Shopify AI Agent Integrations: 34 Apps by What Their APIs Allow
We checked 34 Shopify apps across eight support categories on 28 September 2026. For 19 of them, a Shopify AI agent working support tickets can change a record, such as skipping a subscription charge, replying to a review or voiding a shipping label, through a documented API with a static key.
Key takeaways
- Of 34 Shopify apps checked across eight categories on 28 September 2026, 19 document at least one support write that an AI agent can call with a static API key.
- Six of those 19 apps sell API access only on a paid plan, from ShipStation's Standard plan at $29.99 a month to Smile.io's Plus plan at $999 a month, billed annually.
- Recharge has no pause endpoint, Route has no claim endpoint and Yotpo's reviews API uses an access token that expires, so those three jobs stay with a person or the vendor's own app.
- Order-tracking apps split on the lookup key: CWILL, formerly ParcelPanel, accepts an order number, while 17TRACK accepts only a tracking number registered first.
- Macha reads Shopify orders and issues refunds through its built-in Shopify connector and connects every other app here through a custom API tool that Macha's team sets up during onboarding. On a test ticket, the Shopify connector answered while placeholder-key tools for Loop Returns and Smile.io got HTTP 401 from the vendors' live APIs.
Six more are read-only for an agent, six can't be reached at all, and three we couldn't verify because the developer docs were behind a login or offline. Six of the 19 put their API behind a paid plan. Below is the full map, the Black Friday tickets each app answers, the jobs that still need a person, one live test ticket, and what to check before 27 November.
What does "Shopify AI agent" mean on this page?
Shopify uses the phrase for three different things. Sidekick is the assistant inside the Shopify admin that works for the merchant. Agentic commerce is Shopify's name for AI shopping agents that act for buyers, finding products and checking out through its Universal Commerce Protocol. This page covers the third kind: an agent that works customer support tickets in your help desk and reads or changes records in Shopify and the apps around it. For choosing the vendor behind that agent, see AI customer service for Shopify.
| Meaning | What does the job | One concrete fact |
|---|---|---|
| Sidekick | Shopify's own assistant, working for the merchant in the admin | Merchants can chat with it from any page of the Shopify admin, by text, voice or screen sharing |
| Agentic commerce | AI shopping agents acting for buyers | Shopify's MCP tools implement the Universal Commerce Protocol at every step of the buyer journey, from discovery to order tracking |
| Support agent (this page) | An agent layer on your help desk that works tickets | It reads Shopify orders and calls app APIs; 19 of the 34 apps below accept its writes with a static key |
Which Shopify apps can an AI support agent work with?
"Static key" means the merchant creates a token once in the app's settings and the agent sends it in a header on every call. No shopper login, no token that expires overnight. That's the condition for an agent that works tickets on its own at 2 a.m. on Black Friday. Every "can do" cell lists only what the vendor's API reference documents, and the app name links to that reference. Ratings and review counts are from each app's Shopify App Store listing on 28 September 2026.
| Category | App (rating, reviews) | What an AI agent can do, per the API docs | Auth and plan gate | Route |
|---|---|---|---|---|
| Subscriptions | Appstle Subscriptions (5.0, 8,822) | Skip an order, pause or cancel via status, change next billing date and address | X-API-Key; paid API plan unless used through an approved partner | Custom API tool |
| Subscriptions | Recharge (4.8, 3,121) | Skip a charge, cancel, set next charge date, change address; no pause | X-Recharge-Access-Token | Custom API tool |
| Subscriptions | Seal Subscriptions (4.9, 3,113) | Pause, cancel, resume; skip or reschedule a billing attempt | X-Seal-Token | Custom API tool |
| Subscriptions | Kaching Subscriptions (5.0, 1,067) | No public API found | none | Not feasible |
| Subscriptions | Shopify Subscriptions (3.7, 825) | Needs an Admin API app. New custom apps can't be created in the Shopify admin since 1 January 2026; a Dev Dashboard app's tokens expire after 24 hours | Expiring app token | Not feasible with a static key |
| Subscriptions | Loop Subscriptions (5.0, 767) | Find subscriptions by email, skip next order, pause, cancel | X-Loop-Token; PRO plan | Custom API tool |
| Subscriptions | Skio (5.0, 241) | Skip, pause, unpause, cancel, change next billing date (GraphQL) | authorization: API <token> | Custom API tool |
