Skip to content

Events schema blocks app deploys that use legacy OAuth scopes #8388

Description

@AlexVPopov

Summary

Shopify app deploy is blocked for an established app that uses the legacy OAuth installation flow with per-shop dynamic scope overrides.

The current remote app-config schema requires an Events section with at least one subscription. Adding a Product subscription and declaring read_products passes shopify app config validate, but app-version creation fails with:

Missing scope for event topic: Product (read_products)

This happens with both the documented scopes string and the newer required_scopes array when use_legacy_install_flow = true. Removing the Events section instead fails config validation with [events]: Required.

Reproduction

  1. Use Shopify CLI 4.7.0 with an app config containing access_scopes, read_products, and use_legacy_install_flow = true.
  2. Add an Events subscription for the Product topic.
  3. Run shopify app config validate: the config is valid.
  4. Run shopify app deploy --no-release: version creation fails because read_products is allegedly missing.
  5. Remove the Events section and validate again: validation fails because Events is required.

The same mandatory-Events schema is received by the repository-pinned CLI 3.94.3.

Expected behavior

Events is a developer-preview feature and should remain optional. Apps using legacy OAuth should be able to deploy without an Events section. Alternatively, if Events is intended to support legacy installation, its topic-scope validator should recognize scopes declared in the app config.

Impact

The app cannot create staging or production app versions without either adopting preview Events and abandoning its existing legacy dynamic-scope flow, or failing app-config validation. This blocks unrelated extension deployments.

Activity

  1. hanyi1994 commented on Aug 24, 2026

    @hanyi1994

    Same issue and look forward to a solution

  2. nikunjgrowisto commented on Aug 24, 2026

    @nikunjgrowisto

    Same issue here — CLI 4.7.0, fresh reinstall (ruled out local corruption). App has no use_legacy_install_flow set (defaults to legacy).
    [events] absent → "events": Required. Added a bare [events] block with no subscriptions → got both "Unsupported section(s) in app configuration: events" and ["events",
    "subscription"]: Required at once. No valid TOML satisfies all three checks.

    Also now blocking shopify app dev, not just deploy — this stops local development entirely, not just releases. Would appreciate a priority bump.

  3. AlexVPopov commented on Aug 24, 2026

    @AlexVPopov
    Author
  4. github-actions commented on Oct 6, 2026

    @github-actions
    Contributor

    This issue seems inactive. If it's still relevant, please add a comment saying so. Otherwise, take no action.
    → If there's no activity within a week, then a bot will automatically close this.
    Thanks for helping to improve Shopify's dev tooling and experience.

    P.S. You can learn more about why we stale issues here.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions