TellWang
Dashboard

Storefront Import

The public Tryout detects and captures Shopify, Shopline, or WooCommerce storefronts. A committed live_transition can start for Shopify or Shopline. Shopify has the active end-to-end migration pipeline; Shopline can securely authorize and create its Storefront token, then stops at a visible source-import blocker until the dedicated worker is ready. WooCommerce live migration is not startable yet.

The one-time full-migration contract is a release candidate. Shopify custom distribution is restricted to botanic-pretti5-l-skincare.myshopify.com, multi-store installation is disabled, and the active app version still requests only read_themes. Do not ask Pretti5 to approve the app until the matching pretti5-full-migration.v1 app version, control plane, worker, and template are published together. The replacement client secret is encrypted in platform secrets and the initial credential was revoked. The candidate release includes the Shopify authorization, managed Storefront runtime, detected account connection, segmented source capture, fixed worker, compatibility compiler/runtime, exact Preview deployment, deployment-bound browser and commerce evidence, fail-closed parity, and editable Wok handoff. No merchant-authorized Pretti5 run has passed, and no production template or migration worker is active. WooCommerce stops before committed journey creation and is directed to public Tryout. Never paste a token, secret, cookie, or nonce into the Storefront URL, Wang chat, an issue, or frontend code. DNS and Shopify theme publication remain unavailable.

Choose the migration intent

"Progressive migration" can mean testing whether the import is worthwhile, or moving the complete live store first and redesigning it afterward. Import must ask which job the merchant is doing before it asks for connections.

Try it first

Start with the storefront URL and an owned Preview Wok. The one assigned password-protected development store can connect through the same Shopify app used for the live-store pilot; TellWang keeps its private discovery gates locked until authorization. TellWang can capture the visible site without touching live traffic. A future authorized source capture can add richer private source evidence, then let the merchant stop. It does not compile or deploy a Wok. Runtime catalog, accounts, checkout, production domains, and cutover are not required.

Provider access is still an administrative change. A Shopify app remains installed until revoked or uninstalled, so TellWang must show the exact access and revocation action before approval. WooCommerce admin setup is outside the Pretti5 release.

The future Shopify Tryout dynamically requests read_themes as an optional scope plus only other approved read-only source scopes, never write_themes. WooCommerce authorization and source-connector work is outside the Pretti5 release.

The current workspace implements only this URL-based public capture. Provider-authorized Tryout is not live yet.

Move a live store

This customer path can start for Shopify or Shopline. A committed Shopify merchant gets one resumable guided run for source authorization, runtime catalog and cart access, accounts, data continuity, checkout, consent, analytics, production-host readiness, rollback origin, and route acceptance. A committed Shopline merchant gets the same Preview and secure connection setup, and its catalogue is read and recorded from the Shopline Admin Open API. It then stops at an explicit gate: theme analysis, candidate compile, and deploy are not implemented for Shopline, so no Shopline storefront is served yet.

The complete Shopify permission set is disclosed and approved during the first app connection. This is the only planned app approval in a normal migration. TellWang provisions Storefront runtime access from that grant. Customer-account configuration and domains remain distinct, receipted operations inside the same resumable run.

The full versioned permission contract is approved early. TellWang creates or reuses the app-owned Storefront token when the runtime needs it; the merchant does not install Headless or paste a token for that managed Storefront runtime. A store already using Shopify's newer Customer Accounts may still need its Headless-channel public client setup. Account settings and adapter setup appear when discovery proves they are needed. Production domains, Shopify's stable legacy origin, and the whole-host DNS plan appear near launch, after their evidence is current. The Pretti5 release does not offer a redirect theme or request write_themes.

Setup is not activation. Shopify DNS waits for a complete verified Wok baseline. The original Shopify storefront stays online while the Preview is built and tested.

The source stays online and authoritative through cutover and for as long as commerce, synchronization, a provider handoff, or the rollback window depends on it. Production DNS remains a deployment-bound, owner-approved operation. Shopify keeps the original published theme live and performs no theme action. Redirect-theme publication is outside the Pretti5 release so the old storefront remains independently usable as the hot backup.

For Shopify, every public storefront route needs a verified Wok baseline before the hostname moves; the native Shopify theme cannot remain transparently proxied under selected paths. The merchant can launch a native / while product pages use the imported compatibility frontend and Shopify continues to power commerce and checkout.

WooCommerce passthrough and progressive route activation are future work. They are not available from the committed migration UI and do not affect the Shopify/Pretti5 workflow.

Route state Meaning after cutover
Compatibility Imported, evidence-backed Wok behavior. Shopify storefront routes begin here.
Native Merchant-edited Wok route. Visual parity is intentionally waived, while the frozen functional contract still runs.
Provider handoff Verified provider checkout, account, or extension journey that cannot run under the Wok route. Unknown or session-unsafe handoffs block activation.

The committed Shopify flow is a separate resumable journey today. Reusing public Tryout evidence through a new immutable-input child execution is planned follow-up; it must revalidate the current Shopify MAIN theme rather than mutate a started request.

Minimum needed to start

  1. Confirm that you own the source store or are authorized to migrate it.
  2. A public Tryout needs only the storefront URL. Admin access is not required until the merchant chooses an authorized source capture or live transition.
  3. For a connected Shopify run, use a staff role that can manage apps and sales channels. Do not create WooCommerce keys or install a connector for this iteration; WooCommerce can use public Tryout only.
  4. Keep the existing storefront and checkout live. A reference capture is not a deployable copy.
  5. Let Import create a journey-unique Wok and linked Preview, or choose an active owned Preview that is empty and not assigned to another migration. TellWang's managed .claude/skills/tellwang/SKILL.md file is neutral Wok context; other .claude files still count as customer work. Preview uses a stable HTTPS hostname such as <wok-id>.tellwang.com.
  6. For a live transition, inventory accounts, payments, subscriptions, tax, shipping, search, reviews, loyalty, analytics, consent, and every app or extension that changes the storefront.
  7. Confirm which source-backed capabilities remain in use. TellWang derives and displays each connection lifecycle; a credential or connector stays active while synchronization or runtime behavior depends on it.
  8. Do not change production DNS yet.

Know which connection you need

Connection Purpose Credential boundary
Shopify migration authorization Imports the exact published MAIN theme. One server-handled approval of the exact pretti5-full-migration.v1 contract. Admin access is read-only; no merchant-created Admin key.
Storefront runtime Supplies live catalog, content, Markets, cart, and Shopify's exact returned checkoutUrl. TellWang creates or reuses an app-owned Storefront token, verifies it server-side, and stores it encrypted. Nothing is copied from Shopify Admin.
Customer accounts Import detects the live /account mode and binds classic customer-access-token or new Customer Account API sessions. Classic reuses managed Storefront access automatically. New mode may additionally need a public Customer Account client ID and exact Preview URLs. It never uses a browser client secret.

The production hostname is not another API credential. It stays on Shopify during Preview acceptance.

Shopify setup

Shopify setup has one planned app approval. TellWang then provisions the Storefront runtime automatically from the approved contract. The merchant does not install the Headless channel, create a Storefront token, or paste one into Import for that managed runtime. A store already using Shopify's newer Customer Accounts may still need Headless-channel public-client setup for account login.

This complete section applies to Move a live store. Provider-authorized Tryout and evidence reuse are planned follow-up. Today a committed Shopify migration starts its own resumable journey and captures the current published theme before admission. A confirmed start retires its browser retry key; only an uncertain network outcome keeps the key for safe replay.

These steps define the production connection flow. Do not generate, copy, or rotate a credential. Classic accounts use TellWang's managed Storefront runtime automatically; new Customer Accounts may require a public client ID with PKCE and no client secret when detected. The release includes the fixed Shopify worker, segmented capture, compatibility compiler/runtime, three connection brokers, editable Wok handoff, candidate evidence producer, and parity gate. The candidate connection surface is ready for release review; no Pretti5 migration is ready until the matching app version is published and the merchant installs and authorizes the app, every app/account adapter or blocker has evidence, and merchant review plus independent QA pass.