| Tracking | 17TRACK (4.9, 4,399) | Register a tracking number, then read status and events | 17token; 200 free numbers once | Custom API tool, read-only |
| Tracking | CWILL, formerly ParcelPanel (5.0, 3,159) | Read tracking by order number or order ID | x-parcelpanel-api-key; Professional, $59/mo | Custom API tool, read-only |
| Tracking | Track123 (4.9, 1,727) | Read tracking by tracking number or by an orderNos list of order numbers | Track123-Api-Secret | Custom API tool, read-only |
| Tracking | AfterShip Tracking (4.6, 1,505) | Read trackings, retrack an expired one | as-api-key; Premium, $59/mo on aftership.com, $70/mo through the App Store listing | Custom API tool, read-only |
| Returns | AfterShip Returns (4.7, 1,542) | Read returns; approve, resolve or reject a return | as-api-key; Premium, $99/mo | Custom API tool |
| Returns | Redo (4.9, 783) | Read return status, create a return | Bearer API secret | Custom API tool |
| Returns | Return Prime (4.8, 768) | Developer docs didn't load on 28 Sept | unverified | Unverified |
| Returns | Loop Returns (4.6, 443) | Get return details by order name, cancel a return; labels need OAuth | X-Authorization scoped key | Custom API tool |
| Reviews | Judge.me (5.0, 47,588) | Find reviews, post a public reply (POST /replies), send a private reply, update a review | X-Api-Token plus shop_domain | Custom API tool |
| Reviews | Loox (4.9, 9,689) | Developer docs returned an error on 28 Sept | API on the Convert plan, $49.99/mo | Unverified |
| Reviews | Yotpo Reviews (4.8, 4,628) | Access token is generated from a secret and expires; regenerate on 401 | X-Yotpo-Token | Not feasible with a static key |
| Loyalty | Smile.io (4.9, 4,608) | Read points, tier and referral link; add points; redeem a points product | Bearer key; Plus plan, $999/mo billed annually | Custom API tool |
| Loyalty | BON Loyalty (5.0, 1,937) | API offered only on an enterprise plan, no public docs | none public | Not feasible today |
| Loyalty | Yotpo Loyalty (4.7, 968) | Fetch a customer's balance and referral link, adjust points | GUID and API key, two headers | Custom API tool |
| Loyalty | LoyaltyLion (4.6, 538) | Add or remove points, redeem or refund a reward | Authorization: Bearer pat_... | Custom API tool |
| Loyalty | Stamped (4.7, 3,751) | Adjust points and VIP tier, redeem a reward, void a coupon; its reviews API is "coming soon", so it's counted here | stamped-api-key | Custom API tool |
| Email and SMS | Shopify Messaging (4.8, 4,560) | Consent lives on the Shopify customer record | Shopify app token | Not feasible |
| Email and SMS | Privy (4.5, 4,212) | Developer docs sit behind a Privy login | unverified | Unverified |
| Email and SMS | Klaviyo (4.7, 3,328) | Read consent, unsubscribe, suppress | Klaviyo-API-Key plus revision, two headers | Custom API tool |
| Email and SMS | Omnisend (4.7, 3,184) | Find and update a contact | Omnisend-API-Key plus Omnisend-Version, two headers | Custom API tool |
| Email and SMS | Postscript (4.7, 1,207) | Unsubscribe, redact, update a subscriber | Shop key; custom use on enterprise plans only | Custom API tool |
| Email and SMS | Attentive (4.7, 111) | Check eligibility, unsubscribe, file a privacy deletion | Bearer private-app key | Custom API tool |
| Shipping and protection | ShipStation (4.2, 707) | Void a label (PUT /v2/labels/:label_id/void), hold an order | API-Key; Standard plan, $29.99/mo | Custom API tool |
| Shipping and protection | Route (4.0, 377) | Read a shipment; no claim endpoint | token header | Custom API tool, read-only |
| Shipping and protection | ShipBob (4.3, 286) | Update a shipment address, cancel an order, place a shipment on hold | Personal access token | Custom API tool |
| Fraud | Blockify Fraud Filter (4.9, 1,732) | No public API found | none | Not feasible |
| Fraud | Signifyd (4.4, 90) | Read the fraud decision on an order | API key | Custom API tool, read-only |
| Baseline | Shopify | Search and get orders, look up a customer and their orders, search products, read discounts; cancel an order; refund everything still refundable (no partial amount) | OAuth | Built-in connector |
| Baseline | Stripe | Get customers, list payments, create a refund or charge | API key | Built-in connector |
The tally by category, which is where the sentence at the top comes from:
| Category | Apps checked | Agent can change records | Read-only | Not feasible | Unverified |
|---|---|---|---|---|---|
| Subscriptions | 7 | 5 | 0 | 2 | 0 |
| Order tracking | 4 | 0 | 4 | 0 | 0 |
| Returns | 4 | 3 | 0 | 0 | 1 |
| Reviews | 3 | 1 | 0 | 1 | 1 |
| Loyalty | 5 | 4 | 0 | 1 | 0 |
| Email and SMS | 6 | 4 | 0 | 1 | 1 |
| Shipping and protection | 3 | 2 | 1 | 0 | 0 |
| Fraud | 2 | 0 | 1 | 1 | 0 |
| Total | 34 | 19 | 6 | 6 | 3 |
Shopify and Stripe are not counted in the 34; they are the baseline every other app is compared against.
