Manual token is a compatibility path for stores that still have a legacy admin-created custom app (Shopify closed
creation of those in 2026 — see how-it-works). It needs read_orders +
read_shopify_payments_disputes. Token is sent only to this worker per-request and never persisted.
Connect with Shopify opens Shopify's official authorization page: you approve read-only access
(read_orders + read_shopify_payments_disputes) and you can revoke it in your Shopify admin at any time.
ChargeRadar never moves money, never refunds, never changes orders.