Approve the complete migration permission set

For a new migration, TellWang first creates the Wok and its editable Preview automatically. The dashboard names that work Create Preview Wok, shows the elapsed time, and tells the merchant to keep the page open because no action is required. Only after provisioning finishes does the journey surface Connect Shopify as its first provider action. TellWang then creates a short-lived, browser-bound install intent and opens Shopify's approval screen. The generated custom install link stays in platform secrets. After installation, Shopify returns to TellWang, which verifies Shopify's signed request and automatically continues authorization. Sign in to Shopify and approve the exact pretti5-full-migration.v1 contract once.

The Shopify Admin scopes are read-only:

The shopper-facing Storefront scopes are:

The Storefront write scopes let shoppers update only their own checkout and account state through Shopify. TellWang requests no Admin write, order, payment, domain, or traffic scope. Import shows the contract version, SHA-256 digest, full lists, and lifecycle before continuing. The authorization route stores its expiring offline credential in an encrypted control-plane connection. The broad token never reaches the migration worker. The worker can only resolve the published MAIN theme, read bounded theme-file pages, and verify the same snapshot through fixed control-plane operations. Completing the action pins that connection and creates one idempotent discovery capture bound to the organization, Preview Wok, canonical source, and Shopify platform. A complete public route universe is retained by digest and divided into independently budgeted reference captures of at most 20 routes. Import exposes aggregate and segment progress, verified-stage progress, total elapsed time, and time since the latest status check. Active work refreshes every four seconds. The journey warns when the worker has not accepted a capture within two minutes or an accepted capture has no fresh status for three minutes. A password page fails visibly and asks for the Online Store password in Import. TellWang exchanges it server-side for temporary storefront access, discards the raw password, and restarts the same capture. Other access challenges remain blocked. Later setup forms remain hidden until they are actionable, and Resume retries only failed segments. The journey remains blocked until every immutable admission input exists. Once admitted, the fixed worker imports and verifies the exact published MAIN theme, compiles it, and deploys only to Preview. It never modifies or publishes a Shopify theme.

The production connection uses server-handled OAuth through the dedicated, single-store Shopify app. Its exact installation and OAuth callbacks, encrypted client credentials and install link, control-plane encryption key, and full permission contract must be healthy together. Full migration execution still needs merchant installation and authorization, the fixed-worker installation, and signed Marketplace publication. The encrypted connection is retained and its rotating offline grant is renewed in the background for source refresh and the required near-launch source recheck without another merchant approval. That recheck is not implemented yet and remains a production release gate. Shopify asks the merchant to connect again only if the grant becomes impossible to renew, an extended outage lets it expire, the app is uninstalled or revoked, or a future migration materially expands the permission contract. Transient renewal and token-provisioning failures are retried without involving the merchant. When a reconnect is genuinely required, the same journey displays Connect Shopify with the complete permission disclosure. TellWang archives only secret-free lineage digests, invalidates the old source capture and execution, and starts a fresh capture and re-import after approval.

The connection uses the store's permanent Shopify identity, such as acme.myshopify.com, even when shoppers currently use acme.com. TellWang should detect and display that identity for confirmation; do not substitute the new Wok hostname.

If access must be removed, use Disconnect in Import. TellWang blocks the journey, stops active work, removes Shopify configuration from linked Preview and Published Woks, scrubs the full encrypted connection family, and confirms every active Wok restart before reporting success. Then uninstall the TellWang app in Shopify Admin to finish provider-side revocation. If a restart cannot be confirmed, the connection remains fail-closed in revoking; retry Disconnect rather than assuming the old runtime is safe.

Once a Shopify journey claims its Preview, visual changes go through Wok Git. Direct frontend, app-server, edge-function, promotion, and custom-domain writes are blocked while the journey is active. This makes every edit run the post-edit commerce checks and keeps the source hostname on Shopify throughout Preview testing.

Do not create a Shopify custom app or paste a Shopify app client secret or Admin token into TellWang. Shopify no longer permits new admin-created custom apps, and a multi-merchant TellWang product must use Shopify's install and token flow. Source import remains locked until the connection is consumed by the bounded importer and its artifact, freshness, and credential-boundary receipts are durable.

Let TellWang provision Storefront access

After Shopify returns from the one approval, Import provisions the runtime connection automatically. TellWang uses the encrypted Admin grant inside the control plane to find its exact app-owned Storefront token or create one when none exists. It accepts only the ten Storefront scopes disclosed above, verifies the permanent shop, navigation, catalog, content, localization, empty-cart creation, and Shopify's HTTPS checkout URL, then stores the token encrypted for the protected Wok server. The connection reports auth_mode: managed_public_token without returning the token to Import or browser code.

The merchant does not install Shopify's Headless sales channel, add a Headless storefront, change shared Headless permissions, or copy a Storefront credential for the normal Pretti5 flow. A safe retry reuses the app-owned token; even an ambiguous Shopify timeout is followed by a bounded re-check before TellWang considers creating another one. Transient failures return CP_STOREFRONT_SHOPIFY_MANAGED_RUNTIME_UNAVAILABLE and do not require another approval. If Shopify says the app cannot create a Storefront token, CP_STOREFRONT_SHOPIFY_MANAGED_RUNTIME_NOT_EXTENDABLE sends the repair to a TellWang operator, who publishes a storefront-capable, extendable app version and retries with the existing merchant approval.

The first production canary must prove that Shopify permits this distributed app to create a Storefront access token. Shopify may require the app to be extendable before storefrontAccessTokenCreate succeeds. Until that real canary passes, keep the existing Shopify storefront live and do not tell Pretti5 that automatic runtime provisioning is proven.

The Wok calls https://<shop>.myshopify.com/api/<version>/graphql.json from the server. Ordinary Storefront API calls do not need the Wok hostname in a Shopify origin allowlist.

A copied theme's own scripts expect that endpoint on the storefront they are running on, so the Wok answers /api/<version>/graphql.json on its own hostname and forwards each document to Shopify server-side. The request must be a same-origin POST; the storefront token stays on the server and never reaches browser code. Without this route a browser's cart mutations are refused while server-side commerce checks still pass.

Read Shopify's official Storefront token creation reference, Storefront API setup, and Storefront API authentication rules.

Connect customer accounts

  1. In Import, select Detect and connect customer accounts. TellWang probes the committed journey's live public /account route and login handoff, then records digest-bound classic or new evidence. If neither mode can be proven, setup stops without changing the connection. Verify the result in Shopify Admin → Settings → Customer accounts.
  2. Pretti5 currently resolves /account to its same-origin legacy login form, so TellWang detects Legacy customer accounts. Do not upgrade it during preparation. TellWang keeps this mode and uses Shopify's legacy customer-access-token flow through the Wok server.
  3. For a legacy-account store, no additional Shopify setup is needed. TellWang already verified that the managed Storefront runtime has unauthenticated_read_customers and unauthenticated_write_customers. Do not create a Customer Account API client or add callback origins for this mode.
  4. Use a dedicated test customer during the real Preview canary. Its password is posted over HTTPS to the Wok only for Shopify's login mutation; TellWang must neither persist nor log it. The customer access token is encrypted in a secure, HTTP-only Preview cookie.
  5. Only for stores already using the newer Customer accounts, Import may ask the merchant to install or open Shopify's Headless channel, then open Sales channels → Headless → the TellWang storefront → Customer Account API settings.
  6. Under Permissions, preserve every currently enabled shared permission and add only missing customer data used by the Wok. Account and order-history flows normally need customer_read_customers and customer_read_orders. Add customer_write_customers only for profile or address editing, and add company, location, subscription, draft-order, metaobject, market, or store-credit scopes only for captured features.
  7. Create a Public client. TellWang uses Authorization Code with PKCE S256 and accepts the Client ID only. Never generate or paste a browser client secret.
  8. Under Application setup, add the exact Preview callback, logout URL, and JavaScript origin that TellWang displays. Add production values later, when the launch hostname is fixed.
  9. TellWang appends sso=silent to Shopify's exact returned checkout URL after a verified Customer Account session. Localized account paths pass their exact locale to Shopify's hosted login and return to that path. Complete a merchant-assisted real Preview login, logout, order-history, and checkout canary. Mode detection or discovery alone does not prove account UI parity.

