# Forward verified uninstall contact

Use the token-free uninstall contact path when it suits your app.

## What you need

The matching app client secret configured in HeyCrust and your own Shopify webhook handler. Preserve Shopify’s raw signed body and original HMAC headers.

## Steps

1. Choose this path when you want uninstall contact forwarding without sending a merchant access token through the identify hook.
2. Choose one supported forwarding method. The app-generated framework recipes verify Shopify in your own handler, then send authorized contact fields to `/api/identify` with your private workspace key and no merchant access token. Forward before deleting local session/contact context.
3. For a direct signed Shopify receiver instead, register/forward the exact raw body to `https://heycrust.com/api/webhooks/shopify/<HeyCrust app UUID>` with Shopify’s `x-shopify-hmac-sha256`, `x-shopify-topic` and `x-shopify-shop-domain` headers.
4. Preserve your app’s required cleanup and acknowledgement behavior. Do not reconstruct JSON before HMAC verification/forwarding.
5. Inspect HTTP acknowledgement and the merchant contact record using an authorized uninstall test.

## Expected result

A valid signed `app/uninstalled` payload can upsert merchant contact. This receiver does not replace Shopify Partner lifecycle sync or supply arbitrary product usage.

See [Framework recipes](/docs/developers/framework-recipes) and [Identification](/docs/developers/identify).

## Troubleshooting

401 indicates missing/mismatched secret or invalid signature. Non-uninstall topics are acknowledged without that contact work; a 200 alone does not prove a usable contact was extracted. Merchant tokens are already revoked at uninstall, so a later contact fetch is not a reliable replacement.
