Forward verified uninstall contact
Use the token-free uninstall contact path when it suits your app.
On this page
What you need
The matching app client secret configured in HeyCrust and your own Shopify webhook handler. Preserve Shopify’s raw signed body and original HMAC headers.
Steps
- Choose this path when you want uninstall contact forwarding without sending a merchant access token through the identify hook.
- Choose one supported forwarding method. The app-generated framework recipes verify Shopify in your own handler, then send authorized contact fields to
/api/identifywith your private workspace key and no merchant access token. Forward before deleting local session/contact context. - For a direct signed Shopify receiver instead, register/forward the exact raw body to
https://heycrust.com/api/webhooks/shopify/<HeyCrust app UUID>with Shopify’sx-shopify-hmac-sha256,x-shopify-topicandx-shopify-shop-domainheaders. - Preserve your app’s required cleanup and acknowledgement behavior. Do not reconstruct JSON before HMAC verification/forwarding.
- Inspect HTTP acknowledgement and the merchant contact record using an authorized uninstall test.
Expected result
A valid signed app/uninstalled payload can upsert merchant contact. This receiver does not replace Shopify Partner lifecycle sync or supply arbitrary product usage.
See Framework recipes and Identification.
Troubleshooting
401 indicates missing/mismatched secret or invalid signature. Non-uninstall topics are acknowledged without that contact work; a 200 alone does not prove a usable contact was extracted. Merchant tokens are already revoked at uninstall, so a later contact fetch is not a reliable replacement.