Which Black Friday tickets does each app answer?
Black Friday 2026 is 27 November and Cyber Monday is 30 November. The holiday peak planning guide does the volume arithmetic from tickets per order, using the tickets-per-order benchmarks by vertical; this table does the routing. For each ticket type that climbs in the peak window, it names the first system an agent should read and the app that finishes the job.
| What the shopper writes | First read | App category that finishes it | Can an agent finish it end to end? |
|---|---|---|---|
| "Where is my order?" | Shopify order: fulfillment status, carrier, tracking number | Tracking app for scan events and delivery estimates | Yes, it's a read in every tracking app above |
| "Cancel my next box" / "skip December" | Shopify customer by email | Subscription app | Yes in 5 of 7 subscription apps; Recharge's API can skip but not pause |
| "My package says delivered but it isn't here" | Tracking app | Package protection (Route) | No. The agent can check coverage and send the claim link; filing stays with Route's own app or a person |
| "I want to return this" | Shopify order | Returns app | Partly. Status and cancel, yes; label creation in Loop Returns needs OAuth |
| "Where are my points?" | Loyalty app by email | Loyalty app | Yes where the plan includes the API; goodwill points should follow a written limit |
| "My discount code didn't work" | Shopify order total and line items | None of the apps above | Rarely. Code rules live in Shopify's discount settings, so this usually needs a person |
| "Stop texting me" | Email/SMS app by phone or email | Email/SMS app | Yes in Klaviyo, Omnisend, Attentive; Postscript only on enterprise plans |
| "Refund to my Klarna / Shop Pay Installments" | Shopify order and payment method | Shopify | Yes for a full refund: it's issued in Shopify, and the provider adjusts the installments |
Shop Pay Installments is provided by Affirm, but the refund still starts in Shopify. According to Shopify's installments FAQ, a partial refund leaves the customer "a smaller payment balance on the final payment" or fewer future payments, paid interest isn't refunded, and the merchant doesn't get the transaction fee back. Macha's built-in Create Refund refunds the whole remaining balance, so a partial refund on an installments order is one for a person in the Shopify admin. An agent can still explain the rules accurately, which answers most "why is my next installment still due" follow-ups before they're written. The BNPL refunds page covers Klarna and Afterpay the same way.
Which of these apps already have AI actions inside Gorgias or Zendesk?
For the most common subscription jobs, the help desk's own AI got there first. Gorgias AI Agent ships ready-made Actions for Recharge, Skio and Loop Subscriptions, and Shopify order changes such as canceling an order or editing its address. AfterShip announced an integration that feeds tracking and returns data to Gorgias's AI. On Zendesk, AI agents can call Shopify actions in action flows, and Route's Zendesk app lets a human agent file a claim, which Route's public API doesn't.
Help desks have an incentive to build AI actions for the apps with the most shared merchants, because each action sells their AI tier to thousands of stores at once. That's why Recharge and Loop get ready-made Actions while Seal and Appstle, each with more App Store reviews than Loop, have none that we could find in Gorgias's help center. If your stack is the top three apps on one help desk's partner list, its native AI may already cover you. If you run the fourth app, or you're on a desk whose marketplace is thin on ecommerce, the gap is a custom call. The help desk AI actions matrix compares what each desk's own AI can do in Shopify, and the Gorgias integrations roundup lists the apps Gorgias connects natively.
