Macha

Shopify AI Agent Integrations: 34 Apps by What Their APIs Allow

Abbas, Customer Support & AI, Macha

Written by

Ankeet Guha, Co-founder & CTO, Macha

Reviewed by

Published September 28, 2026

We checked 34 Shopify apps across eight support categories on 28 September 2026. For 19 of them, a Shopify AI agent working support tickets can change a record, such as skipping a subscription charge, replying to a review or voiding a shipping label, through a documented API with a static key.

Key takeaways

  • Of 34 Shopify apps checked across eight categories on 28 September 2026, 19 document at least one support write that an AI agent can call with a static API key.
  • Six of those 19 apps sell API access only on a paid plan, from ShipStation's Standard plan at $29.99 a month to Smile.io's Plus plan at $999 a month, billed annually.
  • Recharge has no pause endpoint, Route has no claim endpoint and Yotpo's reviews API uses an access token that expires, so those three jobs stay with a person or the vendor's own app.
  • Order-tracking apps split on the lookup key: CWILL, formerly ParcelPanel, accepts an order number, while 17TRACK accepts only a tracking number registered first.
  • Macha reads Shopify orders and issues refunds through its built-in Shopify connector and connects every other app here through a custom API tool that Macha's team sets up during onboarding. On a test ticket, the Shopify connector answered while placeholder-key tools for Loop Returns and Smile.io got HTTP 401 from the vendors' live APIs.
Shopify AI Agent Integrations: 34 Apps by What Their APIs Allow

Six more are read-only for an agent, six can't be reached at all, and three we couldn't verify because the developer docs were behind a login or offline. Six of the 19 put their API behind a paid plan. Below is the full map, the Black Friday tickets each app answers, the jobs that still need a person, one live test ticket, and what to check before 27 November.

What does "Shopify AI agent" mean on this page?

Shopify uses the phrase for three different things. Sidekick is the assistant inside the Shopify admin that works for the merchant. Agentic commerce is Shopify's name for AI shopping agents that act for buyers, finding products and checking out through its Universal Commerce Protocol. This page covers the third kind: an agent that works customer support tickets in your help desk and reads or changes records in Shopify and the apps around it. For choosing the vendor behind that agent, see AI customer service for Shopify.

MeaningWhat does the jobOne concrete fact
SidekickShopify's own assistant, working for the merchant in the adminMerchants can chat with it from any page of the Shopify admin, by text, voice or screen sharing
Agentic commerceAI shopping agents acting for buyersShopify's MCP tools implement the Universal Commerce Protocol at every step of the buyer journey, from discovery to order tracking
Support agent (this page)An agent layer on your help desk that works ticketsIt reads Shopify orders and calls app APIs; 19 of the 34 apps below accept its writes with a static key

Which Shopify apps can an AI support agent work with?

"Static key" means the merchant creates a token once in the app's settings and the agent sends it in a header on every call. No shopper login, no token that expires overnight. That's the condition for an agent that works tickets on its own at 2 a.m. on Black Friday. Every "can do" cell lists only what the vendor's API reference documents, and the app name links to that reference. Ratings and review counts are from each app's Shopify App Store listing on 28 September 2026.

