Shopify Private App Token
ID |
shopify_private_app_token |
Severity |
low |
Vendor |
Shopify |
Family |
API Token |
Description
Shopify Inc. is an e-commerce company and e-commerce platform for online stores and retail point-of-sale systems.
A private application allows to integrate third-party web services with a Shopify store.
Security
Any hardcoded Shopify Token is a potential secret reported by this detector.
Accidentally checking-in the token to source control repositories could compromise your Shopify account.
Mitigation / Fix
-
Remove the
Token
from the source code or committed configuration file. -
Follow your policy for handling leaked secrets, which typically require revoking the secret in the target system(s). API Key revocation can be achieved by following their Revoking API Credentials Documentation.
-
If under a git repository, you may remove unwanted files from the repository history using tools like
git filter-repo
orBFG Repo-Cleaner
. You may follow the procedure listed here for GitHub.
You should consider any sensitive data in commits with secrets as compromised. Remember that secrets may be removed from history in your projects, but not in other users' cloned or forked repositories. |