Shopify private app: connect with a dummy offline session and isPrivateApp
When you connect a private Shopify app with a permanent token, skip the OAuth dance.
When you connect a private Shopify app with a permanent token, skip the OAuth dance. Create a Session object with a placeholder id, the shop domain, and isOnline false, then init the API with apiSecretKey set to the permanent token and isPrivateApp true. Build REST or GraphQL clients from that session. Note the library still requires the scopes field at init even for private apps.
Context: GitHub issue Shopify/shopify-api-js#700 (closed, 18 comments): the reporter had a private app on a single store with a permanent access token and could not find how to connect without OAuth. A Shopify maintainer showed the pattern: build a dummy Session with isOnline false, put the permanent token in apiSecretKey, and set isPrivateApp to true in the config. Scopes still cant be an empty array at init, pass at least an empty-but-present value per the thread.