CategoryApp (rating, reviews)What an AI agent can do, per the API docsAuth and plan gateRoute
SubscriptionsAppstle Subscriptions (5.0, 8,822)Skip an order, pause or cancel via status, change next billing date and addressX-API-Key; paid API plan unless used through an approved partnerCustom API tool
SubscriptionsRecharge (4.8, 3,121)Skip a charge, cancel, set next charge date, change address; no pauseX-Recharge-Access-TokenCustom API tool
SubscriptionsSeal Subscriptions (4.9, 3,113)Pause, cancel, resume; skip or reschedule a billing attemptX-Seal-TokenCustom API tool
SubscriptionsKaching Subscriptions (5.0, 1,067)No public API foundnoneNot feasible
SubscriptionsShopify Subscriptions (3.7, 825)Needs an Admin API app. New custom apps can't be created in the Shopify admin since 1 January 2026; a Dev Dashboard app's tokens expire after 24 hoursExpiring app tokenNot feasible with a static key
SubscriptionsLoop Subscriptions (5.0, 767)Find subscriptions by email, skip next order, pause, cancelX-Loop-Token; PRO planCustom API tool
SubscriptionsSkio (5.0, 241)Skip, pause, unpause, cancel, change next billing date (GraphQL)authorization: API <token>Custom API tool
Tracking17TRACK (4.9, 4,399)Register a tracking number, then read status and events17token; 200 free numbers onceCustom API tool, read-only
TrackingCWILL, formerly ParcelPanel (5.0, 3,159)Read tracking by order number or order IDx-parcelpanel-api-key; Professional, $59/moCustom API tool, read-only
TrackingTrack123 (4.9, 1,727)Read tracking by tracking number or by an orderNos list of order numbersTrack123-Api-SecretCustom API tool, read-only
TrackingAfterShip Tracking (4.6, 1,505)Read trackings, retrack an expired oneas-api-key; Premium, $59/mo on aftership.com, $70/mo through the App Store listingCustom API tool, read-only
ReturnsAfterShip Returns (4.7, 1,542)Read returns; approve, resolve or reject a returnas-api-key; Premium, $99/moCustom API tool
ReturnsRedo (4.9, 783)Read return status, create a returnBearer API secretCustom API tool
ReturnsReturn Prime (4.8, 768)Developer docs didn't load on 28 SeptunverifiedUnverified
ReturnsLoop Returns (4.6, 443)Get return details by order name, cancel a return; labels need OAuthX-Authorization scoped keyCustom API tool
ReviewsJudge.me (5.0, 47,588)Find reviews, post a public reply (POST /replies), send a private reply, update a reviewX-Api-Token plus shop_domainCustom API tool
ReviewsLoox (4.9, 9,689)Developer docs returned an error on 28 SeptAPI on the Convert plan, $49.99/moUnverified
ReviewsYotpo Reviews (4.8, 4,628)Access token is generated from a secret and expires; regenerate on 401X-Yotpo-TokenNot feasible with a static key
LoyaltySmile.io (4.9, 4,608)Read points, tier and referral link; add points; redeem a points productBearer key; Plus plan, $999/mo billed annuallyCustom API tool
LoyaltyBON Loyalty (5.0, 1,937)API offered only on an enterprise plan, no public docsnone publicNot feasible today
LoyaltyYotpo Loyalty (4.7, 968)Fetch a customer's balance and referral link, adjust pointsGUID and API key, two headersCustom API tool
LoyaltyLoyaltyLion (4.6, 538)Add or remove points, redeem or refund a rewardAuthorization: Bearer pat_...Custom API tool
LoyaltyStamped (4.7, 3,751)Adjust points and VIP tier, redeem a reward, void a coupon; its reviews API is "coming soon", so it's counted herestamped-api-keyCustom API tool
Email and SMSShopify Messaging (4.8, 4,560)Consent lives on the Shopify customer recordShopify app tokenNot feasible
Email and SMSPrivy (4.5, 4,212)Developer docs sit behind a Privy loginunverifiedUnverified
Email and SMSKlaviyo (4.7, 3,328)Read consent, unsubscribe, suppressKlaviyo-API-Key plus revision, two headersCustom API tool
Email and SMSOmnisend (4.7, 3,184)Find and update a contactOmnisend-API-Key plus Omnisend-Version, two headersCustom API tool
Email and SMSPostscript (4.7, 1,207)Unsubscribe, redact, update a subscriberShop key; custom use on enterprise plans onlyCustom API tool
Email and SMSAttentive (4.7, 111)Check eligibility, unsubscribe, file a privacy deletionBearer private-app keyCustom API tool
Shipping and protectionShipStation (4.2, 707)Void a label (PUT /v2/labels/:label_id/void), hold an orderAPI-Key; Standard plan, $29.99/moCustom API tool
Shipping and protectionRoute (4.0, 377)Read a shipment; no claim endpointtoken headerCustom API tool, read-only
Shipping and protectionShipBob (4.3, 286)Update a shipment address, cancel an order, place a shipment on holdPersonal access tokenCustom API tool
FraudBlockify Fraud Filter (4.9, 1,732)No public API foundnoneNot feasible
FraudSignifyd (4.4, 90)Read the fraud decision on an orderAPI keyCustom API tool, read-only
BaselineShopifySearch and get orders, look up a customer and their orders, search products, read discounts; cancel an order; refund everything still refundable (no partial amount)OAuthBuilt-in connector
BaselineStripeGet customers, list payments, create a refund or chargeAPI keyBuilt-in connector

The tally by category, which is where the sentence at the top comes from:

CategoryApps checkedAgent can change recordsRead-onlyNot feasibleUnverified
Subscriptions75020
Order tracking40400
Returns43001
Reviews31011
Loyalty54010
Email and SMS64011
Shipping and protection32100
Fraud20110
Total3419663

Shopify and Stripe are not counted in the 34; they are the baseline every other app is compared against.

