Overview
Shopify Webhooks is an automated identity associated with Shopify and used for Delivering Shopify Events and webhook notifications to subscribed HTTPS endpoints..
The primary recorded identity signal is Shopify-Webhooks. Representative HTTP identity: Shopify-Webhooks.
Directory status: Active. Identity classification: Verified with High confidence. Identity type: signed-webhook.
robots.txt is not used as a reliable access-control mechanism for this request class.
Risk classification: Safe. Recommended handling: no.
Identity
- User-Agent Pattern
-
Shopify-Webhooks - Aliases
- Shopify Events
- HTTP Agent Examples
-
Shopify-Webhooks - Identity Type
- signed-webhook
- Evidence Method
- Verify HTTPS deliveries with the Shopify-Hmac-Sha256 signature using the app secret; use webhook IDs for delivery deduplication.
Classification
- Type
- Webhook
- Kind
- Webhook
- Family
- Shopify
- Purpose
- Signed event delivery
Behavior and handling
- Common Use
- Delivering Shopify Events and webhook notifications to subscribed HTTPS endpoints.
- Detection Notes
- The current Shopify Events delivery path sets User-Agent to Shopify-Webhooks and includes signed delivery metadata.
- Respects robots.txt
- No
- Spoofing Risk
- Do not authenticate Shopify deliveries by User-Agent. Validate the HMAC signature and relevant delivery metadata.
- Risk
- Safe
- Recommended Handling
- Do not block
Rules and controls
- Robots.txt Snippet
-
# This is signed server-to-server event delivery, not a crawler. Restrict or reject it at the application/webhook endpoint if unwanted. - Apache Rule
-
SetEnvIfNoCase User-Agent "Shopify-Webhooks" bot_match - Nginx Rule
-
if ($http_user_agent ~* "Shopify-Webhooks") { set $bot_match 1; }