Doing what the Shopify API can’t, safely 安全地做 Shopify API 做不到的事
A browser-automation (RPA) solution that retroactively links historical customer orders to B2B Company Locations in Shopify Admin, a workflow Shopify’s API doesn’t expose at all. 一套浏览器自动化(RPA)方案,把历史客户订单补关联到 Shopify 后台的 B2B 公司地点,而 Shopify 的 API 根本不提供这个操作。
2026-07-07 · updated 2026-08-08 · first published on boheastill.com最初发表于 boheastill.com
The problem
In Shopify B2B, customers often place orders before their account is linked to a Company Location. Those orders are left orphaned: no corporate pricing, missing from the company’s purchase history, no unified invoicing. There can be hundreds of them.
The constraint
The problem: Shopify’s Admin API (GraphQL and REST) has no endpoint for retroactively associating existing orders with a B2B company. The only supported path is a precise sequence of clicks in the Admin UI: unlink the customer, save, re-link, and tick an “add the customer’s orders to this location” checkbox in a confirmation dialog. It can’t be scripted through the API, and it’s painfully slow by hand.
The solution: RPA that mimics the exact UI workflow
A Playwright engine drives the Admin UI through the exact 5-step wizard, triggered by a simple API call carrying a company ID and customer ID. It’s built to survive the things that break naive automation:
- Automated 2FA, without holding the client’s password long-term. When Shopify asks for a login, the script generates the current TOTP code from a secret seed (pyotp), so multi-factor auth never stalls an unattended run.
- Session persistence. After one successful login the browser state is serialized to JSON and reused, so repeated logins don’t trip Shopify’s rate limiters and CAPTCHAs.
- Selectors that survive UI changes. Buttons are found by ARIA role and label text rather than fragile CSS class names, so a Shopify UI update doesn’t quietly break the script.
- Cloud-ready. Runs headless on Browserless over a secure WebSocket, so there’s no Chrome maintenance to babysit.
The trust angle: no password sharing
Handing an automation vendor your store password and 2FA seed is a real security concern. This design keeps that exposure small: the client can switch to a one-click cookie-refresh flow, so I never need standing access to credentials. Addressing the client's security concerns is part of the deliverable, not an afterthought.
Proof
Where else this applies
Any SaaS admin task the vendor's API refuses to expose: bulk back-office edits, cross-platform syncs (Amazon, HubSpot, POS systems), migrations that only exist as a manual wizard. If your team is clicking the same sequence hundreds of times, it can be a safe, unattended script.
问题
在 Shopify B2B 里,客户经常在账户关联到“公司地点”之前就下了单。这些订单就成了孤立订单:享受不到企业价,不出现在公司采购记录里,也没法统一开票。这样的订单可能有几百笔。
约束
问题在于:Shopify 的 Admin API(GraphQL 和 REST 都一样)没有接口能把已有订单补关联到 B2B 公司。官方唯一的办法,是在后台界面里按顺序点:解除客户关联、保存、重新关联,再在确认弹窗里勾选“把该客户的订单加入此地点”。用 API 写不了脚本,手工做又慢得要命。
方案:精确复刻 UI 流程的 RPA
一个 Playwright 引擎驱动后台界面,走完精确的 5 步向导,由一个携带公司 ID 和客户 ID 的简单 API 调用触发。它被设计成能扛住那些让粗糙脚本崩溃的情况:
- **自动通过 2FA,且不长期持有客户密码。**Shopify 要求登录时,脚本用密钥种子(pyotp)实时算出当前的 TOTP 验证码,无人值守运行时也不会被多因素认证卡住。
- **会话持久化。**首次登录成功后,浏览器状态序列化为 JSON 复用,避免反复登录触发 Shopify 的限流和验证码。
- **不怕界面改版的选择器。**按钮按 ARIA 角色和标签文字定位,不靠容易变的 CSS 类名,Shopify 改版也不会让脚本悄悄失效。
- **云端就绪。**通过安全 WebSocket 在 Browserless 上无头运行,不用伺候本地 Chrome 的维护。
信任要点:无需共享密码
把店铺密码和 2FA 种子交给自动化外包,确实让人担心安全。这个设计把风险压到最低:客户可以改用一键刷新 Cookie 的流程,我不需要长期持有任何凭据。打消客户的安全顾虑,本身就是交付的一部分,不是事后补的。
证明
还能用在哪
任何 SaaS 后台里、厂商 API 就是不开放的操作:批量后台编辑、跨平台同步(Amazon、HubSpot、POS 系统)、只以手工向导形式存在的数据迁移。如果你的团队在把同一套点击重复几百遍,它就能变成一个安全、无人值守的脚本。