Which Shopify apps can't an AI agent reach, and why?
Six apps in our set are out of reach today, and three reachable ones have a single job an agent can't do. The reasons fall into five groups.
- No public API. Kaching Subscriptions and Blockify publish none that we could find. BON Loyalty's listing says to contact it for an enterprise plan that includes an API; there's no public reference to build against.
- A token that expires. Yotpo's reviews API generates an access token from the store's secret, and its docs say to generate a new one when a call returns 401. A tool with a fixed header can't do that refresh. Yotpo Loyalty is a separate API with a static GUID and key, which is why it's in the reachable column.
- OAuth only for one job. Loop Returns' keys cover return details and cancellation, but its authentication page says OAuth is required for the Label API.
- No endpoint for the job. Recharge's 2021-11 reference has no pause endpoint: pausing is a customer-portal feature that the API only reports through a
subscription/pausedwebhook, so an agent can at most skip a charge or move the next charge date, and Route's merchant API has no claim endpoint. The Recharge page and the Route page set out what an agent can do instead. - The platform moved the door. Shopify Subscriptions and Shopify Messaging keep their data inside Shopify's Admin API. Since 1 January 2026, new custom apps can't be created in the Shopify admin; Shopify's changelog points merchants to the Dev Dashboard instead, and a Dev Dashboard app that authenticates itself gets tokens that, per Shopify's docs, "expire after 24 hours." That's the same problem as Yotpo's token. Custom apps created before 2026 keep working. Macha's Shopify connector reads orders, customers, products and discounts, and can cancel or refund an order, but it has no subscription-contract or marketing-consent tool.
Plan gates aren't a wall, but they're the most common surprise, and the incentive behind them is an upsell: API access is cheap to serve and valuable to a merchant automating support, so vendors park it one tier up. Loop Subscriptions issues tokens only on its PRO plan. Postscript's page on API access says that since April 2022 "custom API access for individual shops is limited to those on enterprise plans"; shops that had custom access before then kept it as "grandfathered access." Appstle's authentication page says merchants need a paid API plan unless they use an approved partner integration, whose scoped tokens "bypass the paid API plan requirement." Smile.io's docs say merchant API keys are "only available on the Plus or Enterprise plan", and Plus is $999 a month billed annually. AfterShip puts the Tracking API on Premium at $59 a month on its own site ($70 through the App Store listing) and the Returns API on Premium at $99. ShipStation's App Store listing puts "Shipping API" on Standard at $29.99, and Loox lists "API access" on Convert at $49.99.
What can an AI agent do in each app category?
Each category has its own hub with the full matrix. These are the short versions, with the one fact that decides each.
Subscriptions
Pause is where the subscription apps differ. Five of the seven apps here document skip and cancel with a static key, and every one of those five except Recharge also documents pause. Recharge customers can pause in its portal, but the API has no pause call. The subscription apps hub compares them job by job.
Order tracking
All four tracking apps are read-only for support purposes, which suits the job, since "where is my order" is a read. What differs is the key the shopper has. Customers quote order numbers. CWILL's GET /api/v2/tracking/order takes one directly, and Track123's POST /tk/v2.1/track/query accepts an orderNos list, which only matches trackings that carry the order reference; 17TRACK needs a tracking number registered first and allows 3 requests a second. Shopify's own order already carries the carrier and tracking number, so an agent can answer the basic question before calling any tracking app. The order-tracking hub covers them in detail.
Returns
Three of four returns apps accept writes with a key. AfterShip Returns can approve, resolve or reject a return; Redo can create one; Loop Returns can cancel one. Nobody here lets a static key generate a label. See the returns apps hub.
Reviews
Judge.me, the most-reviewed app in our whole set at 47,588 reviews, has the most useful support API in the category: POST /replies posts a public reply on the review widget and POST /private_replies emails the reviewer privately, both with a private key in X-Api-Token. Stamped's newer review API is still "coming soon", per its own docs, so this page counts Stamped under loyalty, where its documented writes are. The review apps hub compares the rest.
