Shopify

Point Shopify at one webhook and every paid order becomes a review invitation — one per product in the basket, with the products registered for you the first time they are ordered.

  1. 1

    Tell TrueAvis which shop is yours

    Set your myshopify.com domain and a webhook secret on the project. The domain is how an incoming webhook is matched to your account; the secret is what proves the webhook really came from Shopify.

  2. 2

    Add the webhook in Shopify

    In Shopify admin, go to Settings → Notifications → Webhooks and create one:

    FieldValue
    Eventorders/paid — or orders/fulfilled if you would rather ask after delivery
    FormatJSON
    URLhttps://trueavis.com/api/shopify/webhook

    Copy the signing secret Shopify shows you into the project’s webhook secret. They must match, or every delivery is rejected with a 401.

  3. 3

    Place a test order

    Shopify sends the order; TrueAvis verifies the signature, reads the line items, and records one invitation per distinct product.

What it does with an order

SituationWhat happens
Two sizes of one shirtOne product, one invitation. A repeated line item is still one thing to review.
Three different productsThree invitations, each bound to its own product.
A product TrueAvis has never seenRegistered automatically from the Shopify handle and title, then invited. No catalogue sync to maintain.
An order with no line-item handlesOne invitation for the business itself, rather than none.
An order with no email addressAcknowledged with 200 and no invitation. A point-of-sale order is not a failure, and Shopify must not be left retrying it.
Shopify retries a deliveryThe repeat is recognised and reported as already invited. Retries cannot mint a second link, so they cannot inflate a rating.

Why the signature check is strict

The HMAC is computed over the exact bytes Shopify sent. TrueAvis reads the raw body and never re-serialises it first — parsing JSON and stringifying it again reorders keys and changes whitespace, and the digest stops matching. If you proxy this endpoint, your proxy must pass the body through untouched.

The comparison is timing-safe, and a webhook whose signature does not verify is rejected outright. Without that, anyone who learned your shop domain could mint verified reviews at will.

Sending the invitation is not wired up yet

The webhook records invitations, but nothing emails them, and the tokens are deliberately kept out of the webhook response — Shopify logs replies, and a logged token is a forgeable review. So invitations created this way cannot be delivered yet. Until that is built, use the admin API, which returns the link for you to send from your own email system.

The response

Deliberately thin: how many invitations were created, and why none were, if that is the case. No tokens, no email addresses.

json
{ "invited": true, "invitations": 2 }