🔒 Secure Shopify Access for Agency OTTO Installation

Camilo Aponte

Camilo Aponte

Last updated on Sep 30, 2026

Overview

As an agency partner, you should never need to ask a client for their Shopify username and password. Shopify provides a built-in staff and collaborator access system that lets your client invite you directly — giving you the permissions needed to install OTTO securely, without credential sharing of any kind.

What You Need Before Starting

  • Your client's Shopify store URL (e.g., storename.myshopify.com)
  • The email address associated with your Shopify account or the one you want your client to send the invite to
  • Your client to have Staff or Owner-level access to their own Shopify admin

Step 1 — Ask Your Client to Grant You Staff Access

Ask your client to add you as a staff member or collaborator through their Shopify admin. They should use the email address you provide, and assign you sufficient permissions to install apps. Your client does not need to share any passwords — Shopify will send an invitation directly to your inbox, granting you secure, role-based access.

For exact navigation steps within their Shopify admin, your client can refer to Shopify's official Help Center at help.shopify.com for up-to-date guidance on managing staff and permissions.

Step 2 — Accept the Staff Invitation

Once your client has sent the invite, check the inbox of the email address they used. Open the invitation email from Shopify and follow the prompts to accept access. You will need to create or log in to a Shopify account when prompted. After completing this step, you will have access to your client's Shopify admin with the permissions they assigned.

Step 3 — Install OTTO on the Client's Store

Once you have staff access to your client's Shopify store, proceed to connect and install OTTO through your Search Atlas account. To do this, log in to Search Atlas, open the OTTO setup flow for the relevant project, and when you are prompted to authenticate with Shopify, log in using your own staff account credentials — not your client's. This keeps your client's primary credentials secure while allowing you to complete the installation on their behalf. If you are unsure which project to connect or encounter an error during the Shopify authentication step, note the exact error message and the store URL so our team can assist you quickly.

Why This Method Is Recommended

  • No password sharing: Your client never needs to hand over credentials.
  • Role-based access: Shopify's permission system limits what each staff member can see and do.
  • Revocable at any time: Your client can remove your access from their Shopify admin whenever needed.

If you need further assistance, open the chat widget in the bottom-right corner of the platform and type human teammate to be connected with a member of our team.