Connecting a store and permissions
What Kobold asks for when you install it, and what it will never touch.
What Kobold asks for
Kobold is installed as a Shopify app with exactly two access scopes:
| Scope | Why |
|---|---|
read_themes | Read your live theme so the agents understand how it is built. |
write_themes | Create and edit a copy of your theme (kobold-NNNN), and publish it only after you approve. |
In plain words: Read your theme · Write to a copy only · Publish only with your OK · Never checkout, payments or customer data. No other scopes are requested.
How copies work
Each task gets its own duplicate of your live theme, named like kobold-0412. Nib only ever writes to that copy; Kobold's Shopify client refuses any write to the theme that is currently live. Shopify allows 20 themes per store, so Kobold removes copies it created once they are older than 30 days and no longer needed for rollback.
If your live theme is edited in the Shopify admin while a task is waiting for approval, Kobold notices before publishing. You can re-apply the change to a fresh copy (recommended) or publish anyway, which is recorded in the audit log.
Supported themes
Kobold works with Horizon, Dawn and most Online Store 2.0 themes: themes that use JSON templates, sections and blocks. When you connect, Kobold reads the theme and tells you if something isn't supported, for example a vintage (1.0) theme or files it can't parse.
Password-protected stores
If your storefront has a password, add it under Store settings → Storefront access so Moss can test the preview. The password is encrypted and only used by the QA browser.
Disconnecting
Uninstall Kobold from Shopify, or disconnect the store from Settings → Stores. Kobold deletes that store's memory, rules and theme index after 30 days. Theme copies stay in your Shopify theme library until you remove them.