AI assistants
How a subscriber connects an assistant
The three steps a shopper takes themselves, and exactly what the resulting key can and cannot reach.
You do not hand anything to anyone. The subscriber does this themselves, from their own subscription, and nothing in it gives an assistant standing access to your store.
- They open their subscription. The Manage your subscription page, from their Shopify account or the link in your emails. They have to be logged in.
- They tap Create assistant key. The button appears on an active subscription once you have switched the endpoint on.
- They paste the key and the address into their assistant. In ChatGPT, Claude or Copilot they add the address as a connector and give it the key when it asks to sign in.
What the key can and cannot do
| Property | Value |
|---|---|
| Scope | One subscription, belonging to the shopper who created it. |
| Lifetime | Expires on its own after 30 days. |
| Confirmation links | Single use, valid 30 minutes, and rejected if replayed as an access key. |
| Reach | Cannot read or touch any other subscription, customer or order. |
| Revocation | Every key can be revoked, and expired or revoked keys stop working immediately. |
Least privilege by construction. A key is issued against one contract and one customer. Even a leaked key cannot reach a second subscription, which is why this is safe to offer at all.
Related articles