Shopify App Store Compliance: Why Third-Party Orders Must Use Shopify Checkout

Hey store owners and fellow Shopify enthusiasts! I often see fascinating discussions pop up in the Shopify Community forums, and one recently caught my eye because it touches on a really critical point for anyone using or building apps that handle orders from outside Shopify. It’s about navigating the fine line between what the API technically allows and what the App Store policies actually permit.

The original question, posed by a developer named adamdturner, was pretty straightforward: “Is importing paid third-party platform orders via orderCreate allowed for App Store apps?” He was building a public app where customers would buy a merchant’s products on an entirely separate platform. Payment would complete there, never touching the Shopify storefront. The app’s job was then to import these already completed, paid orders into Shopify using the

orderCreate
mutation, primarily for fulfillment tracking.

The Conflicting Signals: API vs. App Store Rules

Now, here’s where the confusion began for adamdturner. On one hand, Shopify’s API terms compliance guidelines seem to suggest that orders originating from a third-party product listing should be imported using

orderCreate
. Sounds like a green light, right?

But then there’s App Store requirement 1.1.2, which explicitly states that public apps cannot “bypass checkout or payment processing, or register any transactions through the Shopify API in connection with such activity.” This is where alarm bells start ringing. It felt like a classic case of what the API can do versus what the App Store will allow.

The Community Weighs In: A Clear “No” for Public Apps

Thankfully, the community jumped in to clarify. AlogramAI quickly highlighted this “important scope distinction.” While the API terms explain how to sync an order if it’s permitted, it doesn’t override the core App Store requirement. As AlogramAI pointed out, Shopify staff had already clarified that for public App Store apps, checkout currently has to happen through the merchant’s Shopify checkout.

Then, cuongnm_trooix provided a really comprehensive breakdown that solidified the answer. He agreed with the “two separate layers” idea: API capability and App Store eligibility are distinct. He emphasized that requirement 1.1.2 is paramount for public apps and directly prohibits registering API transactions connected to an offsite or third-party checkout.

To drive the point home, cuongnm_trooix even referenced a previous, closely related public-app case where Shopify staff gave a direct “No” to importing orders already paid outside Shopify for fulfillment. This is a crucial piece of insight!

So, the takeaway is pretty clear: for a normal public App Store app, this flow is not allowed. Even the current sales channel requirements insist that customers must be taken to Shopify Checkout. This makes total sense when you think about it from Shopify's perspective — they need to ensure the security, integrity, and proper attribution of transactions within their ecosystem.

What’s Your Action Plan If This Affects You?

If you’re a developer building an app, or a merchant considering an integration that involves importing already paid orders from a third-party platform, here’s the critical advice from the experts in the thread:

Before you build around this model, get written confirmation from Shopify App Review. This isn't just a suggestion; it’s a non-negotiable step to avoid having your app rejected or removed from the App Store later. When you reach out to them, make sure you clearly describe your exact flow, including these key points:

  1. Where product discovery happens: Is it on Shopify, on the third-party platform, or somewhere else entirely?
  2. Where checkout and payment happen: Is it exclusively on the third-party platform, or is there any interaction with Shopify's checkout?
  3. Whether the app directs a buyer away from a Shopify storefront: Does your app ever redirect customers to an external site for purchase?
  4. Whether the imported order includes a successful transaction or is marked paid: Are you importing orders that have already been fully paid for externally?
  5. Whether Shopify expects the integration to be reviewed as a sales channel: Sometimes specific types of integrations might fall under a sales channel classification, which could have different rules, but don't assume this automatically resolves the checkout bypass issue.

Unless App Review specifically confirms a permitted path for your unique model, the current guidance for public apps is to route the buyer through Shopify Checkout. It’s all about maintaining a consistent, secure, and compliant experience within the Shopify ecosystem. Better safe than sorry when it comes to App Store compliance!

Share:

Start with the tools

Explore migration tools

See options, compare methods, and pick the path that fits your store.

Explore migration tools