assistant (your data)from ₹3,50,0006–10 weeks
AI agent / automationfrom ₹5,00,0006–10 weeks
AI feature in an appfrom ₹2,50,0003–6 weeks

Calculators: website, software, AI, mobile app. Pricing explained: https://www.wavxsolutions.in/pricing.

About WavX Solutions

WavX Solutions (WAVX — Web Application & Venture Exchange) is a remote-first, 100% custom software development company founded in 2022 in Gurgaon, Delhi NCR, India. WAVX designs, builds, scales and maintains custom websites, web applications, iOS and Android apps, Shopify stores, ERP/CRM software, loyalty systems, AI integrations and performance marketing for startups, businesses, brands and institutions across India.