Loyalty
"Where are my points?" is a read in every reachable loyalty app, and a goodwill top-up is a write in four: Smile.io, Yotpo Loyalty, Stamped and LoyaltyLion, whose API keys start with pat_ and carry scopes you choose when you create them. The Smile.io page covers points lookups and missing points in detail. Stamped also documents Adjust VIP Tier; Smile.io's reference lists VIP tiers but has no endpoint to change a customer's tier. The loyalty apps hub goes deeper.
Email and SMS
Unsubscribe requests are a compliance job as well as a support one, and the Klaviyo page walks through unsubscribes, suppressions and consent checks for that one app. Klaviyo and Omnisend both need two headers on every call: Klaviyo a revision date, Omnisend Omnisend-Version: 2026-03-15. Postscript's Unsubscribe and Redact endpoints exist for every shop, but only enterprise shops may call them from a custom build. The email and SMS hub maps the rest.
Shipping and package protection
ShipBob documents Update Shipment Address and Bulk Place Shipments On Hold; ShipStation documents voiding a label, and its docs note a voided label "cannot be un-voided." Route is read-only for claims. The shipping and protection hub covers the before-it-ships window in detail.
Fraud
An agent's job with a fraud app is to read the decision and tell the customer what happens next, or hand off. Signifyd's API documents Get Decision; Blockify has no API. A fraud hold isn't a decision an agent should reverse.
What should you check before Black Friday on 27 November?
Most of what breaks an app connection in peak week is visible a month earlier. Run this list per app, in this order.
- Confirm the plan includes the API. Loop Subscriptions, Smile.io, AfterShip, ShipStation and Postscript all tie API keys or custom use to a plan, so check the plan before anyone builds a tool.
- Create a key with only the scopes the job needs. LoyaltyLion and Loop Returns both scope keys at creation. A read-only tool should hold a read-only key.
- Pin the API version. AfterShip's Tracking and Returns APIs are versioned
2026-07in the URL; Recharge sends2021-11; Loop Subscriptions uses2026-04; Klaviyo and Omnisend take a version header. An unpinned call changes behavior when the vendor ships. - Check rate limits against peak volume. 17TRACK allows 3 requests a second, CWILL 120 a minute per key, AfterShip's GET /trackings 6 a second, Loop Subscriptions 50 a second per store. At 3 a second, 17TRACK handles 180 lookups a minute, more than most support queues need, but a bulk backfill during peak week can hit it.
- Check for rebrands and moved hosts. CWILL changed its API base URL from open.parcelpanel.com to open.parcelwill.com on 11 February 2026. A tool built from an old tutorial calls the dead host.
- Test on a real order. Pick one real order and one real subscriber, run each read, and confirm the answer the agent writes matches what the app's admin shows. Run writes on a test customer.
- Write the handoff line. For every job in the "can't reach" list, the agent's instructions should say who takes it and what the agent tells the customer meanwhile.
How does Macha connect these apps?
Two of the rows in the table are built-in. Macha's Shopify connector (walked through in the Macha Shopify integration guide) authorizes once with OAuth and gives an agent eight tools: Search Orders, Get Order (line items, fulfillment and payment status), Lookup Customer, Customer Orders, Search Products, Get Discounts, Cancel Order and Create Refund. Create Refund refunds everything still refundable on the order, items and shipping, so it can't refund a partial amount; Cancel Order by default refunds to the original payment method and restocks the items. Both are Write tools that ask for confirmation in chat. Macha's Stripe connector adds customers, payments, refunds and charges. That pair covers order status from Shopify's fulfillment data and refunds, including full refunds on Shop Pay Installments and other BNPL orders taken through Shopify.
Every other app on this page connects through a custom API tool that Macha's team sets up during onboarding. A custom tool is one HTTP call: a method, a URL, an auth type (API key, Bearer or Basic) and any fixed headers, so Klaviyo's revision or Omnisend's version header travels with every request. Each tool is marked Read or Write. When we tested in dashboard chat on 28 September, the built-in Zendesk write tools paused for a confirmation card, but a custom Write tool ran with no card, even though the tool editor labels it "Write (requires confirmation)". So the guard for a custom write goes in the agent's instructions: when to call it, and when to hand the ticket to a person. On a triggered run, Write tools execute directly when the instructions say to. Custom tools are included on every plan, which starts at $299/month for 750 tickets, and a ticket costs the same however many tool calls it takes. We ran two of these tools against the vendors' live APIs with placeholder keys (the test is below), but not against a live merchant account; the custom API tools guide shows how one is defined.