Which Black Friday tickets does each app answer?

Black Friday 2026 is 27 November and Cyber Monday is 30 November. The holiday peak planning guide does the volume arithmetic from tickets per order, using the tickets-per-order benchmarks by vertical; this table does the routing. For each ticket type that climbs in the peak window, it names the first system an agent should read and the app that finishes the job.

What the shopper writesFirst readApp category that finishes itCan an agent finish it end to end?
"Where is my order?"Shopify order: fulfillment status, carrier, tracking numberTracking app for scan events and delivery estimatesYes, it's a read in every tracking app above
"Cancel my next box" / "skip December"Shopify customer by emailSubscription appYes in 5 of 7 subscription apps; Recharge's API can skip but not pause
"My package says delivered but it isn't here"Tracking appPackage protection (Route)No. The agent can check coverage and send the claim link; filing stays with Route's own app or a person
"I want to return this"Shopify orderReturns appPartly. Status and cancel, yes; label creation in Loop Returns needs OAuth
"Where are my points?"Loyalty app by emailLoyalty appYes where the plan includes the API; goodwill points should follow a written limit
"My discount code didn't work"Shopify order total and line itemsNone of the apps aboveRarely. Code rules live in Shopify's discount settings, so this usually needs a person
"Stop texting me"Email/SMS app by phone or emailEmail/SMS appYes in Klaviyo, Omnisend, Attentive; Postscript only on enterprise plans
"Refund to my Klarna / Shop Pay Installments"Shopify order and payment methodShopifyYes for a full refund: it's issued in Shopify, and the provider adjusts the installments

Shop Pay Installments is provided by Affirm, but the refund still starts in Shopify. According to Shopify's installments FAQ, a partial refund leaves the customer "a smaller payment balance on the final payment" or fewer future payments, paid interest isn't refunded, and the merchant doesn't get the transaction fee back. Macha's built-in Create Refund refunds the whole remaining balance, so a partial refund on an installments order is one for a person in the Shopify admin. An agent can still explain the rules accurately, which answers most "why is my next installment still due" follow-ups before they're written. The BNPL refunds page covers Klarna and Afterpay the same way.

Which of these apps already have AI actions inside Gorgias or Zendesk?

For the most common subscription jobs, the help desk's own AI got there first. Gorgias AI Agent ships ready-made Actions for Recharge, Skio and Loop Subscriptions, and Shopify order changes such as canceling an order or editing its address. AfterShip announced an integration that feeds tracking and returns data to Gorgias's AI. On Zendesk, AI agents can call Shopify actions in action flows, and Route's Zendesk app lets a human agent file a claim, which Route's public API doesn't.

Help desks have an incentive to build AI actions for the apps with the most shared merchants, because each action sells their AI tier to thousands of stores at once. That's why Recharge and Loop get ready-made Actions while Seal and Appstle, each with more App Store reviews than Loop, have none that we could find in Gorgias's help center. If your stack is the top three apps on one help desk's partner list, its native AI may already cover you. If you run the fourth app, or you're on a desk whose marketplace is thin on ecommerce, the gap is a custom call. The help desk AI actions matrix compares what each desk's own AI can do in Shopify, and the Gorgias integrations roundup lists the apps Gorgias connects natively.

Which Shopify apps can't an AI agent reach, and why?

Six apps in our set are out of reach today, and three reachable ones have a single job an agent can't do. The reasons fall into five groups.

