Thanks @Alan_G I believe I have all of that information already, so shouldn’t be a problem to provide it.
So you’d prefer if I send the user IDs as a DM rather than post them here?
Thanks @Alan_G I believe I have all of that information already, so shouldn’t be a problem to provide it.
So you’d prefer if I send the user IDs as a DM rather than post them here?
Thanks @simon_b - sending you a DM!
Hey @simon_b, just replying here publicly in case other folks are seeing this.
I was able to check this further on our end, and the examples you shared do look consistent with the authenticated POS staff user not having access to use the app. That would explain getSessionToken() returning an empty value even though the extension itself is loading.
The next thing I’d have the merchant confirm is that the logged-in POS user’s role includes access to your app/apps in general, not just that the POS staff member/account has general admin-style permissions. In Admin, they should check the user/role permissions and make sure the app is enabled for that user’s role.
So from your app side, I’d still recommend keeping the guard you added: if getSessionToken() returns "", null, or undefined after retries, I wouldn’t send the backend request and show a permissions/access message instead.
Let me know if they’re still seeing this after confirming the user has app access and I can keep looking into it from our end here.
Thanks @Alan_G I’ll feed this info back to any merchants I see encounter this issue.
Strange thing is that it appears to happen intermittently which is why I thought it may be linked to some other issue on the POS, but perhaps these merchants are just attempting to use different user accounts from time to time, or they are varying their permissions ![]()
Thanks again for looking into this one for me.
No worries @simon_b - if your merchants can confirm that the staff member should have access, just let me know and I can set up a DM and we can look into this further for sure.
I’ll mark the thread as solved for now, but just ping me here if I can help out ![]()
Hi @Alan_G while I’m updating my app to use web components I’m also looking at refining messaging, particularly around this permissions issue, I’m wondering how best to communicate which permissions are required to the user.
I know the app needs access to Shopify products, collections, and orders, but the user that first encountered this problem sent through this error message that they managed to capture some how on POS - user [###] does not have access to this feature for gid://shopify/App/XXX which suggests there is another app specific permission that is required, do you know what this is?
Hey @simon_b - I took another look into this, and I want to clarify my earlier wording a bit.
From what I can tell after digging into things on our end here, the error doesn’t point to products, collections, or orders permissions specifically. The gid://shopify/App/XXX part points to access to the app itself during session-token generation.
For getSessionToken(), the relevant user is the Shopify user actually logged into POS, not necessarily the pinned POS staff member. That user likely needs broader access to apps/channels in Admin.
The merchant-side check I’d suggest is:
From your app side, I’d keep treating getSessionToken() returning "", null, or undefined as a recoverable permissions state. I’d avoid sending the backend request in that case and show a message like:
Your Shopify user doesn’t have access to this app. Ask a store admin to update your user role so it has access to this app, then log out and back into Shopify POS.
I know you mentioned the merchant believed the user had admin/store-owner-level access, but from what I can see, the error message points to that app-level access check specifically, rather than products/orders/collections scopes.
If you see this again, just send over the shop ID, authenticated user ID from the POS session, POS version/platform, and UTC timestamp, and I can check that specific session-token failure on our end (I can set up a DM for this since some of that info is a bit private if needed for sure). If it is affecting the account owner, I’d agree this is really odd behaviour that I’d like to investigate further.
Thanks heaps @Alan_G, I did see this again in the last few days, one instance of an empty token "" and another with undefined, I’ll send you the details via DM.