Shopify App未登录时出现OAuth重定向URI白名单错误求助
Hey there, let's tackle this Shopify OAuth redirect URI issue you're running into—especially since it only crops up when users aren't logged in. Here's a breakdown of what's likely happening and how to fix it:
Shopify enforces strict exact matching for OAuth redirect URIs—this includes the protocol (http/https), domain, port, path, and even trailing slashes. From the URL you shared for logged-in users, the redirect_uri is http://54.218.116.25:8080/login/finalize/ (note the trailing slash at the end).
- Head to your Shopify app's settings and verify that the "Allowed redirection URL(s)" list includes this exact URI:
- Did you accidentally omit the trailing slash in the whitelist?
- Is the protocol (http vs https) a match? If your testing environment uses HTTP but production uses HTTPS, make sure both variants are added (or use the correct one for your current setup).
- Is the port number
8080included? If your whitelisted URI doesn't have the port, Shopify will reject the request.
The key clue here is that the error only happens for logged-out users. This suggests the redirect_uri being passed in the OAuth authorization request might differ when the user isn't logged in. For example:
- Your app's code might generate the redirect_uri dynamically (e.g., pulling from request headers) and that logic fails for logged-out users (maybe headers are missing or different).
- Double-check the code that builds your OAuth authorization URL. Instead of relying on dynamic values that might change, use a hardcoded or config-based URI that matches your Shopify whitelist exactly.
Here's a quick example of what that might look like in Node.js/Express:
// Use a fixed, whitelisted redirect URI const redirectUri = 'http://54.218.116.25:8080/login/finalize/'; const authUrl = `https://${shopDomain}/admin/oauth/request_grant?client_id=${yourApiKey}&redirect_uri=${encodeURIComponent(redirectUri)}&scope=write_products,write_orders,write_customers,read_checkouts`;
You mentioned the app worked fine two weeks ago. Ask yourself:
- Did you modify the "Allowed redirection URL(s)" in Shopify's app settings recently?
- Did you update the code that generates the redirect_uri?
- Did your server's domain, port, or path configuration change?
Even a tiny tweak (like removing a trailing slash) could break the matching.
Since you only have the URL from logged-in users, use your browser's developer tools to inspect the OAuth request when a user is logged out:
- Open the Network tab in DevTools.
- Trigger the authorization flow for a logged-out user.
- Look for the request to
oauth/request_grantand check theredirect_uriparameter in its URL. - Compare this value directly against your Shopify whitelist—any discrepancy (even a single character) will cause the error.
If you're stuck finding the exact mismatch, add all plausible variants of your redirect URI to Shopify's allowed list to test:
http://54.218.116.25:8080/login/finalize(no trailing slash)http://54.218.116.25:8080/login/finalize/(with trailing slash)- If you use HTTPS in any environment, add
https://54.218.116.25:8080/login/finalize/too
Once the error goes away, you can remove the unused variants to narrow down the exact match you need.
内容的提问来源于stack exchange,提问作者Shivkumar Agrawal

