Grant Partner Access to Your Shopify Store (2026 Guide)

June 18, 2026 ·7 min read

Everything you need to set up Wapitee’s access to your store — secure, limited, and fully revocable.

Overview

When you work with Wapitee, we need access to your Shopify admin to implement changes — themes, translations, settings, and code. Instead of creating a full staff account (which consumes a seat and has broad permissions), Shopify provides a better way: Collaborator Access.

Why We Use It

FeatureBenefit
No Staff SeatUnlimited collaborators on any plan
No Financial AccessBank details & payments stay hidden
Instantly RevocableOne click to remove, access ends immediately
Fully LoggedEvery action recorded in Activity Log

Key Point Collaborator access is like a guest pass with specific room permissions — we can enter the rooms you approve, but never the vault.

Collaborator access works like a guest pass — approved rooms open, the vault stays locked


Why Not Just Create a Staff Account?

FeatureCollaboratorStaff Account
Counts toward plan limitNo — unlimited, freeYes — 2 to 15 seats
Bank / payment detailsNever accessibleCan be granted
Permission scopeCategory-specific, granularFull admin by default
Activity loggingFully loggedFully logged
Best forAgencies, freelancers, partnersFull-time employees

Staff accounts count against your plan’s seat limits. Basic Shopify includes 2 staff seats; standard Shopify includes 5; Advanced includes 15.

Collaborator accounts don’t count toward these limits — you can give us access without giving up a single seat. That matters, because seats are one of the quiet costs of growing a store.

Staff accounts can also access sensitive financial data. Collaborator accounts cannot touch bank account details or Shopify Payments settings by default. That protection is built in — it’s not something you have to configure or remember to enforce.


How It Works

Three parties, one secure handoff — no password sharing, no full admin risk.

The collaborator access flow
Wapitee — Partner Dashboard
Request access
Your Store — Shopify Admin
New collaborator request — Wapitee
DenyApprove
✉️Confirmation email
🔓Access granted — scoped permissions only
Payments & bank details stay locked at every step.
  1. Wapitee (Partner Dashboard) sends an access request with specific permission categories
  2. Your Store (Shopify Admin) reviews and approves the request
  3. Access Scope is limited to approved categories — Payments and Bank details are always blocked

How to Grant Access (Your Side)

You only need to do two things on your end — takes about five minutes in total. The rest is automatic.

Step 1: Set Up a Collaborator Request Code

Go to Settings → Users and permissions → Collaborators. Click “Enable collaborator request code.” Shopify generates a 4-digit code (e.g., 4821).

Then share two things with us:

  1. The 4-digit code
  2. Your store’s myshopify.com domain (e.g., yourstore.myshopify.com) — visible in your admin URL or under Settings → Store details

The code alone isn’t enough: our Partner Dashboard needs the store domain to know which store to send the collaborator request to.

Step 2: Approve Our Request

After we send the access request, you’ll receive an email + in-admin notification. Go to Settings → Users and permissions → Collaborators, find the pending request, review the permission categories, and click Approve.

⚠️ Important The 4-digit request code is the key security gate. Share it only with us (Wapitee) — never post it publicly. You can change or disable it at any time.


What We’ll Request

For typical localization and development projects, we request these specific permission categories:

PermissionWhat It IncludesStatus
ProductsProduct listings, inventory, collections
ContentBlog posts, pages, metaobjects
Online StoreThemes, navigation, preferences
SettingsStore settings, languages, markets
AppsApp installations, channels
OrdersOrder management, fulfillmentOptional
Payments / BankNever accessible — blocked by design

We always start with the minimum permissions a project needs, and only ask for more if a specific task requires it. You stay in control of every escalation.


Keeping Your Store Safe

Your security checklist
Enable the collaborator request code Settings Users and permissions Collaborators
Review the store activity log weekly Settings Store activity log
Remove access when the project ends — one click, access ends immediately Settings Users and permissions Collaborators Remove access
🔒
Payments & bank details — never accessible to collaborators Blocked by design, on every plan

Turn On the Request Code

The request code keeps strangers out: only people who have your code — right now, that’s us — can even send an access request. If you ever end the engagement, change or disable the code and that door closes for good.

Keep an Eye on the Activity Log

Go to Settings → Store activity log to see every change we make. Filter by user to see exactly what we touched. During an active project, a weekly glance is plenty — and if you ever spot something you don’t recognize, flag it to us right away.

Remove Our Access When We’re Done

When the project wraps, revoking us takes one click: Settings → Users and permissions → Collaborators → Remove access. Our access ends instantly — no grace period, no leftover sessions.

A Note on AI Tools

Modern Shopify stores increasingly use AI tools like Shopify Sidekick. These tools interact with store data based on your permission settings. As stores integrate more AI systems, sensible permissions matter even more.

The good news: we can’t grant AI tools any extra permissions on your behalf. Only you control AI access levels — that separation is by design.


FAQ

Will this cost me anything?

No. Collaborator accounts are free and don’t count toward your plan’s staff seat limit — our access costs you nothing on any Shopify plan.

Can Wapitee see my bank details or payment settings?

No. Collaborator accounts are blocked from accessing Shopify Payments settings and bank account details by default. This protection exists regardless of which other permissions are granted.

How long does the request code last?

The code remains active until you change or disable it — it doesn’t expire on its own. Once our project wraps up, we recommend rotating it.

Can I approve from my phone?

Yes. Open the Shopify mobile app → Users section → pending requests appear with notification badges. You can review and approve directly from your phone.

What if I want to remove access mid-project?

You can revoke access at any time, instantly. Go to Settings → Users and permissions → Collaborators, find our name, and click “Remove access.” We lose entry immediately.

Can I limit what Wapitee can see or change?

Absolutely. When approving our request, you can uncheck any permission category you don’t want us to have. You can also adjust permissions after approval at any time without notifying us.

Information Verification

Verified: 2026-06-25