Hello everyone,
Quick heads up on session token troubleshooting ![]()
Some partners are reporting merchants receiving null session tokens, and we’ve found the pattern: it’s typically a permissions setup issue on the merchant side. Worth noting: we’re talking Shopify admin user permissions (the account that logs into POS), not POS staff permissions themselves (the staff member who “pins in” to the Shopify POS app).
When this happens consistently, the merchant needs to add a user role that grants access to your app. They’ll find this in the Admin under Settings → Users; they can edit existing roles and add app-specific permissions there. It’ll look something like the below images.
That said, we’re working on ways to more clearly communicate the user permission information within an extension. Thank you!