  1. No public API. Kaching Subscriptions and Blockify publish none that we could find. BON Loyalty's listing says to contact it for an enterprise plan that includes an API; there's no public reference to build against.
  2. A token that expires. Yotpo's reviews API generates an access token from the store's secret, and its docs say to generate a new one when a call returns 401. A tool with a fixed header can't do that refresh. Yotpo Loyalty is a separate API with a static GUID and key, which is why it's in the reachable column.
  3. OAuth only for one job. Loop Returns' keys cover return details and cancellation, but its authentication page says OAuth is required for the Label API.
  4. No endpoint for the job. Recharge's 2021-11 reference has no pause endpoint: pausing is a customer-portal feature that the API only reports through a subscription/paused webhook, so an agent can at most skip a charge or move the next charge date, and Route's merchant API has no claim endpoint. The Recharge page and the Route page set out what an agent can do instead.
  5. The platform moved the door. Shopify Subscriptions and Shopify Messaging keep their data inside Shopify's Admin API. Since 1 January 2026, new custom apps can't be created in the Shopify admin; Shopify's changelog points merchants to the Dev Dashboard instead, and a Dev Dashboard app that authenticates itself gets tokens that, per Shopify's docs, "expire after 24 hours." That's the same problem as Yotpo's token. Custom apps created before 2026 keep working. Macha's Shopify connector reads orders, customers, products and discounts, and can cancel or refund an order, but it has no subscription-contract or marketing-consent tool.
Yotpo's Generate Access Token reference noting that an expired token returns 401 and must be regenerated
Yotpo's Generate Access Token reference noting that an expired token returns 401 and must be regenerated

Plan gates aren't a wall, but they're the most common surprise, and the incentive behind them is an upsell: API access is cheap to serve and valuable to a merchant automating support, so vendors park it one tier up. Loop Subscriptions issues tokens only on its PRO plan. Postscript's page on API access says that since April 2022 "custom API access for individual shops is limited to those on enterprise plans"; shops that had custom access before then kept it as "grandfathered access." Appstle's authentication page says merchants need a paid API plan unless they use an approved partner integration, whose scoped tokens "bypass the paid API plan requirement." Smile.io's docs say merchant API keys are "only available on the Plus or Enterprise plan", and Plus is $999 a month billed annually. AfterShip puts the Tracking API on Premium at $59 a month on its own site ($70 through the App Store listing) and the Returns API on Premium at $99. ShipStation's App Store listing puts "Shipping API" on Standard at $29.99, and Loox lists "API access" on Convert at $49.99.

What can an AI agent do in each app category?

Each category has its own hub with the full matrix. These are the short versions, with the one fact that decides each.

Subscriptions

Pause is where the subscription apps differ. Five of the seven apps here document skip and cancel with a static key, and every one of those five except Recharge also documents pause. Recharge customers can pause in its portal, but the API has no pause call. The subscription apps hub compares them job by job.

Recharge 2021-11 API reference, Subscriptions endpoints: set next charge date, change address, cancel, activate; no pause
Recharge 2021-11 API reference, Subscriptions endpoints: set next charge date, change address, cancel, activate; no pause

Order tracking

All four tracking apps are read-only for support purposes, which suits the job, since "where is my order" is a read. What differs is the key the shopper has. Customers quote order numbers. CWILL's GET /api/v2/tracking/order takes one directly, and Track123's POST /tk/v2.1/track/query accepts an orderNos list, which only matches trackings that carry the order reference; 17TRACK needs a tracking number registered first and allows 3 requests a second. Shopify's own order already carries the carrier and tracking number, so an agent can answer the basic question before calling any tracking app. The order-tracking hub covers them in detail.

CWILL Tracking API v2 docs: GET /api/v2/tracking/order takes order_number or order_id, with the x-parcelpanel-api-key header
CWILL Tracking API v2 docs: GET /api/v2/tracking/order takes order_number or order_id, with the x-parcelpanel-api-key header

Returns

Three of four returns apps accept writes with a key. AfterShip Returns can approve, resolve or reject a return; Redo can create one; Loop Returns can cancel one. Nobody here lets a static key generate a label. See the returns apps hub.

Loop Returns API docs: API keys go in X-Authorization; OAuth 2.0 is required only for the Label API and Webhooks API
Loop Returns API docs: API keys go in X-Authorization; OAuth 2.0 is required only for the Label API and Webhooks API

Reviews

Judge.me, the most-reviewed app in our whole set at 47,588 reviews, has the most useful support API in the category: POST /replies posts a public reply on the review widget and POST /private_replies emails the reviewer privately, both with a private key in X-Api-Token. Stamped's newer review API is still "coming soon", per its own docs, so this page counts Stamped under loyalty, where its documented writes are. The review apps hub compares the rest.