Macha fits teams running a Shopify store on Zendesk, Freshdesk, Gorgias, Front, HubSpot or Intercom with three or more of the apps above that want one agent that reads Shopify first and then the right app, and would rather Macha's team build and test the API calls than own them. It's the wrong fit if your stack is Recharge plus Gorgias and nothing else, because Gorgias's own Actions may already cover it. For the "which AI option" question on Shopify in general, see AI customer service for Shopify.
Here's an agent instruction for a peak-week order-status ticket, written for acting:
When a customer asks where their order is, get the order from Shopify by order number, or by the requester's email if they didn't give one. If it's unfulfilled and under 2 business days old, give the dispatch window from the shipping policy. If it's fulfilled, call the tracking tool with the order number and reply with the latest scan, location and estimated delivery. If tracking shows delivered more than 48 hours ago and the customer says it isn't there, check whether the order carries package protection; if it does, send the claim link and tag the ticket protection-claim; if it doesn't, hand the ticket to a person with an internal note. Never promise a delivery date the carrier hasn't given.
What happened when we ran a Shopify AI agent on a test ticket?
We built one triage agent in Macha's own test account to see the built-in versus custom-tool split on a real call path. It ran in safe mode: it could write an internal note and add a tag, but not reply to the customer. Its tools were Shopify's built-in Get Order, the Zendesk read, note and tag tools, and two custom API tools: "Loop Returns: Get return details", which calls GET https://api.loopreturns.com/api/v1/warehouse/return/details?order_name= with an X-Authorization key, and "Smile.io: Find customer by email". Both custom tools held placeholder keys, because we don't have a Loop Returns store or a Smile.io Plus account.
On 28 September 2026 we created ticket #1117 on our sandbox Zendesk from a made-up customer, Priya Nair, with three asks in one message: has order #1097 shipped, how do I start a return if it's late, and did I earn loyalty points. The store behind it is Macha's own Shopify development store. The ticket was created with Macha's agent test feature, which is why the customer's message carries an "Internal" badge and the ticket says "Via API".
The note landed 11 seconds after the ticket was created. Here's what each system returned:
| Ask | Tool | Route | Result |
|---|---|---|---|
| Has #1097 shipped? | Shopify Get Order | Built-in connector | Answered: paid, unfulfilled, no tracking, so not shipped |
| How do I start a return? | Loop Returns: Get return details | Custom API tool | Loop's live API returned HTTP 401 twice; the note says it couldn't confirm and a teammate should check |
| Did I earn points? | Smile.io: Find customer by email | Custom API tool | Smile's live API returned HTTP 401 twice; same handoff |
The built-in connector needed no setup beyond the store's OAuth approval, and it answered the part of the ticket that most Black Friday tickets are about. The two custom tools did reach the vendors' real endpoints, and the vendors refused them at authentication, which is what should happen with a placeholder key. With a real key, the same tool definition should return data, though we haven't confirmed that on a paying account. The agent also reported the failures plainly. It named each 401, said what it couldn't confirm, tagged the ticket ai_triaged, and left the rest to a person.
The agent also noticed that the email on the Shopify order didn't match the Zendesk requester and wrote that a teammate "should verify ownership before sharing order-specific details externally." Its instructions never mentioned ownership checks. In peak week, shoppers often write from a different address than the one they checked out with, and some of those are not the buyer. Put the check in the instructions so it runs on every ticket instead of when the model happens to notice.
