Shopify/shopify-api-ruby
64.5
Adequate · 20 September 2026
3.3k
lines of production code
Ruby
primary language
1
measurement over time
What this system is
This system is the official Shopify API Ruby gem, providing a client library for interacting with the Shopify Admin and Storefront APIs. It supports both REST and GraphQL interfaces, offering auto-generated resource models for multiple API versions alongside low-level HTTP clients for direct request handling. The library manages authentication flows, including OAuth and token exchange, and includes a structured system for registering and processing webhooks.
How it got here
2009–2021 — v16.3.0 release and type safety adoption
28 changes.
This period marks the release of shopify\_api gem v16.3.0, introducing a comprehensive new authentication system, dedicated HTTP clients for REST and GraphQL APIs, and structured webhook management. The project simultaneously enforced strict code quality and static type safety by integrating RuboCop and Sorbet, including autogenerated RBI definitions for dependencies. Extensive test coverage was added across all new modules, replacing legacy testing frameworks with Minitest and WebMock to ensure robustness.
2022–2024 — REST API version updates
14 changes.
This period focused on maintaining and expanding support for Shopify's REST API by auto-generating resource classes and corresponding tests for multiple API versions from 2022-04 through 2025-10. The work also included refactoring the underlying REST base class to improve type strictness and error handling structures.
2025–2026 — Quarterly API version updates
4 changes.
This period focused on integrating successive quarterly releases of the Shopify REST Admin API, specifically versions 2025-01, 2026-04, and 2026-07. The work involved auto-generating and adding corresponding Ruby resource classes to support new endpoints and entities. It also included updating test coverage for these versions and addressing specific breaking changes, such as the removal of the \permits\_sku\_sharing\ attribute in the 2026-04 release.
Features
Add 2022-07 REST API resources
The library now includes auto-generated Ruby resource classes for the Shopify REST API version 2022-07. This update adds support for interacting with resources such as AbandonedCheckout, AccessScope, AndroidPayKey, ApplePayCertificate, ApplicationCharge, ApplicationCredit, Article, Asset, AssignedFulfillmentOrder, Balance, Blog, CancellationRequest, CarrierService, and Checkout, enabling developers to use the latest API endpoints and data structures in their applications.
_lib/shopify\_api/rest/resources/2022\07 · high confidence
Add 2023-04 REST API resource definitions
This release adds the auto-generated Ruby resource classes for the Shopify Admin API version 2023-04. The new files in lib/shopify\_api/rest/resources/2023\_04 provide type-safe access to REST endpoints, including resources such as AbandonedCheckout, AccessScope, ApplePayCertificate, ApplicationCharge, Article, Asset, AssignedFulfillmentOrder, Balance, Blog, CancellationRequest, CarrierService, and Checkout. These classes enable developers to interact with the 2023-04 API version using the library's standard REST client patterns.
_lib/shopify\_api/rest/resources/2023\04 · high confidence
Add 2025-04 REST API resource models
The library now includes auto-generated Ruby resource classes for the Shopify 2025-04 REST API release. This update adds support for managing key commerce entities, including AbandonedCheckouts, Checkouts, Articles, Blogs, Assets, ApplicationCharges, ApplicationCredits, ApplePayCertificates, AccessScopes, AssignedFulfillmentOrders, CancellationRequests, CarrierServices, and Balances, enabling developers to interact with the latest API endpoints and data structures.
_lib/shopify\_api/rest/resources/2022\_04, lib/shopify\_api/rest/resources/2024\_07, lib/shopify\_api/rest/resources/2025\04 · high confidence
Add Ruby REST resource classes for Shopify API version 2026-07
New auto-generated Ruby classes for the 2026-07 REST API version have been added to the library, enabling developers to interact with Shopify endpoints using this specific release. This update introduces resource models for key entities including AbandonedCheckout, AccessScope, ApplePayCertificate, ApplicationCharge, ApplicationCredit, Article, Asset, AssignedFulfillmentOrder, Balance, Blog, CancellationRequest, CarrierService, and Checkout, each providing the necessary methods and attributes to perform standard CRUD operations and specific API actions for the 2026-07 release.
_lib/shopify\_api/rest/resources/2026\07 · high confidence
Add Shopify REST API resources for the 2024-04 version
This update introduces the complete set of auto-generated REST resource classes for the Shopify 2024-04 API version. The new files in \lib/shopify\_api/rest/resources/2024\_04\ provide Ruby models and API methods for managing core shop data, including AbandonedCheckouts, AccessScopes, ApplePayCertificates, ApplicationCharges, ApplicationCredits, Articles, Assets, AssignedFulfillmentOrders, Balances, Blogs, CancellationRequests, CarrierServices, and Checkouts. Users can now interact with these specific endpoints using the updated resource definitions.
(repo-wide) · high confidence
Added 2022-10 REST API resource classes
The library now includes auto-generated Ruby resource classes for the Shopify 2022-10 REST API release. This adds support for interacting with resources such as AbandonedCheckout, AccessScope, AndroidPayKey, ApplePayCertificate, ApplicationCharge, ApplicationCredit, Article, Asset, AssignedFulfillmentOrder, Balance, Blog, CancellationRequest, CarrierService, and Checkout, enabling developers to query, create, update, and delete these entities via the updated API version.
_lib/shopify\_api/rest/resources/2022\10 · high confidence
Added Shopify REST API resources for the 2024-10 version
The library now includes auto-generated Ruby resource classes for the Shopify 2024-10 REST API release. This update adds support for managing a wide range of shop data, including abandoned checkouts, application charges and credits, articles, assets, blogs, cancellation requests, carrier services, and checkouts, among others. These new classes enable developers to interact with the latest API endpoints and data structures introduced in this version.
_lib/shopify\_api/rest/resources/2024\10 · high confidence
Added Sorbet RBI shims for FakeFS, Hash, and OpenSSL
New RBI shim files have been added to the \sorbet/rbi/shims\ directory to provide type definitions for external libraries and Ruby standard library extensions. Specifically, a shim for the \FakeFS\ module, a shim for \Hash\#with\_indifferent\_access\, and a shim for \OpenSSL.secure\_compare\ are now included to support static type checking.
sorbet/rbi/shims · high confidence
Added Sorbet RBI type definitions for project dependencies
Autogenerated Sorbet RBI files have been added for several gems used in the project, including activesupport (7.0.1), addressable (2.8.0), ast (2.4.2), concurrent-ruby (1.1.9), crack (0.4.5), diff-lcs (1.5.0), fakefs (1.4.1), hash\_diff (1.0.0), hashdiff (1.0.1), httparty (0.20.0), i18n (1.8.11), jwt (2.3.0), mime-types (3.4.1), and minitest (5.15.0). These files provide static type signatures for the gems, enabling Sorbet to type-check code that interacts with these libraries.
sorbet/rbi/gems · high confidence
Added Tapioca CLI entry point
A new executable script for the Tapioca gem has been added to the bin directory, allowing users to run the Tapioca command-line interface directly from the project root.
bin · high confidence
Added auto-generated 2023-01 REST API resources
The library now includes the full set of auto-generated Ruby resource classes for the Shopify 2023-01 REST API release. This adds support for interacting with 2023-01 endpoints, including resources such as AbandonedCheckout, AccessScope, ApplePayCertificate, ApplicationCharge, Article, Asset, AssignedFulfillmentOrder, Balance, Blog, CancellationRequest, CarrierService, and Checkout, enabling developers to use the latest API features and data structures in their applications.
_lib/shopify\_api/rest/resources/2023\01 · high confidence
Adds Shopify REST API resources for the 2025-01 version
This update introduces the full set of auto-generated REST API resource classes for the Shopify 2025-01 release. Users can now interact with the latest API endpoints through new Ruby models, including AbandonedCheckout, AccessScope, ApplePayCertificate, ApplicationCharge, ApplicationCredit, Article, Asset, AssignedFulfillmentOrder, Balance, Blog, CancellationRequest, CarrierService, and Checkout. These classes provide the necessary methods and attributes to manage these resources programmatically against the 2025-01 API version.
_lib/shopify\_api/rest/resources/2025\01 · high confidence
Initial Sorbet configuration added
Sorbet has been added to the project with a configuration file that sets the root directory to the current location and explicitly excludes the test/rest folder from type checking.
sorbet · high confidence
Initial Tapioca configuration and runtime requirements
Added the initial Tapioca configuration file to set type overrides for the 'openssl' gem and created a require.rb file that explicitly loads the necessary runtime dependencies for Sorbet, including ActiveSupport, HTTParty, JWT, and Mocha.
sorbet/tapioca · high confidence
Introduction of the Admin REST API Client
A new \ShopifyAPI::Clients::Rest::Admin\ client class has been added to enable HTTP requests to the Shopify Admin REST API. This client supports standard HTTP methods (GET, POST, PUT, DELETE) and allows users to specify an API version, which defaults to the context setting but can be overridden per instance. It also includes a safety check that raises a \DisabledResourceError\ if the REST client is explicitly disabled via configuration, directing users to the GraphQL Admin API instead.
_lib/shopify\api/clients/rest · high confidence
New GraphQL Admin and Storefront clients with API versioning and debug support
This change introduces dedicated GraphQL client classes for the Admin and Storefront APIs. The new Admin client accepts a session and an optional API version, allowing users to override the default API version for GraphQL requests. The Storefront client supports both public and private access tokens, validates shop domains, and automatically applies the correct authentication header based on the token type. Both clients now support a debug option to include debug parameters in requests and allow overriding the response\_as\_struct behavior, providing more control over how GraphQL responses are processed.
_lib/shopify\api/clients/graphql · high confidence
New OAuth authentication data structures and query handling
The OAuth module now includes dedicated classes for handling authentication flows: \AccessTokenResponse\ models the data returned from the token endpoint, including support for \refresh\_token\ and \refresh\_token\_expires\_in\ fields alongside standard access details; \AuthQuery\ parses and validates incoming OAuth callback parameters (code, shop, state, etc.) for HMAC verification; and \SessionCookie\ manages the temporary session cookie used during the OAuth handshake. These components provide the foundational data structures for the new OAuth implementation.
_lib/shopify\api/auth/oauth · high confidence
New authentication primitives and token exchange capabilities
The authentication module introduces several new classes and methods to support modern Shopify API security models. The \Session\ class now tracks expiration times and refresh tokens, with methods to check if sessions or refresh tokens are expired, and supports temporary session activation via \Session.temp\. A new \TokenExchange\ module allows exchanging session tokens for online or offline access tokens, and includes a \migrate\_to\_expiring\_token\ helper to convert legacy non-expiring offline tokens. The \Oauth\ module now supports custom scope overrides and uses an HTTP client for token requests. New \JwtPayload\ parsing handles optional \sub\ and \sid\ claims and uses a configurable leeway for expiration checks. Additionally, \AssociatedUser\ and \AuthScopes\ classes provide structured handling of user identity and permission scopes.
_lib/shopify\api/auth · high confidence
New low-level HTTP client for direct API requests
The library introduces a new \ShopifyAPI::Clients::HttpClient\ along with \HttpRequest\ and \HttpResponse\ classes, providing a dedicated mechanism for making raw HTTP calls to the Shopify API. This client handles session management, constructs requests with appropriate headers (including user-agent and access tokens), and manages response parsing, including pagination links, API rate-limit headers, and retry logic for 429/500 errors. It also captures deprecation warnings from response headers and gracefully handles non-JSON responses (like HTML) by raising specific errors rather than failing silently or crashing on parse errors.
_lib/shopify\api/clients · high confidence
New utility modules for session handling, validation, and GraphQL proxying
This change introduces several new utility modules in the \lib/shopify\_api/utils\ directory to support core API operations. \SessionUtils\ provides methods to extract session IDs from Shopify ID tokens (supporting both 'id\_token' and 'Bearer id\_token' formats) and cookies, distinguishing between online and offline sessions. \HmacValidator\ implements HMAC signature verification using both current and legacy API secrets to ensure backward compatibility during secret rotation. \ShopValidator\ adds domain validation and sanitization logic, ensuring shop domains belong to trusted Shopify domains (e.g., shopify.com, myshopify.com) and handling Unified Admin URLs. \GraphqlProxy\ enables proxying GraphQL queries through the API, supporting both raw GraphQL and JSON-formatted requests. Additionally, \AttributesComparator\ introduces logic to compare REST resource attributes, handling atomic hash updates and diffing, while \HttpUtils\ normalizes HTTP headers and \VerifiableQuery\ defines an interface for verifiable requests.
_lib/shopify\api/utils · high confidence
Behavioural changes
Add support for Shopify REST Admin API version 2026-04
This release adds the new 2026-04 REST Admin API version to the library, providing auto-generated resource classes for the updated quarterly release. Users can now interact with Shopify's 2026-04 endpoints using the standard client interface. This update includes a breaking change for the FulfillmentService resource: the \permits\_sku\_sharing\ attribute has been removed, as all fulfillment services now implicitly permit SKU sharing.
