Connect a Shopify instance to SSPM to detect posture risks.
| Where Can I Use This? | What Do I Need? |
|
|
- SaaS Security Posture Management license
Or any of the following licenses that include the Data Security license:
|
For SSPM to detect posture risks in your Shopify instance, you must onboard your
Shopify instance to SSPM. Through the onboarding process, SSPM connects to a Shopify
API by using an API token that you generate from the Shopify admin page. To ensure
the token has access to only the scopes SSPM needs, you will create a custom app.
You will generate the scope-restricted API token through this custom app. After
connecting to the Shopify API, SSPM scans your Shopify store for misconfigured
settings and account risks.
By following these steps, you onboard only one Shopify
store. If you want SSPM to perform scans for multiple stores, you can onboard each
store separately.
The supported Shopify account plan for SSPM scans is the Shopify Plus plan.
To access your Shopify instance, SSPM requires the following information, which you
will specify during the onboarding process.
| Item | Description |
|
API Token
|
A unique, alphanumeric string that Shopify generates for a
Shopify custom app that you create. SSPM will use the API token
to authenticate to the Shopify API. The API token gives SSPM
access to the scopes specified in the Shopify custom app.
|
|
Store Name
|
A unique, permanent identifier assigned to your store on the
Shopify platform. It is derived from the permanent, default URL
that Shopify assigned to the store. The default URL has the
following format:
<store-name>.myshopify.com.
|
To onboard your Shopify instance, you complete the following actions: