---
title: Storefront API Permissions
description: Shopify Storefront API scopes for the default storefront and custom data.
url: "https://shop-docs.labs.vercel.dev/docs/reference/storefront-api-permissions"
docs_index: /llms.txt
lastUpdated: 2026-09-30
type: reference
prerequisites:
  - /docs/getting-started
---

> For an index of all documentation, see [/llms.txt](/llms.txt).

After [Getting Started](/docs/getting-started), open **Settings → Apps and sales channels → Headless → your storefront** in Shopify admin and grant these Storefront API permissions to the token.

## Required

| Scope                                   | Enables                                            |
| --------------------------------------- | -------------------------------------------------- |
| `unauthenticated_read_product_listings` | Products, collections, search, and recommendations |
| `unauthenticated_read_product_tags`     | Product tags requested by the storefront           |
| `unauthenticated_write_checkouts`       | Cart operations and checkout                       |
| `unauthenticated_read_content`          | Pages, blogs, and articles                         |

## Optional

Grant optional scopes only when your storefront queries the related data.

| Scope                                    | Enables                                                                                                 |
| ---------------------------------------- | ------------------------------------------------------------------------------------------------------- |
| `unauthenticated_read_product_inventory` | Inventory quantities, such as `quantityAvailable`; not required for the default availability indicators |
| `unauthenticated_read_metaobjects`       | Custom content stored in metaobjects                                                                    |

Customer sign-in uses separate Customer Account API permissions. See [Authentication](/docs/anatomy/authentication) for account setup and [Shopify's scope reference](https://shopify.dev/docs/api/usage/access-scopes) for additional permissions.

See [Environment Variables](/docs/reference/env-vars) for token configuration and [Storefront API](/docs/reference/storefront-api) for query validation and runtime behavior.

---

For a semantic overview of all documentation, see [/sitemap.md](/sitemap.md)

For an index of all available documentation, see [/llms.txt](/llms.txt)

For agent-facing discovery, including API and MCP surfaces, see [/agents.md](/agents.md)