_lib/shopify\_api/rest/resources/2026\04 · high confidence
Added RBI todo file for unresolved constants
A new \sorbet/rbi/todo.rbi\ file has been added to track unresolved constants, specifically defining empty modules for \Rack::Request::Env\ and \Rack::Request::Helpers\. This file is auto-generated and should be updated by running \bin/tapioca todo\ rather than edited manually, ensuring Sorbet can resolve these external dependencies without type errors.
sorbet/rbi · high confidence
Clearer error messages when REST resources are missing for the configured API version
When using the REST Admin API, the gem now provides specific, actionable error messages instead of generic "uninitialized constant" errors if the configured API version lacks bundled resource definitions. This occurs when the API version is not set, is set to "unstable", or is a stable version not yet bundled in the current gem release. The change helps users quickly identify whether they need to call \Context.setup\, switch to a stable API version, upgrade the gem, or use the GraphQL API instead.
lib · high confidence
Enforce code quality and type-safety standards with RuboCop and Sorbet
The project now enforces consistent code style and static type checking by introducing a \.rubocop.yml\ configuration that inherits from \rubocop-shopify\ and enables \rubocop-sorbet\ rules, alongside a \.ruby-version\ file pinning the runtime to Ruby 3.3.7. This ensures all new contributions adhere to the library's specific linting and Sorbet typing requirements.
(repo-wide) · high confidence
Introduce structured webhook registration and handling API
The library now provides a dedicated webhook management system via the \ShopifyAPI::Webhooks::Registry\, allowing developers to register webhook topics with support for HTTP, Pub/Sub, and Event Bridge delivery methods. This new API supports advanced filtering options, including \fields\, \metafield\namespaces\, and custom \filter\ strings, enabling more precise data control. The \WebhookHandler\ interface and \WebhookMetadata\ struct standardize how incoming webhook payloads are processed, while the \Request\ class ensures robust parsing of both legacy and new \shopify-\\ header formats. Registration results are returned via a typed \RegisterResult\ object, simplifying error handling and status checking for users.
_lib/shopify\api/webhooks · high confidence
Introduces specific error classes for API operations
The library now provides distinct error classes within the ShopifyAPI::Errors namespace to handle specific failure scenarios, replacing generic exceptions with more precise types. This includes HttpResponseError, which exposes HTTP status codes and response bodies, and specialized errors for authentication and session issues (such as InvalidJwtTokenError, NoActiveSessionError, and SessionNotFoundError), validation failures (InvalidShopError, InvalidOauthError), and webhook management (InvalidWebhookError, WebhookRegistrationError). Notably, RestResourceNotLoadedError inherits from NameError to maintain compatibility with existing rescue blocks, while MaxHttpRetriesExceededError extends HttpResponseError to provide context on failed requests.
_lib/shopify\api/errors · high confidence
New REST resource base class and error handling structure
The \lib/shopify\_api/rest\ area now introduces a new \ShopifyAPI::Rest::Base\ class that serves as the foundation for REST resources, featuring Sorbet type strictness, support for custom HTTP headers, and specific handling for read-only and atomic hash attributes. Alongside this, a new \ShopifyAPI::Rest::BaseErrors\ class has been added to aggregate HTTP response errors and provide access to error codes, replacing the previous error handling mechanism in this layer.
_lib/shopify\api/rest · high confidence
Release Shopify API gem version 16.3.0
This update releases version 16.3.0 of the Shopify API library. It introduces a new \AdminVersions\ module that defines the list of supported Admin API versions, including the new 2026-10, 2026-07, 2026-04, and 2026-01 releases, while removing the previous \LATEST\_SUPPORTED\_ADMIN\_VERSION\ and \RELEASE\_CANDIDATE\_ADMIN\_VERSION\ constants. The \Context\ class now enforces that the configured \api\_version\ exists in this supported list, raising an \UnsupportedVersionError\ if it does not. Additionally, the library adds an \Auth\ module with an \embedded\_app\_url\ helper to construct host app URLs and includes a dedicated \Logger\ class to manage logging levels and deprecation warnings.
_lib/shopify\api · high confidence
Support for metafield namespaces and filters in webhook registrations
The webhook registration logic in \lib/shopify\_api/webhooks/registrations\ has been extended to support \metafield\_namespaces\ and \filter\ parameters for HTTP, EventBridge, and Pub/Sub webhook types. This allows users to register webhooks that include specific fields and apply filters, with the registry now correctly checking and updating these attributes when they change.