The same day we pointed placeholder-key tools at seven vendor APIs, six through the Test button on Macha's custom-tool screen and Loop Subscriptions from a test ticket. Each call reached the vendor and came back 401, and the bodies differ enough that an agent's error note should quote them verbatim:
| Vendor API | Auth header | What it said to a wrong key |
|---|---|---|
| AfterShip Tracking | as-api-key | "The API key is invalid." |
| 17TRACK | 17token | "Access token is invalid." (error code -18010002) |
| Judge.me | X-Api-Token | "Failed to authenticate. Shop domain or Api Token is wrong" |
| ShipStation v2 | API-Key | "Access denied.", with error_source shipengine |
| Recharge | X-Recharge-Access-Token | "bad authentication" |
| Loop Returns | X-Authorization | "Unauthorized." (GEN-UNAUTHORIZED) |
| Loop Subscriptions | X-Loop-Token | "Invalid token" |
Two of them matter when you debug. Judge.me's message doesn't say whether the key or the shop_domain is wrong, so check both. ShipStation's v2 errors name ShipEngine as the source, because ShipEngine serves that API. None of these runs made a successful vendor call, since none had a real key.
In the tool above, the order_number parameter is set to Body, but on a GET Macha still substitutes the value into the URL's order-number placeholder: ShipStation's 401 response echoes the path it received, /v2/shipments?sales_order_id=1097.
The test didn't cover a fulfilled order with tracking, any write action, or a working vendor key, so it shows the call path and the failure handling only.
Frequently asked questions
Which Shopify apps can an AI support agent work with? Of 34 apps checked on 28 September 2026, 19 let an agent change records with a static API key, including Recharge, Loop Subscriptions, Judge.me, Klaviyo, Attentive, ShipStation and ShipBob. Six are read-only for an agent, such as 17TRACK, CWILL and Route.
Can an AI agent answer "where is my order" without a tracking app? Usually, yes. Shopify's own order record carries the fulfillment status, carrier and tracking number, which answers the basic question. A tracking app adds scan events and delivery estimates; CWILL and Track123 can look them up by order number, 17TRACK only by tracking number.
Which Shopify apps can't an AI agent reach? Kaching Subscriptions and Blockify publish no API, BON Loyalty offers one only on an enterprise plan, Yotpo's reviews API uses an expiring token, and Shopify Subscriptions and Shopify Messaging need an Admin API app: new custom apps can't be created in the Shopify admin since 1 January 2026, and Dev Dashboard app tokens expire after 24 hours.
Does an AI agent need a paid plan in these apps? Often. Loop Subscriptions needs PRO, Smile.io needs Plus at $999 a month billed annually, AfterShip Tracking needs Premium at $59 on aftership.com ($70 through the App Store listing), AfterShip Returns Premium at $99, ShipStation Standard at $29.99, and Postscript custom use needs an enterprise plan.
Can an AI agent file a Route package protection claim? Not through the API. Route's merchant API has no claim endpoint. An agent can read the shipment, check coverage and send Route's claim link; filing on the customer's behalf happens in Route's own Zendesk or Gorgias app, or by a person.
Does Macha have built-in connectors for these Shopify apps? Shopify and Stripe are built-in. Every other app here connects through a custom API tool that Macha's team sets up during onboarding, using the app's own key.
How we researched this
On 28 September 2026 we read each app's Shopify App Store listing for its rating and review count, taking the figure from the listing's structured data, and each vendor's API reference, authentication page and pricing page for the endpoints, headers and plan gates in the table; every source is linked where it's used. We picked the most-reviewed apps in each category and added a few whose review counts understate their size (Loop Subscriptions, Skio, Attentive, LoyaltyLion, Signifyd). "Change records" means the reference documents at least one support write that works with a static credential; "read-only" means reads only; "not feasible" means no public API, an expiring token, or a platform restriction; "unverified" means we couldn't load the docs (Loox returned an error, Privy's docs require a login, Return Prime's didn't resolve). Plan prices are the vendor's or App Store listing's monthly price that day. We didn't run any call against a live merchant account, so every action in the table is documented, not tested. The one live run, ticket #1117, used Macha's test account, a sandbox Zendesk, Macha's own Shopify development store and a made-up customer, with placeholder keys for Loop Returns and Smile.io. Gorgias and Zendesk capabilities come from their own help centers. Arithmetic: 19 + 6 + 6 + 3 = 34 apps; 3 requests a second is 180 a minute. The agent instruction is synthetic, and no customer data was used.
To try a Shopify AI agent on your own help desk, start a trial with $50 of free usage (about 125 tickets), no credit card, no time limit, or compare tiers on the pricing page.
Resolve tickets automatically with AI agents
Macha's AI agents work on top of the help desk you already use — no code.
Intercom
Shopify
Stripe
Slack
Notion
Google Workspace
Confluence

