← Latest Shopify changes
Action / breaking change

Expiring offline access tokens required for new public apps as of April 1, 2026

Action RequiredAPIDeprecation announcementAdmin GraphQL APIAdmin REST API

Shopify developer change

MerchantDiff detected this entry in Shopify's official developer changelog on March 20, 2026.

This Shopify update is categorized as Action Required, API, Deprecation announcement, Admin GraphQL API, Admin REST API.

What changed

We're updating how public apps handle offline access tokens to enhance merchant data protection. Starting April 1, 2026, all new public apps must request and use expiring offline access tokens. What apps are affected Public apps created on or after April 1, 2026 that call the Admin API What apps are not affected Public apps created before April 1, 2026 Custom apps created at any time Apps created by merchants either in the Dev Dashboard or in the Shopify admin Why we’re making this change Expiring tokens enhance security. If a token is ever leaked, it stops working within 60 minutes, which significantly narrows the risk to both your app and the merchants who trust it. This change aligns with modern OAuth practices, and as a developer it lets you build your app around predictable refresh flows.

Who is affected

Apps using the affected Shopify GraphQL API surface should review this change.

What action may be needed

New public apps: Implement expiring offline access tokens. If you use Shopify’s app templates and libraries this is already handled for you. Need help? Engage with the dev platform community for support and questions.

Use the official Shopify entry below as the source of truth for technical implementation details, affected APIs, migration instructions and deadlines.

Want the actionable version?

MerchantDiff monitors Shopify API changes, deprecations, deadlines and ecosystem updates, then turns them into developer-focused release intelligence: what changed, who is affected and what action may be needed.

Get MerchantDiff →