_lib/shopify\api/webhooks/registrations · high confidence
Test coverage
Added REST API tests for the 2025-10 version; Added automated tests for 2023-04 REST resources; Added generated REST API tests for the 2024-10 version; Added test coverage for Admin Versions, Auth, Context, Logger, and REST resource loading; Added test coverage for authentication components; Added test coverage for the new HTTP client and REST resource layers; Added test coverage for utility modules; Added test helpers for REST resources, GraphQL client, and webhook handling; Added tests for 2022-04 REST API resources; Added tests for 2022-10 REST resources; Added tests for BaseErrors error handling; Added tests for GraphQL Admin and Storefront clients; Added tests for OAuth access token response and auth query validation; Added tests for the 2026-04 REST Admin API version; Added tests for the Admin REST client; Added tests for webhook registry and request handling.
Dependencies
Initial release of shopify\_api gem v16.3.0
This entry introduces the shopify\_api gem (version 16.3.0) for Ruby developers, enabling programmatic access to the Shopify Admin API. The package requires Ruby 3.2 or higher and relies on runtime dependencies including activesupport, addressable, concurrent-ruby, httparty, jwt, oj, openssl, securerandom, sorbet-runtime, and zeitwerk. Development tooling is provided via rubocop, sorbet, tapioca, and minitest.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
Baseline
- First survey — no prior run to compare against. CAI 64.
Lenses
- Code Health 97
- Architecture 91
- Maturity 53
- Readiness 74
- Security 67
Changes since last survey
- 300 commits — 272 feature/other, 28 fixes
By area
- (repo) — 121 commits
- lib/shopify_api — 76 commits
- (root) — 68 commits
- docs/usage — 13 commits
- .github/workflows — 9 commits
- .claude/skills — 3 commits
- .github/CODEOWNERS — 2 commits
- test/clients — 2 commits
- test/webhooks — 2 commits
- .github/ISSUE_TEMPLATE — 1 commit
- sorbet/rbi — 1 commit
- test/auth — 1 commit
- test/test_helpers — 1 commit
Notable commits
- fix: Fix FeatureDeprecatedError being raised without a message
- fix: Fix edge cases for internal hosts
- fix: Fix gift card adjustment resource to proper name.
- fix: Fix sorbet types of the jwt payload attr_reader
- fix: Fix test
- fix: Fix type for Shop#google_apps_login_enabled
- fix: Fix webhook registration for topics containing dots
- fix: Fix: Apply same fixes to 2024-01
- fix: Fix: FulfillmentEvent returns String for province and country Feature: Tests for FulfillmentEvent that use non-nil province and country attributes Q: Does the API ever return Integer? Hard to prove a negative Fix: Variant class inventory_quantity attribute type which can be either integer, string or nil Chore: Add to changelog
- fix: Fix: ShopifyAPI::Webhooks::Registry doesn't update webhooks if metafield_namespaces has changed (#1344)
- fix: Fixed missing response_as_struct param for query method override
- fix: Fixes attribute diffing logic when updating REST resources with .save (#1282)
- fix: Fixes https://github.com/Shopify/shopify-api-ruby/issues/1311 by ensuring that the response body is always a Hash, even if ShopifyAPI.Context.response_as_struct is true. Had to add a Utility (ShopifyAPI::Utils::OstructHashUtils) to handle the conversion since a simple .to_h and even JSON.parse(response.body.to_json) did not work as expected (nested Keys and Array handling failed).
- fix: Fixes ruby version to have openssl
- fix: Merge branch 'Shopify:main' into fix/registry-process-with-response-as-struct
- fix: Merge branch 'main' into fix/registry-process-with-response-as-struct
- fix: Merge branch 'main' into fix/registry-process-with-response-as-struct
- fix: Merge branch 'main' into sle-c/shopify-env-fix
- fix: Merge pull request #1245 from hrdwdmrbl/fixes/type_errors
- fix: Merge pull request #1280 from Shopify/sle-c/shopify-env-fix
- …and 280 more
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
Shopify/shopify-api-ruby was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 20 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 4eca719dfbb38326e66d6bff0f3611ceeec53aeb — the exact code this score is about.
- Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-b51f968c9b10.