Shopify surface
Identify whether testing shopify api integrations belongs to the Admin GraphQL API, Storefront API, a webhook subscription, a Function, Flow, or an app-owned service. Each surface has different trust, execution, and version contracts. Use realistic fixtures, contract checks, dependency stubs, replay, failure injection, and a known rollback point.
Access and version
Document installation context, token type, header, scopes, protected data needs, and API version for development stores, fixtures, contract checks, webhooks, and failure replay. Authentication identifies the caller; authorization still has to be enforced for the requested action.
Cost and async state
Account for calculated GraphQL query cost, pagination, bulk-operation state, webhook delivery, or queue capacity as applicable. Mock-only happy paths conceal permission, rate, ordering, data-shape, and lifecycle defects.
Commerce reconciliation
Verify products, variants, orders, inventory, customers, or fulfillments reached the intended Shopify and external states. HTTP 200 can still contain GraphQL errors, and successful receipt is not final business proof.