> ## Documentation Index
> Fetch the complete documentation index at: https://docs.depict.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Run an allow-listed Shopify Admin GraphQL operation for the merchant

> Forwards a GraphQL request to the merchant's Shopify Admin API with the app's stored access token. Only the portal's own allow-listed operations pass (the name and document must both match); everything else is refused. Allow-listed mutations write to the live store. Returns Shopify's GraphQL body verbatim, including GraphQL-level `errors`.



## OpenAPI

````yaml /api-reference/openapi/lite.json post /shopify/proxy/{merchant_id}/admin-api/graphql.json
openapi: 3.1.0
info:
  title: Search & Merchandising API
  version: 1.0.0
  description: >-
    REST API behind Depict: Search & Merchandising, the native Shopify app:
    onboarding, collections, boost & bury, dashboards, A/B testing and
    multi-store management. Endpoints are served under the /api/lite prefix and
    are authenticated with the Shopify session token that App Bridge issues to
    the embedded app.
servers:
  - url: /api/lite
security:
  - ShopifySessionToken: []
paths:
  /shopify/proxy/{merchant_id}/admin-api/graphql.json:
    post:
      summary: Run an allow-listed Shopify Admin GraphQL operation for the merchant
      description: >-
        Forwards a GraphQL request to the merchant's Shopify Admin API with the
        app's stored access token. Only the portal's own allow-listed operations
        pass (the name and document must both match); everything else is
        refused. Allow-listed mutations write to the live store. Returns
        Shopify's GraphQL body verbatim, including GraphQL-level `errors`.
      operationId: shopifyAdminProxy
      parameters:
        - schema:
            type: string
            description: Lite merchant id, e.g. `shopify-<shop id>`.
          required: true
          description: Lite merchant id, e.g. `shopify-<shop id>`.
          name: merchant_id
          in: path
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/AdminGraphqlRequest'
      responses:
        '200':
          description: Shopify's response.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/AdminGraphqlResponse'
        '400':
          description: >-
            The body failed the schema, the query does not parse, or the
            merchant has no Shopify configuration.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Detail'
        '401':
          description: Not authenticated.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Detail'
        '403':
          description: >-
            This identity may not call the API, or the operation is not
            allow-listed.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Detail'
        '404':
          description: Merchant not found for this caller.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Detail'
        '415':
          description: Content-Type is not application/json.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Detail'
        '429':
          description: >-
            Shopify throttled the call (its body is in `detail`); back off and
            retry.
          headers:
            Retry-After:
              schema:
                type: string
                description: Shopify's own Retry-After, when it sent one.
              required: false
              description: Shopify's own Retry-After, when it sent one.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Detail'
        '500':
          description: Internal error.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Detail'
        '502':
          description: >-
            Shopify could not be reached or answered another non-2xx (its status
            and body are in `detail`).
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/Detail'
components:
  schemas:
    AdminGraphqlRequest:
      type: object
      properties:
        operationName:
          type: string
          minLength: 1
          description: >-
            Must name one of the portal's allow-listed Admin API operations;
            anything else is refused with 403.
        query:
          type: string
          minLength: 1
          description: The GraphQL document; must match the allow-listed one.
        variables:
          type: object
          additionalProperties: {}
      required:
        - operationName
        - query
      additionalProperties: {}
    AdminGraphqlResponse:
      type: object
      properties:
        data: {}
        errors:
          type: array
          items: {}
        extensions: {}
      additionalProperties: {}
      description: Shopify's GraphQL response body, forwarded verbatim.
    Detail:
      type: object
      properties:
        detail:
          type: string
      required:
        - detail
      description: 'Every 4xx/5xx body: `{detail}`.'
  securitySchemes:
    ShopifySessionToken:
      type: http
      scheme: bearer
      bearerFormat: JWT
      description: >-
        Shopify App Bridge session token of the embedded Depict: Search &
        Merchandising app. The shop in the token determines the merchant;
        merchant_id parameters must belong to that shop.

````