TinyShopsTinyShops
Ban shoppers, order webhooks, and agent OAuth β€” week of Sep 24
Back to updates

Ban shoppers, order webhooks, and agent OAuth β€” week of Sep 24

By Tiny Shops TeamΒ·Β·3 min read
product updateorder webhooksban customerMCP agentsTelegram storeTiny Shops

A busy week for shop owners: block problem buyers, push every order to your warehouse or script, connect an AI agent with a browser sign-in, and keep the Mini App up when Sheets or deploys hiccup.

What shipped#

  • Ban a shopper β€” Customers β†’ row menu β†’ Ban customer. They lose the Mini App, checkout, shop bot, and broadcasts. Orders and bonuses stay; Unban customer anytime.
  • Order webhooks & fulfillment β€” Settings β†’ Order webhooks: signed order.created / order.updated to your HTTPS URL. Ship with carrier and tracking from the order page. Same shape over HTTP/MCP: get_order, ship_order. Guide: Orders API & Webhooks.
  • Connect agents with OAuth β€” OAuth 2.1 + PKCE for MCP clients (Cursor, Claude Code, and similar). Connections live next to API tokens under Settings β†’ Agents & API. Walkthrough: Connect an AI agent.
  • More agent tools β€” bot connect, setup analytics, win-back config, plus the full HTTP surface at /v1/{tool} with OpenAPI.
  • Storefront reliability β€” better survival across deploys; Google Sheets quota spikes serve a stale catalog instead of a dead 500.
  • Dashboard & storefront polish β€” count-up stats, sparks on add-to-cart, hold-to-delete with undo, clearer empty states.
  • Inbox & announcements β€” broadcasts show in the conversation thread; waiting threads sort by waiting since. Announcements support real audience segments and each owner gets their own language.
  • Billing note β€” stores that outgrew the free contact allowance are asked to pick a paid plan (no endless free extension). Card billing is Stripe only (Polar is gone).
  • Security β€” harder XSS paths and tighter handling of secrets on the platform side.

English site URLs no longer need an /en prefix β€” /blog/... and /updates/... are the root.

Where to click#

Ban a shopper#

  1. Dashboard β†’ Customers.
  2. Open the row menu β†’ Ban customer β†’ confirm.
  3. To reverse: same menu β†’ Unban customer.
Ban customer confirmation on the Customers page
Ban customer confirmation on the Customers page

1 β€” confirm ban. They lose Mini App, checkout, bot, and broadcasts; unban anytime.

Order webhooks#

  1. Dashboard β†’ Settings β†’ Order webhooks (owner only), or dashboard.tiny-shops.com/settings/order-webhooks.
  2. Paste a public HTTPS URL β†’ Save β†’ copy the signing secret when shown.
  3. Send test event to check your endpoint, then ship a real order with carrier/tracking when you are ready.
Order webhooks settings: HTTPS endpoint and Save
Order webhooks settings: HTTPS endpoint and Save

1 β€” paste a public HTTPS URL. Signed order.created / order.updated land here.

Agents & API: OAuth connect and API tokens
Agents & API: OAuth connect and API tokens

1 β€” connect Cursor / Claude Code with browser OAuth, or create an API token for scripts.

Deep dive for your developer or agent: Orders API & Webhooks. Agent sign-in: Connect an AI agent.

Related how-tos:

Create or open your store at tiny-shops.com β†’