API Explorer
Run live Admin GraphQL, Admin REST, and Storefront requests against your connected store.
The connected Shopify view includes an API Explorer for running live requests against your store. It is a segmented workspace with three surfaces, plus a separate Webhooks tab.
The Storefront surface works at either connection level. The Admin GraphQL, Admin REST, and Webhooks tabs need a full access connection, because they run against the Admin API through your own app.
Credentials stay on Lyna's servers. The explorer sends your query to Lyna, which injects the access token server side and returns only the response. Admin requests use short-lived Admin API tokens that Lyna obtains from your app's Client ID and Client secret and renews automatically. Your Client secret and Admin tokens are never exposed to the browser.
The explorer targets Shopify API version 2025-10. It opens inset in the settings panel and can be expanded to fullscreen.
Admin GraphQL
Requires a full access connection. Query and mutate store data with the Admin GraphQL API, authenticated with a short-lived Admin API token (sent as the X-Shopify-Access-Token header on Lyna's servers).
The Admin GraphQL surface is a full GraphiQL workspace:
- Editor with autocomplete, plus variables and headers panels.
- Schema and Docs explorer to browse every type and field in the Admin API.
- History and tabs that persist across sessions.
- Query cost in the response
extensions(requested cost, actual cost, and throttle status), so you can see how each query draws on Shopify's rate limit. - Send to AI, which drops the last query and response into chat so Lyna can explain it or wire it into your app.
The live GraphiQL workspace is built for wide screens. Open the project on a desktop to query the schema interactively.
Admin REST
Requires a full access connection. Read and write store resources with the Admin REST API, authenticated with the same short-lived Admin API token (X-Shopify-Access-Token, added on Lyna's servers).
The REST surface is a request builder:
- Pick a method (GET, POST, PUT, PATCH, DELETE) and a path (for example
products.json). - Add query parameters as key and value pairs.
- Use the curated endpoints menu for common resources: Products, single product, Orders, Customers, Price rules, Inventory levels, Collects, Smart collections, Custom collections, Webhooks, and Shop.
Prefer the GraphQL surface when an equivalent exists; use REST for endpoints that have no GraphQL counterpart.
Requests that read customer or order data go through your own app, and Shopify may require protected customer data approval on that app before they work on a production store. Development stores are exempt. Request the protected customer data permissions in your app's settings on Shopify if these reads report missing access.
Storefront
Fetch public catalog data with the Storefront API. The storefront access token is public and safe to embed in your client app, so this is the surface your published storefront actually uses.
The token comes from the Headless storefront you created in your Shopify admin during Storefront connect. If the connection has no storefront token yet, add one from Settings > Integrations > Shopify. You can manage the storefront's read permissions from the Headless channel in your Shopify admin.
The Storefront endpoint is https://{shop-domain}/api/{version}/graphql.json, called with the X-Shopify-Storefront-Access-Token header.
Tokens and scopes
The connected Overview tab shows what the connection can do:
- Storefront access token, the public token your app uses to read catalog and cart data. It comes from the Headless storefront on your store.
- Admin API scopes (full access connections), the scopes your app was released with (for example
write_products,read_inventory,write_discounts). These are the scopes you pasted from Lyna's connect wizard when configuring the app version.
To change the Admin scopes, edit the app version in the Shopify Dev Dashboard, release it, and update the installation on your store. Lyna picks up the new grant on the next token renewal.
For your security, your app's Client secret is held encrypted on Lyna's servers and is never displayed in the browser. The Admin API tokens Lyna uses are short-lived and renew automatically. Rotate the Client secret from your app's settings in the Dev Dashboard if you ever need to revoke access.
Webhooks
Requires a full access connection. The Webhooks tab lists the webhook subscriptions registered for the store, and lets you create or delete them. Shopify sends events to these endpoints when store data changes.
- Create a subscription by choosing a topic and a callback URL. Available topics include
APP_UNINSTALLED,APP_SCOPES_UPDATE,SHOP_UPDATE,PRODUCTS_CREATE,PRODUCTS_UPDATE,ORDERS_CREATE, andORDERS_PAID. The callback URL defaults to Lyna's own Shopify webhook route on the current origin (/webhook/shopify). - Delete a subscription to stop Shopify from sending that topic to the endpoint.
You can manage the same subscriptions from chat by asking Lyna to list, create, or delete webhooks.