Chapter 4

Shopware API integration

How to create a dedicated integration in the Shopware admin — with a role that has the minimum required permissions.

Overview

Webshop-Radar connects to your Shopware stores through the built-in Admin API. You create a dedicated integration in the Shopware admin and paste its credentials into the Webshop-Radar dashboard. No SSH, no cron jobs on your side.

Step 1: Create the integration

In the Shopware admin, go to Settings → System → Integrations → Add integration. Give it a clear name (e.g. Webshop-Radar) so future admins recognize it.

Step 2: Assign a dedicated role

Do not tick the admin box. Instead, create a dedicated role and grant only the permissions Webshop-Radar needs.

Security best practice. Use a role with the least permissions required — see the security page for our full recommendation.

Recommended permissions

  • Read — Products, Categories, Orders, Customers (for the read-only monitoring features)
  • Read — Plugins, Sales Channels, System Config (for status & version detection)
  • Write — only for the specific entities you allow Webshop-Radar to modify. For monitoring only: no write permissions.

Step 3: Copy credentials into Webshop-Radar

After saving the integration, Shopware shows the Access Key ID and Secret Access Key once. Copy them into the installation dialog in Webshop-Radar — see chapter 2.

You cannot re-read the secret after closing the dialog. If you lost it, delete the integration and create a new one.

Rotating credentials

Rotate the integration credentials at least every 6 months. Delete the old integration in Shopware, create a new one, and paste the new credentials into the installation in Webshop-Radar.