For either account mode, the first Preview must render the imported Shopify customer login and account templates, including their styles and interactions. An authenticated generic TellWang login page is not parity evidence. The production canary fails closed while the runtime reports ui_parity_verified: false.

standard Wok account URLs
Preview callback:    https://<wok-id>.tellwang.com/account/authorize
Production callback: https://acme.com/account/authorize
Preview logout:      https://<wok-id>.tellwang.com/
Production logout:   https://acme.com/

For a public web client, add https://<wok-id>.tellwang.com and https://acme.com as separate JavaScript origins.

A callback URL contains a path. A JavaScript origin contains only scheme, host, and optional port. Shopify rejects localhost and HTTP here. Do not guess the callback path; copy the values from the Wok's domain step. See Shopify's Customer Account API setup and customer access-scope list.

Treat privacy consent as a blocker when the store uses it

The current compatibility runtime has no reviewed Shopify Customer Privacy adapter. Its fixed browser policy permits same-origin connections only, so a theme script cannot make cross-origin privacy calls work by adding Shopify's checkout domain to connect-src. Do not create another public token or loosen that policy during the current Pretti5 migration. If the source uses Shopify's Customer Privacy API or Shopify cookie banner, retain it as an unresolved dependency: the candidate cannot pass merchant acceptance or launch until a reviewed adapter exists and its consent journeys pass.

A future adapter may expose the existing managed public Storefront token only through its reviewed browser-safe configuration; it must never expose the broad Admin OAuth grant. Bind the Storefront API, storefront root, and checkout root explicitly; keep storefront and checkout under the same registrable root; and verify accept, reject, preferences, sale-of-data, regional banner, and storefront-to-checkout consent continuity against Preview. Shopify documents the required parameters in its Customer Privacy API guide.

Add the storefront, legacy, and checkout hosts

Attach acme.com or www.acme.com through TellWang's Wok custom-domain connection. The production Import domain step will wrap that existing connection and return the exact ownership and routing DNS records; that Import step is not live yet. Do not set the hostname as a Shopify custom-storefront target: Shopify's domain target UI supports Shopify-hosted Hydrogen custom storefronts, not an external TellWang Wok.

Before launch, add and verify a stable legacy hostname such as legacy.acme.com for Shopify's Online Store. Keep the original published theme active there and test home, product, cart, account, and extension journeys directly. The legacy hostname must not redirect to acme.com, the Wok, or another hostname that will move at cutover.

For branded Shopify checkout, add checkout.acme.com under Shopify Admin → Settings → Domains, point only that subdomain to Shopify using Shopify's DNS values, and verify its certificate during preparation. Use the exact Shopify routing values returned for checkout and prove that the resulting checkoutUrl does not loop through the storefront hostname. Shopify documents checkout routing in its traffic migration guide.

The default signed policy is legacy_hot_standby. The original Online Store and published theme stay live at legacy.acme.com; cutover moves the whole storefront hostname to TellWang with theme_action: none. Default rollback restores routing to that already-live origin with theme_action: none. It does not depend on republishing a theme.

The Pretti5 release rejects redirect_theme and never requests write_themes. The original published theme remains available at the legacy origin as the independently usable hot backup.

Shopline setup

Start with the permanent store identity shown in Shopline Admin, such as acme.myshopline.com. After the Preview Wok is ready, choose Connect Shopline. TellWang opens Shopline's public-app approval screen with the complete shopline-headless-migration.v2 permission disclosure. The Admin permissions are read-only; the shopper-facing permissions cover cart, checkout, customer information, and metaobjects.

