Shopify is tightening the trust step that sits between a partner and a merchant’s live store. Agencies and freelancers should treat this as an access-management change that can delay client work if it is left until enforcement starts.
In a 9 July 2026 developer changelog post, Shopify says Partners can now complete identity verification before requesting collaborator access to merchant stores. Verification is optional at launch and will become mandatory in the coming weeks before a new collaborator request can be sent.
The change applies to users in a partner organisation who send new collaborator requests. Shopify says it does not apply simply to accessing collaborator shops where the merchant has already granted access. Verification is completed through Stripe and requires a government-issued photo ID plus a selfie or liveness check.
Why this matters for delivery teams
Collaborator access is often the first practical step in Shopify support, theme work, app configuration and emergency fixes. If the person who normally sends requests is unverified when enforcement starts, a routine handoff could stall before work even begins.
That is especially relevant for agencies with several developers, contractors or account managers. The requirement is per user, not just per partner organisation. A verified founder account will not help if a project manager or developer sends the actual request and has not completed the check.
Kahunam has previously covered Shopify platform access from the development side in How to use Shopify store auth with Claude or Codex to speed up Shopify development. This new verification step belongs in the same access checklist.
What to prepare now
Start by listing everyone who can request collaborator access for client stores. Include staff, contractors and anyone who covers urgent support. Then check whether each person has access to the Partner Dashboard account they use for requests and can complete identity verification on a suitable device.
Next, update onboarding for new delivery staff. Identity verification should happen before they are assigned to Shopify client work, not after a project is waiting for store access. For contractors, agree this step before the first engagement and make clear which partner organisation they will operate under.
Finally, review your access request process. If one person sends all collaborator requests today, create a backup route. If every developer sends their own requests, make sure the account manager can see who has completed verification and who still needs to act.
What merchants should ask partners
Merchants do not need to manage the partner’s verification process, but they can ask better access questions. Ask which people will request access, whether those users have completed Shopify Partner identity verification, and what happens if the named person is unavailable during urgent work.
It is also sensible to ask partners to keep collaborator permissions scoped to the work being done. Verification helps establish identity, but it does not replace permission hygiene. A verified user should still request only the access needed for the task.
The practical takeaway
Shopify’s identity verification requirement is aimed at reducing abuse around collaborator access. Agencies should prepare before enforcement starts by verifying every user who sends requests, documenting a backup requester, and updating onboarding. Merchants should treat verification as one part of a wider access-control conversation.