Judge.me API reference for POST /replies, which posts a public reply to a review with a private key and shop domain
Judge.me API reference for POST /replies, which posts a public reply to a review with a private key and shop domain

Loyalty

"Where are my points?" is a read in every reachable loyalty app, and a goodwill top-up is a write in four: Smile.io, Yotpo Loyalty, Stamped and LoyaltyLion, whose API keys start with pat_ and carry scopes you choose when you create them. The Smile.io page covers points lookups and missing points in detail. Stamped also documents Adjust VIP Tier; Smile.io's reference lists VIP tiers but has no endpoint to change a customer's tier. The loyalty apps hub goes deeper.

Smile.io developer docs, Use merchant credentials: merchant credentials are only available on the Plus or Enterprise plan
Smile.io developer docs, Use merchant credentials: merchant credentials are only available on the Plus or Enterprise plan

Email and SMS

Unsubscribe requests are a compliance job as well as a support one, and the Klaviyo page walks through unsubscribes, suppressions and consent checks for that one app. Klaviyo and Omnisend both need two headers on every call: Klaviyo a revision date, Omnisend Omnisend-Version: 2026-03-15. Postscript's Unsubscribe and Redact endpoints exist for every shop, but only enterprise shops may call them from a custom build. The email and SMS hub maps the rest.

Postscript's developer FAQ stating that since April 2022 custom API access is limited to shops on enterprise plans
Postscript's developer FAQ stating that since April 2022 custom API access is limited to shops on enterprise plans

Shipping and package protection

ShipBob documents Update Shipment Address and Bulk Place Shipments On Hold; ShipStation documents voiding a label, and its docs note a voided label "cannot be un-voided." Route is read-only for claims. The shipping and protection hub covers the before-it-ships window in detail.

ShipStation's Void Labels guide showing PUT /v2/labels/:label_id/void and the warning that voided labels cannot be un-voided
ShipStation's Void Labels guide showing PUT /v2/labels/:label_id/void and the warning that voided labels cannot be un-voided

Fraud

An agent's job with a fraud app is to read the decision and tell the customer what happens next, or hand off. Signifyd's API documents Get Decision; Blockify has no API. A fraud hold isn't a decision an agent should reverse.

Signifyd API reference for Get Decision: GET /v3/orders/{orderId}/decision returns the latest fraud decision
Signifyd API reference for Get Decision: GET /v3/orders/{orderId}/decision returns the latest fraud decision

What should you check before Black Friday on 27 November?

Most of what breaks an app connection in peak week is visible a month earlier. Run this list per app, in this order.

  1. Confirm the plan includes the API. Loop Subscriptions, Smile.io, AfterShip, ShipStation and Postscript all tie API keys or custom use to a plan, so check the plan before anyone builds a tool.
  2. Create a key with only the scopes the job needs. LoyaltyLion and Loop Returns both scope keys at creation. A read-only tool should hold a read-only key.
  3. Pin the API version. AfterShip's Tracking and Returns APIs are versioned 2026-07 in the URL; Recharge sends 2021-11; Loop Subscriptions uses 2026-04; Klaviyo and Omnisend take a version header. An unpinned call changes behavior when the vendor ships.
  4. Check rate limits against peak volume. 17TRACK allows 3 requests a second, CWILL 120 a minute per key, AfterShip's GET /trackings 6 a second, Loop Subscriptions 50 a second per store. At 3 a second, 17TRACK handles 180 lookups a minute, more than most support queues need, but a bulk backfill during peak week can hit it.
  5. Check for rebrands and moved hosts. CWILL changed its API base URL from open.parcelpanel.com to open.parcelwill.com on 11 February 2026. A tool built from an old tutorial calls the dead host.
  6. Test on a real order. Pick one real order and one real subscriber, run each read, and confirm the answer the agent writes matches what the app's admin shows. Run writes on a test customer.
  7. Write the handoff line. For every job in the "can't reach" list, the agent's instructions should say who takes it and what the agent tells the customer meanwhile.

How does Macha connect these apps?

