Shopify
Point Shopify at one webhook and every paid order becomes a review invitation — one per product in the basket, with the products registered for you the first time they are ordered.
- 1
Tell TrueAvis which shop is yours
Set your
myshopify.comdomain and a webhook secret on the project. The domain is how an incoming webhook is matched to your account; the secret is what proves the webhook really came from Shopify. - 2
Add the webhook in Shopify
In Shopify admin, go to Settings → Notifications → Webhooks and create one:
Field Value Event orders/paid— ororders/fulfilledif you would rather ask after deliveryFormat JSON URL https://trueavis.com/api/shopify/webhookCopy the signing secret Shopify shows you into the project’s webhook secret. They must match, or every delivery is rejected with a
401. - 3
Place a test order
Shopify sends the order; TrueAvis verifies the signature, reads the line items, and records one invitation per distinct product.
What it does with an order
| Situation | What happens |
|---|---|
| Two sizes of one shirt | One product, one invitation. A repeated line item is still one thing to review. |
| Three different products | Three invitations, each bound to its own product. |
| A product TrueAvis has never seen | Registered automatically from the Shopify handle and title, then invited. No catalogue sync to maintain. |
| An order with no line-item handles | One invitation for the business itself, rather than none. |
| An order with no email address | Acknowledged with 200 and no invitation. A point-of-sale order is not a failure, and Shopify must not be left retrying it. |
| Shopify retries a delivery | The repeat is recognised and reported as already invited. Retries cannot mint a second link, so they cannot inflate a rating. |
Why the signature check is strict
The HMAC is computed over the exact bytes Shopify sent. TrueAvis reads the raw body and never re-serialises it first — parsing JSON and stringifying it again reorders keys and changes whitespace, and the digest stops matching. If you proxy this endpoint, your proxy must pass the body through untouched.
The comparison is timing-safe, and a webhook whose signature does not verify is rejected outright. Without that, anyone who learned your shop domain could mint verified reviews at will.
Sending the invitation is not wired up yet
The response
Deliberately thin: how many invitations were created, and why none were, if that is the case. No tokens, no email addresses.
{ "invited": true, "invitations": 2 }