Shopify Multipass API

Multipass login is for store owners who have a separate website and a Shopify store, enabling seamless single sign-on by redirecting users and automatically logging them in. Requires a Shopify Plus plan. Tokens are valid for 15 minutes and can only be used once.

OpenAPI Specification

shopify-multipass-api-openapi.yml Raw ↑
openapi: 3.1.0
info:
  title: Shopify Admin REST About Multipass API
  description: The Shopify Admin REST API lets you build apps and integrations that extend and enhance the Shopify admin. Access products, customers, orders, inventory, fulfillment, and more. Endpoints are organized by resource type and versioned by release date.
  version: 2025-01
  contact:
    name: Shopify
    url: https://shopify.dev/docs/api/admin-rest
    email: api@shopify.com
  license:
    name: Shopify API Terms
    url: https://www.shopify.com/legal/api-terms
  x-date: '2026-03-04'
servers:
- url: https://{store}.myshopify.com/admin/api/2025-01
  description: Shopify Admin REST API
  variables:
    store:
      default: my-store
      description: The Shopify store subdomain
security:
- AccessToken: []
tags:
- name: Multipass
  description: Single sign-on token-based authentication
paths:
  /account/login/multipass/{token}:
    get:
      operationId: multipassLogin
      summary: Shopify Log in a customer using a Multipass token
      description: Authenticates a customer using a Multipass token. The token is generated server-side by encrypting a JSON customer payload with AES-128-CBC and signing it with HMAC-SHA256 using keys derived from the store Multipass secret. The token is valid for 15 minutes and can only be used once. On success the customer is logged in and redirected to the return_to URL or the store homepage.
      tags:
      - Multipass
      parameters:
      - name: token
        in: path
        required: true
        description: The encrypted and signed Multipass token. Generated by encrypting a JSON payload containing at minimum an email address, then Base64 URL-encoding the result.
        schema:
          type: string
      responses:
        '302':
          description: Successful authentication. Redirects to the return_to URL specified in the token payload or the store homepage.
          headers:
            Location:
              description: The redirect destination URL
              schema:
                type: string
                format: uri
            Set-Cookie:
              description: Session cookie for the authenticated customer
              schema:
                type: string
        '401':
          description: Token is invalid, expired, or has already been used.
        '403':
          description: Multipass is not enabled for this store or the store is not on a Shopify Plus plan.
components:
  securitySchemes:
    AccessToken:
      type: apiKey
      name: X-Shopify-Access-Token
      in: header
      description: Access token obtained via OAuth