> For the complete documentation index, see [llms.txt](https://doc.duaer.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://doc.duaer.com/troubleshooting/shopify-401-invalid-access-token.md).

# Fix Shopify 401 Invalid API key or access token in Duaer

A Shopify 401 in Duaer means Shopify rejects the token: the wrong value, the wrong shop subdomain, or a token that changed after reinstalling the app.
## What the error looks like in Duaer

[API] Invalid API key or access token (unrecognized login or wrong password), HTTP 401.

## Check each field in Duaer

1. Is it the access token? The Admin API access token starts with shpat_. Neither the API key nor the API secret key is it.
2. Shop Subdomain is only the xxx of xxx.myshopify.com: no custom domain, no https://.
3. After the app is reinstalled or the token rotated, the old token stops working. Put the new one in the Duaer [Shopify credential](/integrations/builtin/credentials/shopify.md).
4. Duaer tests the connection when you save; then run the node with Execute step.

## When it is 403, not 401

403 means the token is valid but lacks a scope, such as read_orders. Add it under the app Admin API scopes, reinstall, and put the new token in Duaer. When Shopify Trigger receives events but fails verification, check APP Secret Key in the credential.
## Questions

### Which token goes into the Duaer Shopify credential?

The Duaer Shopify Access Token credential takes the Admin API access token starting with shpat_, and Shop Subdomain is only the part before myshopify.com.

### Shopify worked in Duaer, then suddenly returned 401. Why?

The app was likely reinstalled or the token rotated. Put the new token in the Duaer credential.

## Related

- [Set up Shopify credentials in Duaer](https://doc.duaer.com/integrations/builtin/credentials/shopify.md)
- [Send new Shopify orders to Google Sheets with Duaer](https://doc.duaer.com/recipes/shopify-orders-to-google-sheets.md)
- [Fix Google invalid_grant and 7-day token expiry in Duaer](https://doc.duaer.com/troubleshooting/google-oauth-invalid-grant.md)

