Set up the Openflow Connector for Shopify¶
Note
This connector is subject to the Snowflake Connector Terms.
This topic describes the steps to set up the Openflow Connector for Shopify.
Prerequisites¶
-
Set up your runtime deployment.
-
If you’re using Openflow - Snowflake Deployments, ensure that you have reviewed the required domain configuration and have granted access to the required domains for the Shopify connector. If you’re using Openflow - BYOC Deployments, configure your cloud network egress to allow HTTPS (port 443) access to
<your_store>.myshopify.comandstorage.googleapis.com. The connector needs the latter to download signed Google Cloud Storage URLs that Shopify returns for bulk-query results. -
Ensure you have access to the Openflow admin role or a similar role you use to manage Openflow.
-
If you’re deploying in Openflow - BYOC Deployments and using the
KEY_PAIRauthentication strategy, set up key pair authentication. For more information, see key pair authentication.
Set up Shopify¶
A Shopify store administrator must create a Shopify dev app and configure API scopes for the connector to authenticate.
-
Log in to the Shopify Dev Dashboard.
-
Select Create app and provide an app name.
-
In the Access section of your new app, select the
read_*scopes for the objects you want to replicate:read_orders: orders, transactions, fulfillments (access limited to the last 60 days by default;read_all_ordersextends this to full order history but requires a separate Shopify access request; for details, see the note below)read_products: products, product variants, collectionsread_customers: customers, segmentsread_inventory: inventory items, locationsread_merchant_managed_fulfillment_orders: fulfillment orders
For the full list of available scopes, see the Shopify access scopes reference.
Important
Some scopes require Shopify approval before your app can use them:
read_all_orders: Required to access orders older than 60 days. Submit an access request through your app’s API access settings in the Dev Dashboard.- Protected customer data: The
read_customersscope includes customer fields (name, address, email, and phone) that Shopify classifies as protected customer data. Apps that read these fields must request access to protected customer data and meet Shopify’s data protection requirements. Submit an access request through your app’s API access settings in the Dev Dashboard.
For more information, see Protected customer data in the Shopify developer documentation.
Note
Grant only the scopes required for the objects you intend to replicate.
Some GraphQL fields require write scopes to read (for example,
marketingUnsubscribeUrlon theCustomerobject requireswrite_customers). If you don’t grant the corresponding write scope, the Shopify API returns an error for that field. To avoid this, either omit the field from thegraphqlFieldslist in the Object Definitions Override parameter, or add it toignoredFields. Note thatignoredFieldsworks on top-level field names only. For nested fields, you must remove them from thegraphqlFieldssub-selection. -
Select Release. Optionally provide a version name and message, then confirm by selecting Release again.
-
On the app Overview page, select Install app. You are redirected to your store. Select Install to confirm the installation.
Note
If you change the app’s scopes later, you must release a new app version and reinstall the app on your store to apply the updated permissions.
-
Navigate to Settings » Credentials to find your Client ID and Client Secret. Copy both values: you need them when configuring the Shopify Client ID and Shopify Client Secret connector parameters.
For more information, see Client secrets in the Shopify developer documentation.
Set up your Snowflake account¶
As an Openflow administrator, perform the following tasks to set up your Snowflake account. With the
default SNOWFLAKE_MANAGED authentication strategy, the runtime’s execute-as role is the identity
the connector uses to access Snowflake, so you grant it the following privileges.
Note
If you’re deploying the connector in Openflow - BYOC Deployments and using the KEY_PAIR authentication
strategy instead of the recommended SNOWFLAKE_MANAGED, you’ll also grant this same execute-as
role to a service user rather than relying on the runtime’s managed token. See
Set up key-pair authentication for Openflow - BYOC Deployments
to create the service user.
Create database, schema, and warehouse¶
-
Create the destination database:
-
Create the destination schema:
-
Grant the required privileges to the runtime’s execute-as role:
-
Create a warehouse (or use an existing one) and grant usage privileges:
-
If any other Snowflake users require access to the tables ingested by the connector (for example, for custom processing in Snowflake), grant those users the execute-as role.
