If you only remember one thing: admin.shopify.com is where Shopify login happens now. Not your store URL, not a bookmark from 2019, not the Partner Dashboard. Type that, sign in with the email attached to your Shopify ID, and you'll land on a picker showing every store that email has access to. The old yourstore.myshopify.com/admin address still works and redirects, but if you're having trouble getting in, the redirect is one more thing that can go sideways. Start clean.
Most access problems we get pulled into aren't really password problems. They're a departed employee's Gmail, a phone that was traded in with the authenticator app still on it, a card that stopped clearing Shopify's monthly bill, or three Google accounts open in one browser. Here's how each of those actually plays out, and what you can do before it happens.
One email, three different doors
Your Shopify ID is the account. The store is separate. That distinction confuses people daily, because the same email address can be a store owner on one store, staff on a second, a collaborator on a third, and a Partner account holder on top of that. Signing in at partners.shopify.com gets you the Partner Dashboard, which is not the store admin. Signing in at admin.shopify.com gets you the stores. Same credentials, different destination.
So when someone tells us "my Shopify login isn't working," the first question is always: which screen are you on, and what exactly does the error say? "No account found with that email" almost always means a different email, not a broken account. "Incorrect password" means the account exists and you're one reset away. Those are completely different problems.
The password reset, when your email still works
Boring and fast. On the login screen, enter your email, hit the forgot-password link, and Shopify mails a reset link. It expires, so use it in the same sitting. Two things trip people up:
- The mail lands in Promotions or gets eaten by a corporate spam filter. Search for shopify.com across all folders rather than scrolling the inbox.
- A password manager autofills an old entry on the new-password screen and you end up setting the same password you forgot. Type it in manually, then save it.
If no mail arrives at all after ten minutes and the address is definitely right, the likely answer is that no Shopify ID exists on that address. Check for a personal address you used during the trial before the company domain existed. We find that one a lot.
Two-factor is where Shopify login goes properly wrong
Password recovery is easy because it's automated. Two-step recovery is hard because it isn't, and that's the point of it.
Depending on what's enabled on the account, your second step is an authenticator app code, an SMS, a passkey or security key, or one of the recovery codes you were shown when you set it up. That last set is the only one that survives a lost phone, and it's the one nobody keeps. Shopify shows those codes exactly once. If you downloaded them, they're sitting in your Downloads folder under a filename you don't recognise. Go look.
If every second factor is gone, you're into a manual identity check with Shopify support, and that runs in days rather than minutes. Expect to prove you are who you say you are: the payment card on the account, domain registrar records, incorporation or GST documents matching the business name on the store. The verification is deliberately unpleasant, because the alternative is that anyone with a convincing story can take over a store.
Two habits that cost nothing. First, set up the authenticator on a second device, or use an authenticator that syncs across devices, so one broken phone isn't a crisis. Second, if the account's SMS number is a +91 mobile you no longer use, change it today. International SMS delivery to Indian networks is not reliable enough to be your only fallback, and a number you've surrendered can be reissued to a stranger.
Passkeys are worth turning on. Face or fingerprint on a device you already own, nothing to type, and phishing-resistant by design. Keep one recovery code printed anyway.
When the store owner has left the company
The ugliest version of this problem. A founder or a first employee set the store up on their personal email, owns it in Shopify's eyes, and is no longer reachable. Everyone else on the team is staff. Staff cannot transfer ownership. Only the owner can.
If you can still reach the person, fix it in ten minutes: they log in, go to Settings, Users, and transfer ownership to a staff account that already has full permissions. Done.
If you can't reach them, it's the same document-heavy support path as the 2FA case, with the added complication that you're asking Shopify to move control of a business asset away from its registered holder. Bring everything: bank statements showing payouts to your company account, the domain WHOIS or registrar login, company registration, the card paying the subscription. It gets resolved. It does not get resolved quickly, and it never resolves on the Saturday of a sale.
Our advice to every client at handover is the same: store ownership sits on a role address like ops@yourdomain.com that the company controls, with two people able to read that mailbox. Personal Gmail is fine for a trial. It is not fine for a business.
