Custom Apps Come with More Security
Shopify wanted to add more security measures to the API process and the custom app features are a solution to this desire. By adding these security steps, store owners will feel confident that their data is protected from unwanted access.
The first security step requires a store merchant to enable the new custom app feature. Store owners must first enable the custom app development features before a token can be created. This prevents any collaborator or staff account from creating an API key without proper permission from the store owner.
Once enabled, the new app settings become accessible from within the Apps page in the Shopify Admin. All of the required API scopes and subscriptions are configured on this page. To activate the app it must be installed in the store. This installation step is the next new security measure that was not previously required for private apps. Only after installation can the app be used within the store.
Another newly added security measure is the one-time access to the secret token. The Admin API access token can only be viewed once to protect access to sensitive store data.