Ecommerce & CMS · Integration

Share Shopify access without sharing a password

Last updated: August 2026

To give an agency access to Shopify, use Shopify collaborator or staff accounts — the agency requests collaborator access, kept separate from the owner login. No password is shared, the client keeps ownership of Shopify stores, and access can be removed anytime.
Full step-by-step guide

The official way to grant Shopify access

Shopify collaborator or staff accounts — the agency requests collaborator access, kept separate from the owner login. You'll find it under Settings → Users and permissions → Collaborators. The client keeps ownership of Shopify stores; the agency is granted only what you assign.

The mistake almost everyone makes: Sharing one staff login sends 2FA codes to the wrong person and leaves no audit trail. Collaborator accounts fix both.

What you'll need first

Access levels explained

Grant the least access the work needs. Here's what each level on Shopify can do:

Access level / roleWhat it can do
CollaboratorAgency-specific access, separate from staff, with granular per-area permissions and its own login. The right method for agencies.
Staff accountAn employee-style account with permissions you set. Use for ongoing team members, not external agencies.
Store ownerFull control including billing and closing the store. Never share.

How long it takes

A few minutes. The agency sends a collaborator request; you approve the requested permissions. No password exchanged.

Why this is safer than sharing a password

Collaborator accounts are Shopify's official agency access — separate from your logins, with their own permissions and audit trail, and no shared 2FA. Remove the collaborator anytime from Users and permissions.

Or do it in one link

Every step above is why agencies move to a single link. HandItSafe requests exactly the Shopify access you need — the client approves it through Shopify's own process in about three minutes, no password shared, and keeps a panel to see and remove access anytime. That visibility is why clients approve faster, and it makes offboarding a one-tap job later.

Read the full step-by-step guide to giving Shopify access

FAQ

Shopify access — your questions answered

Collaborator vs sharing a staff login?

Collaborator accounts are Shopify's official agency method — separate access, its own permissions, its own audit trail, and no shared 2FA.

Do I give my Shopify password?

No. The agency requests collaborator access; you approve the specific permissions.

How do I remove a Shopify agency?

Settings → Users and permissions → remove the collaborator. HandItSafe adds a one-tap client remove.

Collaborator vs staff account?

Collaborator is designed for agencies and developers: separate access, its own login, granular permissions, and it doesn't use a staff seat. Staff accounts suit ongoing internal team members.

Does a collaborator count as a staff member?

No — collaborator accounts don't consume your paid staff seats, so agency access doesn't cost you a seat.

Keep reading

Related guides

Skip the whole thing — send one link.

HandItSafe requests exactly this access in one link. No passwords. Your client keeps a panel to remove it anytime.