Two of the rows in the table are built-in. Macha's Shopify connector (walked through in the Macha Shopify integration guide) authorizes once with OAuth and gives an agent eight tools: Search Orders, Get Order (line items, fulfillment and payment status), Lookup Customer, Customer Orders, Search Products, Get Discounts, Cancel Order and Create Refund. Create Refund refunds everything still refundable on the order, items and shipping, so it can't refund a partial amount; Cancel Order by default refunds to the original payment method and restocks the items. Both are Write tools that ask for confirmation in chat. Macha's Stripe connector adds customers, payments, refunds and charges. That pair covers order status from Shopify's fulfillment data and refunds, including full refunds on Shop Pay Installments and other BNPL orders taken through Shopify.

Every other app on this page connects through a custom API tool that Macha's team sets up during onboarding. A custom tool is one HTTP call: a method, a URL, an auth type (API key, Bearer or Basic) and any fixed headers, so Klaviyo's revision or Omnisend's version header travels with every request. Each tool is marked Read or Write. When we tested in dashboard chat on 28 September, the built-in Zendesk write tools paused for a confirmation card, but a custom Write tool ran with no card, even though the tool editor labels it "Write (requires confirmation)". So the guard for a custom write goes in the agent's instructions: when to call it, and when to hand the ticket to a person. On a triggered run, Write tools execute directly when the instructions say to. Custom tools are included on every plan, which starts at $299/month for 750 tickets, and a ticket costs the same however many tool calls it takes. We ran two of these tools against the vendors' live APIs with placeholder keys (the test is below), but not against a live merchant account; the custom API tools guide shows how one is defined.

Macha fits teams running a Shopify store on Zendesk, Freshdesk, Gorgias, Front, HubSpot or Intercom with three or more of the apps above that want one agent that reads Shopify first and then the right app, and would rather Macha's team build and test the API calls than own them. It's the wrong fit if your stack is Recharge plus Gorgias and nothing else, because Gorgias's own Actions may already cover it. For the "which AI option" question on Shopify in general, see AI customer service for Shopify.

Here's an agent instruction for a peak-week order-status ticket, written for acting:

When a customer asks where their order is, get the order from Shopify by order number, or by the requester's email if they didn't give one. If it's unfulfilled and under 2 business days old, give the dispatch window from the shipping policy. If it's fulfilled, call the tracking tool with the order number and reply with the latest scan, location and estimated delivery. If tracking shows delivered more than 48 hours ago and the customer says it isn't there, check whether the order carries package protection; if it does, send the claim link and tag the ticket protection-claim; if it doesn't, hand the ticket to a person with an internal note. Never promise a delivery date the carrier hasn't given.

What happened when we ran a Shopify AI agent on a test ticket?

We built one triage agent in Macha's own test account to see the built-in versus custom-tool split on a real call path. It ran in safe mode: it could write an internal note and add a tag, but not reply to the customer. Its tools were Shopify's built-in Get Order, the Zendesk read, note and tag tools, and two custom API tools: "Loop Returns: Get return details", which calls GET https://api.loopreturns.com/api/v1/warehouse/return/details?order_name= with an X-Authorization key, and "Smile.io: Find customer by email". Both custom tools held placeholder keys, because we don't have a Loop Returns store or a Smile.io Plus account.

On 28 September 2026 we created ticket #1117 on our sandbox Zendesk from a made-up customer, Priya Nair, with three asks in one message: has order #1097 shipped, how do I start a return if it's late, and did I earn loyalty points. The store behind it is Macha's own Shopify development store. The ticket was created with Macha's agent test feature, which is why the customer's message carries an "Internal" badge and the ticket says "Via API".

Ticket #1117 internal note: Shopify order #1097 unfulfilled; Loop Returns and Smile.io lookups got HTTP 401
Ticket #1117 internal note: Shopify order #1097 unfulfilled; Loop Returns and Smile.io lookups got HTTP 401

The note landed 11 seconds after the ticket was created. Here's what each system returned:

AskToolRouteResult
Has #1097 shipped?Shopify Get OrderBuilt-in connectorAnswered: paid, unfulfilled, no tracking, so not shipped
How do I start a return?Loop Returns: Get return detailsCustom API toolLoop's live API returned HTTP 401 twice; the note says it couldn't confirm and a teammate should check
Did I earn points?Smile.io: Find customer by emailCustom API toolSmile's live API returned HTTP 401 twice; same handoff

The built-in connector needed no setup beyond the store's OAuth approval, and it answered the part of the ticket that most Black Friday tickets are about. The two custom tools did reach the vendors' real endpoints, and the vendors refused them at authentication, which is what should happen with a placeholder key. With a real key, the same tool definition should return data, though we haven't confirmed that on a paying account. The agent also reported the failures plainly. It named each 401, said what it couldn't confirm, tagged the ticket ai_triaged, and left the rest to a person.

