For a new Shopify integration, I use the Dev Dashboard. Creating a new custom app inside a store’s admin is no longer an option.
Shopify’s changelog of 30 October 2025 sets the change at 1 January 2026 and points developers to the Dev Dashboard. Its distribution documentation says existing admin-created apps keep working.
That distinction matters. I do not recommend replacing a working app just because the creation route changed.
The distribution decision comes first
Shopify documents three relevant boundaries:
Comparison table — scroll horizontally to see all columns
| Method | Store footprint | Approval and billing |
|---|---|---|
| Custom distribution | One store, stores in the same Plus organisation, or transfer-disabled development stores | No Shopify approval; no Shopify app billing |
| Public distribution | Multiple stores | Shopify review required |
| Existing admin-created custom app | One store | Continues working; cannot create a new one this way |
The distribution method cannot be changed after selection. I agree it before building the installation flow.
How I organise agency integrations
For unrelated client stores under custom distribution, I create separate app records. Each has documented scopes, credentials, an owner and an installation target.
That does not mean copying the whole codebase for every client. I can maintain shared integration code while keeping app records and access separate. The distribution rule limits where one app can install; it is not a ban on code reuse.
I keep four things in the handover:
- Scopes. What the integration may read or change, and why.
- Credentials. Where they live, who can revoke them and what rotation requires.
- Maintenance. Which API version, webhooks and deployed code the integration uses.
- Ownership. Who maintains the app and what happens when the engagement ends.
Separate app records reduce accidental sharing of access. They do not contain a leak from a shared server or a compromised dependency. Those need separate controls.
What the merchant approves
Custom distribution uses an install link. I explain the requested access before asking the merchant to install.
Ending the engagement needs an explicit handover or shutdown plan: uninstall the app where appropriate, revoke remaining access and retire the integration’s credentials. An app record does not do that administration for us.
For the wider build and maintenance process, see my personal Shopify app lifecycle guide.
I can build the integration
This is part of direct API integrations: the app record, scoped access, event handling and maintenance instructions. The broader service is API integrations and automation.
If the task is clear, I can quote the build directly. If the scope and ownership are unresolved, I start with a separate diagnostic engagement.