Step-by-step guide

How to give agency access to Shopify

Last updated: August 2026

How to give agency access to Shopify: use Shopify collaborator or staff accounts — the agency requests collaborator access, kept separate from the owner login. Open Settings → Users and permissions → Collaborators, add the agency, choose the access level, and confirm. You never share a password and can remove access anytime.

Before you start

Have these ready — it's what onboarding stalls on:

Step-by-step

  1. In Shopify admin, go to Settings → Users and permissions.
  2. Under Collaborators, set who can send requests (or use the store's collaborator code).
  3. The agency sends a collaborator request with the permissions they need.
  4. Review the requested permissions.
  5. Approve — they're added as a collaborator, separate from your staff logins.
Where 90% of onboardings fail: Sharing one staff login sends 2FA codes to the wrong person and leaves no audit trail. Collaborator accounts fix both.

Which access level to grant

Grant the minimum the work needs. On Shopify, the levels are:

Access level / roleWhat it can do
CollaboratorAgency-specific access, separate from staff, with granular per-area permissions and its own login. The right method for agencies.
Staff accountAn employee-style account with permissions you set. Use for ongoing team members, not external agencies.
Store ownerFull control including billing and closing the store. Never share.

How long it takes, and who does what

A few minutes. The agency sends a collaborator request; you approve the requested permissions. No password exchanged.

What you (the client) do

Open Settings → Users and permissions → Collaborators and grant the access — a few minutes.

What the agency does

Accept and confirm from their side, then start work.

How to check it worked

Access is granted when:

If it doesn't work

The most common problems and how to fix them:

Collaborator requests are blocked

Under Users and permissions, set collaborator requests to “anyone” or share your collaborator request code with the agency.

Agency asked for a staff login instead

Don't share a staff login — it sends 2FA to the wrong person. Use a collaborator account, which is Shopify's official agency method.

Too many permissions requested

Review the requested permission list and approve only what the work needs.

Why you don't share a password

Collaborator accounts are Shopify's official agency access — separate from your logins, with their own permissions and audit trail, and no shared 2FA. Remove the collaborator anytime from Users and permissions.

The faster way: one link

Everything above is why agencies switch to a single link. HandItSafe requests exactly this Shopify access for you — the client approves through Shopify's official process in about three minutes, no password shared, and keeps a panel to remove it anytime. When the engagement ends, removing access is one tap with a full log.

FAQ

Giving Shopify access — questions

Collaborator vs sharing a staff login?

Collaborator accounts are Shopify's official agency method — separate access, its own permissions, its own audit trail, and no shared 2FA.

Do I give my Shopify password?

No. The agency requests collaborator access; you approve the specific permissions.

How do I remove a Shopify agency?

Settings → Users and permissions → remove the collaborator. HandItSafe adds a one-tap client remove.

Collaborator vs staff account?

Collaborator is designed for agencies and developers: separate access, its own login, granular permissions, and it doesn't use a staff seat. Staff accounts suit ongoing internal team members.

Does a collaborator count as a staff member?

No — collaborator accounts don't consume your paid staff seats, so agency access doesn't cost you a seat.

Keep reading

Related guides

Skip the whole thing — send one link.

HandItSafe requests exactly this access in one link. No passwords. Your client keeps a panel to remove it anytime.