The agent also noticed that the email on the Shopify order didn't match the Zendesk requester and wrote that a teammate "should verify ownership before sharing order-specific details externally." Its instructions never mentioned ownership checks. In peak week, shoppers often write from a different address than the one they checked out with, and some of those are not the buyer. Put the check in the instructions so it runs on every ticket instead of when the model happens to notice.

The same day we pointed placeholder-key tools at seven vendor APIs, six through the Test button on Macha's custom-tool screen and Loop Subscriptions from a test ticket. Each call reached the vendor and came back 401, and the bodies differ enough that an agent's error note should quote them verbatim:

Vendor APIAuth headerWhat it said to a wrong key
AfterShip Trackingas-api-key"The API key is invalid."
17TRACK17token"Access token is invalid." (error code -18010002)
Judge.meX-Api-Token"Failed to authenticate. Shop domain or Api Token is wrong"
ShipStation v2API-Key"Access denied.", with error_source shipengine
RechargeX-Recharge-Access-Token"bad authentication"
Loop ReturnsX-Authorization"Unauthorized." (GEN-UNAUTHORIZED)
Loop SubscriptionsX-Loop-Token"Invalid token"

Two of them matter when you debug. Judge.me's message doesn't say whether the key or the shop_domain is wrong, so check both. ShipStation's v2 errors name ShipEngine as the source, because ShipEngine serves that API. None of these runs made a successful vendor call, since none had a real key.

Macha custom tool for ShipStation GET /v2/shipments with an API-Key header; a test call with 1097 returns 401 Access denied
Macha custom tool for ShipStation GET /v2/shipments with an API-Key header; a test call with 1097 returns 401 Access denied

In the tool above, the order_number parameter is set to Body, but on a GET Macha still substitutes the value into the URL's order-number placeholder: ShipStation's 401 response echoes the path it received, /v2/shipments?sales_order_id=1097.

The test didn't cover a fulfilled order with tracking, any write action, or a working vendor key, so it shows the call path and the failure handling only.

Frequently asked questions

Which Shopify apps can an AI support agent work with? Of 34 apps checked on 28 September 2026, 19 let an agent change records with a static API key, including Recharge, Loop Subscriptions, Judge.me, Klaviyo, Attentive, ShipStation and ShipBob. Six are read-only for an agent, such as 17TRACK, CWILL and Route.

Can an AI agent answer "where is my order" without a tracking app? Usually, yes. Shopify's own order record carries the fulfillment status, carrier and tracking number, which answers the basic question. A tracking app adds scan events and delivery estimates; CWILL and Track123 can look them up by order number, 17TRACK only by tracking number.

Which Shopify apps can't an AI agent reach? Kaching Subscriptions and Blockify publish no API, BON Loyalty offers one only on an enterprise plan, Yotpo's reviews API uses an expiring token, and Shopify Subscriptions and Shopify Messaging need an Admin API app: new custom apps can't be created in the Shopify admin since 1 January 2026, and Dev Dashboard app tokens expire after 24 hours.

Does an AI agent need a paid plan in these apps? Often. Loop Subscriptions needs PRO, Smile.io needs Plus at $999 a month billed annually, AfterShip Tracking needs Premium at $59 on aftership.com ($70 through the App Store listing), AfterShip Returns Premium at $99, ShipStation Standard at $29.99, and Postscript custom use needs an enterprise plan.

Can an AI agent file a Route package protection claim? Not through the API. Route's merchant API has no claim endpoint. An agent can read the shipment, check coverage and send Route's claim link; filing on the customer's behalf happens in Route's own Zendesk or Gorgias app, or by a person.

