CRM Auth

Loading...

Setup Wizard

Welcome to CRM Sync

Commerce is pivoting from human-to-human to agent-mediated — AI agents discover, negotiate, and transact for customers. CRM Sync is the consent-first identity, consent & agent-permission layer that makes that safe — on your Shopify store, your PWA, or any site you ship.

1 · Connect your worker

Point the extension at your CRM Sync worker and authenticate.

2 · Connect your data

Add only what you need — Shopify (customers & commerce), Xano (identity store), or Webflow CMS (publishing). None of them are required to start. Do it now in Config, or skip and come back.

3 · Turn on your surfaces

Enable the consent banner, account, and dashboard embeds and set your consent defaults — the customer-facing surfaces CRM Sync powers.

You're set up

Paste the embed loader on your site, then manage everything from the dashboard.

Worker Connection

Your deployed Cloudflare CRM Worker endpoint
Tenant token from your CRM Sync purchase, or admin key for self-hosted workers
Need your own worker? Contact Sales →
Upgrade to a Private Worker for dedicated infrastructure, custom domains, and full data isolation. Includes this full Configurator, served by your worker — no Webflow required. We build in Webflow; the interface is plain HTML/CSS/JS with petite-vue for data binding, and any HTML, CSS, or JS component can drive the same API with the same key. Identity is included: Google and Shopify login work on every framework (Next.js, Astro, AEM, …) — no fee-based login service to buy. View plans

ERP & WMS Systems

The CRM App's core purpose: connect to your ERP (financials/GL, costing, MRP) and WMS (inventory, fulfillment). Secrets are stored on the worker and masked here.

Google Merchant · UCP

The agent-catalog plane: Shopify Global Catalog UCP MCP, Google Merchant MCP, and the automated Agent / Dark Warehouse data feed. Feed events log to the ERP & WMS systems above, Remittance, and Customer Service Consent Management. CLI: npm install -g @shopify/ucp-cli then ucp profile init --name agent.

Shopify Global Catalog over MCP (JSON-RPC). Inferred response fields are discovery signals, not merchant-authored text.
MAPI Docs MCP — public, no auth. Pairs with the Merchant Center ID set in Google onboarding.
Local CLI profile (~/.ucp/profiles/<name>) presented on every merchant-scoped request.
Automated products feed (live prices, GTINs, ship-to countries) with no human in the loop; every feed event logs to ERP, WMS, Remittance, and Consent Management.

Shopify Credentials

Settings → Store details → numeric ID in URL
Headless channel → Customer Account API → Client ID (Public/PKCE, no secret needed)
Headless channel → Storefront API → Public access token. This is the whole Shopify connection for catalog, cart and checkout — no app install and no review. Leave the Admin token blank if you only need those.
Only needed for writes back into Shopify: customer tags, native unsubscribe, customer creation, discounts, policy pages. Connect below, or paste a token from a custom app in your own admin.
Which Shopify app this store installs under. There is deliberately no default — the app decides the token, scopes, webhooks and extensions, so Connect returns an error until this is set.
Dev Dashboard → Settings → Secret. Used for OAuth token exchange.

Webflow CMS Sync

Webflow Site Settings → Integrations → API Access → Generate token. Scopes: CMS read/write.
Found in Webflow Designer → CMS → Customers collection → Settings → Collection ID

Google OAuth

Pre-configured on your CRM worker. No setup needed on shared plans.
Custom OAuth domains available on Private & Enterprise plans

Xano Backend

Email (Resend)

From resend.com/api-keys. Required for password reset emails.
Must use a verified domain in Resend. Format: Name <email@domain.com>

Google Analytics (GA4)

GA4 property → Admin → Data Streams → Web → Measurement ID
GA4 property → Admin → Data Streams → Measurement Protocol API secrets → Create

Integrations

Adobe Experience Platform is supported directly — configure it below.
Additional platforms are available on an enterprise deployment:
Salesforce • HubSpot • Klaviyo • Attentive • Braze
Enterprise deployment & pricing →

Adobe Experience Platform (AEP)

Adobe Admin Console → Organization ID
Adobe Developer Console → Project → OAuth Server-to-Server credential
AEP → Sources → HTTP API → Streaming connection → Inlet ID
AEP sandbox name (default: prod)

Auth Methods

Session

Consent & Privacy

UCP Entitlement

Agent protocol access — controls AI agent interactions with customer data

Shopify Everywhere

Embed a consent-governed funnel on any surface. Pick a funnel, pick a platform, copy the snippet. (Recycled from the Story-Story embed model.)

Connect a worker to generate the snippet…

Footer Code (Site Settings)

Paste into Webflow Site Settings → Custom Code → Footer Code

CRM Footer Loader

Page Embeds

Code Embeds for specific pages

Account Page
UCP Dashboard
Compliance / Privacy
Shop Page

Nav Element

The auth script hooks into element with id="kb-login" or id="lo-login"

PIM Sync Embeds

Product catalog embeds from PIM Sync Worker

Your PIM Sync Cloudflare Worker endpoint
Header CSS Variables
Footer / Collection Grid
PDP Variants

Channels & Add-ons

Omni-channel projection of entitlement + consent through Xano (integration layer / data funnel) to Cloudflare, Shopify, GA4, and enterprise add-ons (Adobe / SAP / Nielsen). Full management — sync, connectors, and the Data Funnel (mapping & rules) upsell — lives in the Config Portal.

ChannelCadenceConfiguredCursorStatus
Connect a worker to load channels…

Worker Health

Not checked

Auth Endpoints

OAuth Redirect URIs

Secure token exchange endpoints for customer sign-in. Registered with each identity provider.

Custom Worker Setup Shared

[LOCKED]
Custom CDN domain and dedicated OAuth endpoints
Available on the Private and Enterprise plans — see pricing

Consent & Privacy API

Not checked

GDPR / Data Requests

Not checked

Pricing Compliance Status

EU Omnibus (Directive 2019/2161): the chatbot only quotes a "was" price when a verified 30-day prior-lowest reference exists. Captures land in the crm_price_observations ledger.

Not checked

PIM Linked Logging (Omnibus)

Optional connector — sockets CRM price observations to the linked PIM Sync app over the shared Xano seam. Fail-closed: disabled leaves capture local-only.

Xano outbox keeps the shared Xano layer as the only seam (replay + cursor).
Drift guard — must match the PIM ⇄ CRM boundary contract version.

Variant Reference Lookup