Staff logins, collaborators, and the offboarding nobody does
Staff accounts are for your team. Collaborator accounts are for agencies, developers and freelancers, they're requested from a Partner account, and they don't consume a staff slot on your plan. Practically, that means when you bring in a developer, they should be asking for collaborator access, not for your password. If anyone asks you to share a login, that's a signal about how they work.
You control the front door with the collaborator request code in Settings, Users, under security. Turn it on and only people you've given the code to can even send a request. Keep the permissions tight: a theme developer doesn't need Finances, and an email agency doesn't need Apps.
Now the part that gets skipped. When someone leaves, their Shopify login usually stays alive for months. Same for the agency you stopped working with in March. Open Settings, Users right now and read the list out loud. If you can't name the person and say what they're currently doing, remove them. While you're there, use the option to log out of all sessions so an open browser tab on someone's old laptop stops being a live session.
The login problems that aren't login problems
A good chunk of "I can't get into Shopify" tickets have nothing to do with credentials.
The store is frozen for non-payment. You log in fine, and then you're stuck on a billing screen while your storefront shows customers a closed sign. This hits Indian merchants disproportionately. Recurring charges to Shopify are international, and Indian cards decline them regularly under the RBI's additional-authentication rules for standing instructions. The bank calls it a security feature. You find out when your store goes dark. Keep a second card on file, watch for Shopify's failed-payment emails instead of filtering them, and check the billing page in the first week of every month.
Trial ended and no plan was chosen. Admin opens, storefront doesn't. Pick a plan and it's back.
Browser state. Multiple Google accounts signed in, an aggressive ad blocker, a VPN routing you through another country, or a corporate proxy that strips cookies. Test in a private window with extensions off before you file a support ticket. That alone resolves it about half the time.
POS. Shopify POS staff sign in with a PIN, which is not the same as the admin password. A store manager who's forgotten a PIN needs it reset from the admin, by someone who can get into the admin.
Customer login is a separate system, and merchants mix them up
Worth flagging because we get asked about it in the same breath. Your customers' accounts have nothing to do with your admin credentials. Shopify's newer customer accounts sign shoppers in with a one-time code sent to their email, no password at all, and you can switch between that and the legacy password-based version in Settings, Customer accounts.
If you're seeing customers complain about not being able to log in, look at which version you're running and whether your transactional email is being delivered. On Indian networks, code emails landing in spam is a far more common cause than anything broken in Shopify.
What a lockout actually costs
Being locked out doesn't take your store down. Orders keep coming. What you lose is the ability to change anything, and that's where the money goes.
Take a store running a festive campaign with a 20% code meant to expire at midnight. Nobody can get into the admin to switch it off, and it runs for another 14 hours. In that window the store takes 180 orders at a ₹2,400 average order value: ₹4,32,000 of revenue, with ₹86,400 handed over in discount that was never budgeted. On a 22% gross margin that's most of the day's profit gone, and it was a login problem.
Same maths applies to an out-of-stock SKU you can't unpublish, a pricing error you can't correct, or a Razorpay setting you can't touch. The lockout is cheap. The thing you couldn't fix is expensive.
A fifteen-minute hardening pass
Do this once, in one sitting, and most of the above stops being a risk:
- Move store ownership to a company-controlled email that two people can read.
- Turn on a passkey or authenticator, then download the recovery codes and put them somewhere that isn't the same laptop. A printed copy in the office safe is not old-fashioned, it's correct.
- Delete every staff and collaborator account you can't justify, and log out all sessions.
- Enable the collaborator request code.
- Add a backup payment method to billing and confirm the primary card is a type that reliably clears international recurring charges.
- Write the recovery process on one page and give it to whoever runs operations. The person who needs it at 11pm during a sale will not be you.
If you'd rather someone else looked at it, our free store audit covers admin access and permissions alongside the usual speed and conversion checks. Takes us about a week, and the access review is often the part that surprises people the most.