Install the connector¶
To install the connector, do the following as a data engineer:
-
Navigate to the Connector library tab in Openflow.
-
On the Openflow connectors page, find the connector and select Install.
-
In the Select runtime dialog, select your runtime from the Available runtimes drop-down list and click Install.
Note
Before you install the connector, ensure that you have created a database and schema in Snowflake for the connector to store ingested data.
-
Authenticate to the deployment with your Snowflake account credentials and select Allow when prompted to allow the runtime application to access your Snowflake account. The connector installation process takes a few minutes to complete.
-
Authenticate to the runtime with your Snowflake account credentials.
The Openflow canvas appears with the connector process group added to it.
Configure the connector¶
To configure the connector, perform the following steps:
- Right-click on the added connector process group and select Parameters.
- Populate the required parameter values as described in the following sections.
Shopify parameters¶
The following parameters configure the Shopify source connection:
| Parameter | Description |
|---|---|
| Shop Domain | The Example: |
| Shopify Client ID | Client ID from your Shopify dev app. |
| Shopify Client Secret | Client Secret from your Shopify dev app. Stored securely as a sensitive parameter. |
| Shopify API Version | The Shopify Admin API version to use for requests. Default: |
| Objects to Sync | Comma-separated or newline-separated list of Shopify object types to replicate. Case-insensitive. Each value must correspond to a query endpoint in the Shopify Admin GraphQL API (for example, Default: |
| Objects to Track for Deletes | Comma-separated or newline-separated list of Shopify object types to monitor for deletions through the Events API. Each type is polled independently. Types not found in the registry are skipped. Leave empty to disable delete tracking entirely. Example: |
| Sync Schedule | How frequently the connector polls Shopify for new or updated data. Uses NiFi scheduling syntax. Default: |
| Deletes Schedule | How frequently the connector polls the Shopify Events API for deletion events. Uses NiFi scheduling syntax. Increase this interval to reduce API cost if delete detection latency isn’t critical. Default: |
| Object Definitions Override | Optional JSON array to add new object definitions or override existing ones in the built-in catalog. Each element fully replaces the catalog entry for that For more information, see Object definition overrides. |
| Enable Introspection | When Default: |
| Ignore Deprecated Fields | When Default: |
Snowflake destination parameters¶
The following parameters configure the Snowflake destination:
| Parameter | Description |
|---|---|
| Snowflake Authentication Strategy | Authentication strategy for the connector to connect to Snowflake.
|
| Snowflake Account Identifier | Snowflake account identifier, formatted as Example: |
| Snowflake Username | The Snowflake user for authentication. Required when the authentication strategy is KEY_PAIR. |
| Snowflake Private Key | PEM-encoded private key content (PKCS8 format) for Snowflake key pair authentication. Required when the authentication strategy is Either this parameter or Snowflake Private Key File must be defined. |
| Snowflake Private Key File | Alternative to Snowflake Private Key. Upload the private key file by selecting the Reference asset checkbox, uploading the file as an asset, and selecting the asset as the value for the parameter. Either this parameter or Snowflake Private Key must be defined. |
| Snowflake Private Key Password | Password to decrypt the Snowflake private key, if the key is encrypted. Only applicable when the authentication strategy is KEY_PAIR. |
| Snowflake Role | The execute-as role used for table creation, data ingestion, and access verification. |
| Destination Database | Name of the destination database in Snowflake. The database must already exist before starting the connector. |
| Destination Schema | Name of the destination schema in Snowflake. The schema must already exist before starting the connector. |
| Snowflake Warehouse | The Snowflake warehouse used for table management operations such as CREATE TABLE and MERGE. |
Run the flow¶
- Right-click on an empty area of the canvas and select Enable all Controller Services.
- Right-click on the connector process group and select Start.
The connector starts querying the Shopify Admin API and loading data into Snowflake.
Next steps¶
- For more information about customizing which fields are extracted and registering custom object types, see Object definition overrides for the Openflow Connector for Shopify.
- For more information about resetting connector state, see Maintain the Openflow Connector for Shopify.
- For more information about monitoring the flow, see Monitor Openflow using telemetry data.