---
title: >-
  More resilient token exchanges when migrating tokens without a user session -
  Shopify developer changelog
description: >-
  Shopify’s developer changelog documents all changes to Shopify’s platform.
  Find the latest news and learn about new platform opportunities.
source_url:
  html: >-
    https://shopify.dev/changelog/posts/more-resilient-token-exchanges-when-migrating-tokens-without-a-user-session
  md: >-
    https://shopify.dev/changelog/posts/more-resilient-token-exchanges-when-migrating-tokens-without-a-user-session.md
metadata:
  effectiveApiVersion: ''
  affectedApi:
    - displayName: Admin GraphQL API
      handle: admin-graphql
    - displayName: Admin REST API
      handle: admin-rest
  primaryTag:
    displayName: API
    handle: api
  secondaryTag:
    displayName: Update
    handle: update
  indicatesActionRequired: false
  createdAt: '2026-09-28T16:14:19-04:00'
  postedAt: '2026-09-29T12:00:00-04:00'
  updatedAt: '2026-09-29T09:55:50-04:00'
  effectiveAt: '2026-09-29T12:00:00-04:00'
---

September 29, 2026

# More resilient token exchanges when migrating tokens without a user session

DateSeptember 29, 2026

FlagsUpdate

SurfacesAPI

Affected APIs[Admin GraphQL API](https://shopify.dev/changelog?api_type=admin-graphql)[Admin REST API](https://shopify.dev/changelog?api_type=admin-rest)

# More resilient token exchanges when migrating to expiring offline access tokens

When you migrate an app from non-expiring offline tokens to expiring offline access tokens without a user session, you can now recover a lost migration response by retrying the exchange with the original non-expiring token for up to seven days. This reduces how often you need a merchant to reopen the app to restore access, but you don’t need to change existing flows to keep them working.

## What changed

When you migrate an existing non-expiring offline token to an expiring offline access token without a user session, an eligible retry using the same original token and client credentials returns the same access-token and refresh-token pair as the initial exchange.

On an eligible retry:

* Shopify returns the same access token and refresh token.
* Shopify extends the access token’s expiry when needed.
* Shopify doesn’t extend the refresh token’s expiry.

Recovery for a particular store and app ends when any of the following is true:

* Seven days have passed since the initial exchange for that original token.
* Your app successfully refreshes the issued pair.
* A later token acquisition for the same store replaces that pair, such as a new authorization code or ID-token exchange.

The original non-expiring token remains invalid for `GraphQL Admin API` requests after migration.

## Who's affected

This change affects apps that migrate existing non-expiring offline tokens without a user session, as described in the guide on [migrating existing tokens without a user session](https://shopify.dev/docs/apps/build/authentication-authorization/migrate-to-expiring-offline-access-tokens#migrate-existing-tokens-without-a-user-session).

## Why this matters

If your app loses the migration response or fails to store it, you can often recover the access and refresh tokens without requiring the merchant to reopen the app and go through authorization again.

## What to do

When you don’t receive or persist the migration response:

1. Repeat the same migration request with the original non-expiring token and valid client credentials, within seven days of the initial exchange.
2. Persist the returned access token, refresh token, and expiry values together.
3. Discard the original non-expiring token so your app doesn’t attempt to use it again.

If a retry returns `invalid_subject_token`, acquire a new token for that store through ID-token exchange or the authorization code grant and then update your stored credentials accordingly.