Does Macha have built-in connectors for these Shopify apps? Shopify and Stripe are built-in. Every other app here connects through a custom API tool that Macha's team sets up during onboarding, using the app's own key.

How we researched this

On 28 September 2026 we read each app's Shopify App Store listing for its rating and review count, taking the figure from the listing's structured data, and each vendor's API reference, authentication page and pricing page for the endpoints, headers and plan gates in the table; every source is linked where it's used. We picked the most-reviewed apps in each category and added a few whose review counts understate their size (Loop Subscriptions, Skio, Attentive, LoyaltyLion, Signifyd). "Change records" means the reference documents at least one support write that works with a static credential; "read-only" means reads only; "not feasible" means no public API, an expiring token, or a platform restriction; "unverified" means we couldn't load the docs (Loox returned an error, Privy's docs require a login, Return Prime's didn't resolve). Plan prices are the vendor's or App Store listing's monthly price that day. We didn't run any call against a live merchant account, so every action in the table is documented, not tested. The one live run, ticket #1117, used Macha's test account, a sandbox Zendesk, Macha's own Shopify development store and a made-up customer, with placeholder keys for Loop Returns and Smile.io. Gorgias and Zendesk capabilities come from their own help centers. Arithmetic: 19 + 6 + 6 + 3 = 34 apps; 3 requests a second is 180 a minute. The agent instruction is synthetic, and no customer data was used.

To try a Shopify AI agent on your own help desk, start a trial with $50 of free usage (about 125 tickets), no credit card, no time limit, or compare tiers on the pricing page.

Macha

About Macha

Macha is an AI agent platform that works on top of the help desk you already use — Zendesk, Freshdesk, Gorgias, or Front — and connects to the rest of your stack, even your own internal systems. Its AI agents resolve tickets and automate entire workflows end to end, all set up in plain English, no code. Learn more about Macha →

Zendesk
5.0 on Zendesk Marketplace

Loved by support teams worldwide

See what support teams are saying about Macha AI.

The application seems excellent to me! We are still testing, and we need support for some details and they were extremely efficient too!

Daniela Costa

Daniela Costa

Head of Support, Seabra

Macha has been a great addition to our support toolkit. It generates clear, well-organized responses that fit naturally into our workflow. One feature we particularly appreciate is its ability to automatically reply in the same language as the ticket.

Marius F

Marius F

Support Head, Zentana

We've been using Macha for a little while now and it's been really great addition so far! It's powerful, convenient, and makes getting work done a lot easier for our agents.

Alexander Wedén

Alexander Wedén

Head of Support

Support team is very helpful and responsive. Really enjoy how lightweight this is within Zendesk itself vs other more intrusive tools.

Cathleen Wright

Cathleen Wright

Zendesk Admin, Cortex IO

So far it's pretty good! Our queries are a little nuanced, so we can't always use it, but it's got enough utility for us. It can even incorporate our bilingual country with greetings in a second language.

Jae Oliver

Jae Oliver

Head of Support, Wise

Really enjoying using Macha, it has made a noticeable difference to our support team in a short amount of time. I really like the ticket summary feature, saves us a lot of time.

Harry Jackson

Harry Jackson

Head of Support, Crumb

Macha AI is a great addition to my workspace! It's powerful, convenient, and it really makes productivity so much easier for our agents!

Dave G

Dave G

Head of Support, Cyber Power Systems

Very impressed! AI integration for Zendesk has certainly come a long way and Macha seems to set the standard for now. This will for sure save lot of time in our support team.

Pauli Juel

Pauli Juel

Head of CS, Dokument24

Macha has been working great for us so far! The auto-responses are accurate and our resolution time has dropped significantly.

Lana T

Lana T

Zendesk Admin, Swotzy

Macha AI is a great addition. The knowledge base feature means our agents always have the right answers at their fingertips.

Mischa Wolf

Mischa Wolf

Head of Support, Topi

We're enjoying this integration so far. It's made our support team more efficient and our customers get faster responses.

Paula G

Paula G

Head of Customer Support, Xly Studio

The team enjoys using it. It saves considerable time on common questions and the integration options are excellent.

Kilian Leister

Kilian Leister

Support Head, Didriksons

Ready to supercharge your team with AI?

Get started in minutes. Connect your tools, configure your agents, and let AI handle the rest.

$50 in free credits · no time limit, no credit card