Skip to content
webfixed

Guides / Shopify

What is a Shopify collaborator request and is it safe to accept?

By the WebFixed team. Last updated 21 September 2026.

The short answer

A Shopify collaborator request is how a developer, designer or agency asks for access to your store from their own Shopify Partner account. It is safe to accept if you know who sent it, because they log in with their own details, only see the areas you approve, and can be removed at any time. You never share your password, and a collaborator does not use one of your staff accounts. To make sure only people you have chosen can send a request, keep the collaborator request code switched on under Settings, then Users, then Security, and only give the code to the person you have hired.

What a collaborator account is

Shopify has a free programme for developers and agencies called Shopify Partners. A partner can request access to a client’s store from their Partner Dashboard. When the store owner approves the request, Shopify creates a collaborator account on that store. It appears in your list of users, marked as a collaborator, and works like a staff account with a limited set of permissions.

The important difference from sharing a login is that the collaborator signs in through their own partner account. Your owner email address, your password and your two step login codes stay with you. Collaborator accounts do not count towards the staff limit on your Shopify plan, so accepting one costs nothing and does not take a seat away from your team.

What permissions a collaborator asks for

The request lists the parts of the admin the partner wants to use. You can untick anything you are not comfortable with before approving, and you can change the permissions later. Match the permissions to the job.

  • A theme or design fix normally needs Themes, and sometimes Navigation, Pages or Products so the developer can see how content is set up.
  • An app problem normally needs permission to manage apps.
  • A checkout, shipping or tax problem needs access to the relevant settings.
  • Customer and order data should only be granted when the fault involves orders or customer accounts. It is reasonable to ask why it is needed.

A collaborator with wide permissions can change a lot in your store, in the same way a member of staff could. The protection comes from granting only what is needed, knowing who you are dealing with, and removing the account when the work is finished.

Where to find your collaborator request code

Shopify can require a four digit code before anyone is able to send your store a collaborator request. This stops strangers from sending requests in the hope that you approve one by mistake.

  1. Log in to your Shopify admin as the store owner, or as a staff member who is allowed to manage users.
  2. Click Settings at the bottom left.
  3. Click Users, then Security.
  4. Find the Collaborators section. Your four digit collaborator request code is shown there.
  5. Check that the setting only allows requests from people who have the code.
  6. Send the code, along with your store’s myshopify.com address, to the developer you have chosen.

The code only lets someone send a request. It does not give access by itself, and you still have to approve the request. You can generate a new code in the same place whenever you want the old one to stop working.

How to approve a request

  1. Wait for the developer to tell you they have sent the request. Shopify also emails the store owner and shows a notification in the admin.
  2. Go to Settings, then Users. Pending collaborator requests are listed there.
  3. Open the request and check that the partner or company name matches who you are expecting.
  4. Read the permissions and untick any you do not want to grant.
  5. Approve the request. The developer can then log in from their Partner Dashboard.

If a request arrives that you were not expecting, decline it. A genuine provider will always tell you before sending one.

How to remove a collaborator

  1. Go to Settings, then Users.
  2. Click the name of the collaborator account.
  3. Choose the option to remove the account and confirm.
  4. If you want to be thorough, go to Security and generate a new collaborator request code.

Removal takes effect straight away. If you work with the same developer regularly you can leave the account in place, but there is no cost to removing it and approving a new request next time.

When to get help

You should not need paid help to approve or remove a collaborator, and Shopify support can walk you through the screens if something looks different in your admin. If you find a collaborator on your store that you do not recognise, remove it, generate a new request code and check recent changes to your theme and apps. When you do need a fault fixed, WebFixed works through a collaborator request, so no passwords are shared, and fixes it for a fixed price agreed up front, with one-off fixes from £39 including VAT and nothing charged until you accept the quote.

Related questions

Does a collaborator account use one of my staff seats?
No. Collaborator accounts do not count towards the staff account limit on any Shopify plan, and there is no charge for having one.
Can a collaborator see my password or bank details?
A collaborator never sees your password, because they log in through their own Shopify Partner account. What else they can see depends on the permissions you approve, so only grant access to finance or payment settings if the job needs it.
I received a collaborator request I was not expecting. What should I do?
Decline it. Then check under Settings, then Users, then Security that a collaborator request code is required, so only people you give the code to can send requests.
Can I change a collaborator’s permissions after approving?
Yes. Open the collaborator account under Settings, then Users, and edit the permissions at any time.