Shopify app

Fraud risk, on the order page.

Install it, approve the scopes, and every new order scores itself as it arrives. The assessment sits on the order beside Shopify’s own cards, and the tag lands where your rules can already see it.

admin.shopify.com/store/orders/1042

#1042

Payment pendingUnfulfilledMore actions

Unfulfilled (1)

Pro Cordless Impact Driver Kit

SKU 4482-K · 4 × $620.00

$2,480.00

Verify AI · Order risk

Re-verify
78
High riskVerified 22s ago

A first order at nine times the category average, shipping to a consolidation facility, paid with a card in a third party name.

4 risk factors

  • Shipping address is a freight forwarderhighaddress
  • Cardholder name does not match customerhighpayment
  • IP resolves to a datacenter rangemediumtechnical
  • First order, 9x the category averagemediumbehavioral

Recommendation

Verify identity before fulfilment

Hold

Notes

No notes from customer

Customer

D. Whitfield

1 order

Shipping address

8400 NW 25th St, Ste 120
Miami FL 33122
United States

Tags

wholesaleverify-ai:high

Written by the app. Shopify Flow and saved views can act on it.

Why an app and not an API key

Nobody wants to build fraud review into their checkout.

An API is the right answer when you already run a pipeline. Most Shopify merchants do not, and the honest version of “just call our endpoint” is a two-week project for a developer they would have to hire.

So the work of the integration is done here instead. The webhook subscription, the order fetch, the field mapping, the write-back, and the panel that renders the result are all part of the app.

What is left for you is the part only you can decide: which band gets a person, and what that person does about it.

What gets added

Six surfaces, all inside your admin

Three admin extensions, two pieces of write-back, and one webhook. Nothing to open in a second tab.

Order details page

Order risk block

A panel on every order showing the score, the risk level, each factor with its severity, the reasoning, and the recommended action.

Order details, more actions

Verify order action

Runs a fresh verification on demand, for orders placed before install or when the customer changed something.

Draft order details, more actions

Verify draft order action

Scores a quote before it converts, which is where B2B and phone orders need the check.

Order tags

Risk tag

Writes verify-ai:low through verify-ai:critical so Shopify Flow, saved views, and fulfilment rules can act on the result.

Order metafields

App metafields

Score, level, factors, analysis, and recommendations stored in an app-reserved namespace, readable by your own apps and themes.

orders/create webhook

Automatic verification

New orders are scored as they arrive, so the assessment is already there when someone opens the order.

Install

Four steps, none of them technical

  1. STEP 1

    Install from the App Store

    Shopify sends you straight to its own consent screen. There is no domain to type and no account to create first.

  2. STEP 2

    Approve the scopes

    Read on orders, draft orders, and customers; write on orders so the risk tag and metafields can be added. Nothing else is requested.

  3. STEP 3

    Create or pick a workspace

    Sign in with Google, GitHub, or a passkey. The store attaches to that organization, and its credits and logs live there.

  4. STEP 4

    Watch the next order

    The orders/create webhook scores it as it arrives. Open the order and the assessment is already on the page.

Signup happens after Shopify’s consent screen rather than before it, so the first thing you see is Shopify asking whether to trust the app, not a form asking for your store domain.

Access

Four scopes, and what each one reads

Listed in full, because “we request the permissions we need” is not an answer anybody should accept.

read_orders
Reads the order being scored: amount, line items, addresses, contact details, and the browser IP Shopify captured at checkout.
read_draft_orders
The same, for quotes and phone orders, so a B2B order can be checked before it converts.
read_customers
Order count, cancellations, returns, and average order value. This is what the behavioral family compares the current order against.
write_orders
Adds the risk tag and the app metafields. It is the only write the app performs, and it never changes an order’s status, fulfilment, or payment.
Protected customer data
The order scopes also need Shopify’s separate protected customer data approval on your store. Shopify prompts for it during install.
Automation

The tag is the integration point

Reading the panel is optional. Most stores act on the tag and only open the order when the tag says to.

Shopify Flow

Trigger on order tags added. Route verify-ai:high and verify-ai:critical to a hold, a note, an internal email, or a Slack message.

Saved views

Filter the orders list by tag so the fulfilment team sees a queue of what needs a person rather than everything.

Fulfilment rules

Third-party fulfilment and 3PL apps that read order tags will see the risk band without any additional integration.

App metafields

Score, level, factors, analysis, and recommendations are written to an app-reserved namespace, so your own theme or app can read the full assessment rather than the band alone.

Per-store switches

Automatic verification and automatic tagging are each switchable from the workspace settings, so a store can score without tagging or tag without scoring every order.

Nothing else changes

Order status, fulfilment, payment capture, and customer records are never written to. If Verify AI is removed, your orders are exactly as they were plus a tag.
Webhooks

What the app subscribes to

Four subscriptions, three of which exist because Shopify requires them of every public app.

orders/create
Scores each new order as it arrives, when automatic verification is on. Switch it off per store and verify by hand instead.
app/uninstalled
Removes the store and its cached verifications. Your organization’s verification log is untouched, because that is your record rather than the store’s.
customers/data_request
Shopify’s mandatory privacy webhook. Logged with a 30-day response window.
customers/redact and shop/redact
Also mandatory, also logged. Verify AI holds no customer personal data on a Shopify order beyond the order ID and the assessment, which is what makes these straightforward to answer.
Shopify

Install, scopes, and rules

Does the app hold, cancel, or refund orders?
No. It writes a tag and app metafields, and that is the extent of what it changes. Holding, cancelling, and refunding stay in your Shopify Flow rules and with your team, which keeps the decision on your audit trail rather than ours.
What does the tag look like?
verify-ai: followed by the band, so verify-ai:low, verify-ai:medium, verify-ai:high, or verify-ai:critical. When a re-verification moves an order to a different band the old tag is removed and the new one added, so an order never carries two.
Can I use it in Shopify Flow?
Yes, and it is the most common setup. Trigger on the order tag added, and route high and critical to a hold, a note, or a Slack message. The tag is also usable in saved order views and in fulfilment rules.
Can I score orders placed before I installed?
Yes. Open any order, choose Verify AI from the more actions menu, and it runs on demand. The same action exists on draft orders.
What happens if an order is missing data?
The extension says which fields are missing rather than scoring around the gap. Orders with no shipping address, for example, cannot be scored on the address family, and Verify AI would rather tell you that than return a number that looks complete.
Does it slow down checkout?
No. Verification runs after the order is created, from the webhook, so nothing sits in front of the buyer. A verification takes 15 to 30 seconds and finishes long before anybody opens the order.
Can one workspace hold more than one store?
Yes. Connect as many stores as you like to a workspace and they share its credits, members, and verification log. Agencies that need the balances and the history kept apart run one workspace per client instead, and switch between them from the same login.
What does it cost?
The app is free to install. Verifications consume credits from the workspace balance, at roughly four orders per credit and one dollar per credit. Signup includes five free credits, which is around twenty orders.

Install it and open tomorrow’s first order.

Five free credits, no card, and roughly twenty orders to judge it on. Uninstalling removes the store and its cached verifications the same day.

5 credits on signup · no card required