Skip to content
HeyCrustDocs

Search documentation

Search by topic or tool name
Browse documentation
Guides

Forward verified uninstall contact

Use the token-free uninstall contact path when it suits your app.

On this page

What you need

The matching app client secret configured in HeyCrust and your own Shopify webhook handler. Preserve Shopify’s raw signed body and original HMAC headers.

Steps

  1. Choose this path when you want uninstall contact forwarding without sending a merchant access token through the identify hook.
  2. Choose one supported forwarding method. The app-generated framework recipes verify Shopify in your own handler, then send authorized contact fields to /api/identify with your private workspace key and no merchant access token. Forward before deleting local session/contact context.
  3. For a direct signed Shopify receiver instead, register/forward the exact raw body to https://heycrust.com/api/webhooks/shopify/<HeyCrust app UUID> with Shopify’s x-shopify-hmac-sha256, x-shopify-topic and x-shopify-shop-domain headers.
  4. Preserve your app’s required cleanup and acknowledgement behavior. Do not reconstruct JSON before HMAC verification/forwarding.
  5. Inspect HTTP acknowledgement and the merchant contact record using an authorized uninstall test.

Expected result

A valid signed app/uninstalled payload can upsert merchant contact. This receiver does not replace Shopify Partner lifecycle sync or supply arbitrary product usage.

See Framework recipes and Identification.

Troubleshooting

401 indicates missing/mismatched secret or invalid signature. Non-uninstall topics are acknowledged without that contact work; a 200 alone does not prove a usable contact was extracted. Merchant tokens are already revoked at uninstall, so a later contact fetch is not a reliable replacement.