Shopline gates selling-plan access behind a separate subscription commerce qualification. The baseline connection does not request read_selling_plan_group, so ordinary stores can authorize without that qualification. A source that uses Shopline subscriptions remains blocked until TellWang's public app has the qualification and the subscription runtime has passed its migration canary.

A Shopline development store may keep its normal storefront password screen enabled. TellWang recognizes Shopline's same-store password redirect only to preserve the permanent store identity; it does not copy the redirect query or ask for the password during secure app connection.

Provisioning reserves the Preview Wok and its hostname; it does not make that hostname a website. Import shows the Preview link only after a frontend deployment has been verified. Until the Shopline importer reaches that stage, the dashboard says that the Preview website is still waiting for deployment instead of opening an empty host.

Shopline returns a signed, short-lived authorization code. TellWang binds the permanent store, Shopline shop ID, and merchant ID; stores the ten-hour Admin credential encrypted; renews it before expiry; and creates the app-owned Storefront API token automatically. Merchants do not paste either token into the dashboard. TellWang also verifies or creates the current-version uninstall subscription through Shopline's Admin API before committing the connection. Signed uninstall and mandatory customer/merchant redaction webhooks scrub or receipt the matching connection without retaining customer payloads.

Connection is ready before migration is ready. After authorization, the journey intentionally reports MIGRATION_SHOPLINE_SOURCE_IMPORT_PENDING. The live Shopline storefront remains untouched while the dedicated theme/catalog importer, compiler, Preview runtime, and parity suite are built and health-gated. Do not describe a connected Shopline journey as an imported or editable storefront yet.

WooCommerce (future)

WooCommerce live migration is outside the current product. The dashboard refuses to create or advance a WooCommerce live_transition. Do not generate a REST key, install a connector, configure webhooks, or change a WordPress origin for TellWang. A WooCommerce URL may still be used in Try it first for bounded public detection and capture only.

Hostname map

Hostname Before cutover After cutover
<wok-id>.tellwang.com Stable Preview Wok Can remain Preview; never the source API identity.
acme.com / www.acme.com Existing Shopify Online Store TellWang Wok only after a future owner-approved whole-host switch. It does not move during Preview acceptance.
<shop>.myshopify.com Shopify API/store identity Remains the Shopify API/store identity. Do not repoint it.
legacy.acme.com Verified Shopify Online Store fallback using the original published theme Remains live and unchanged through the rollback window. It must not redirect to the Wok or moved storefront hostname.
checkout.acme.com Optional Shopify checkout hostname Still points to Shopify.

The hostname attached through TellWang's Wok custom-domain connection controls public traffic and TLS. It does not replace the provider's source API identity, and it does not make a credential valid. TellWang verifies credentials and hostnames as separate gates. DNS moves the whole hostname once; later path-by-path migration is Wok routing, not DNS.

Credential lifecycles

Connection Lifecycle When it ends
Shopify migration OAuth retain_while_migration_depends One approval covers the full versioned contract. TellWang retains its encrypted connection and renews its rotating grant in the background for source refresh and the required near-launch source recheck. That recheck is not implemented yet and remains a production release gate. A new approval is needed only if renewal becomes impossible, the app is uninstalled or revoked, or the contract expands. Disconnect returns the same journey to Connect Shopify and requires a fresh capture and re-import; old capture or execution evidence is never reused. It also scrubs TellWang credentials and Wok bindings; uninstall the app in Shopify to finish provider-side cleanup.
Shopify Storefront API retain_while_runtime_depends TellWang retains its app-owned token while the Wok depends on Shopify. Disconnect or an uninstall event scrubs the runtime binding. Safe provisioning retries reuse the same token.
Shopify customer accounts retain_while_runtime_depends Classic follows managed Storefront access and retains only TellWang's sealed session key plus buyer-session cookies. New mode rotates the public client after Preview and production account journeys pass. Re-run detection if the merchant changes account type.

Secrets stay in the secrets backend. Migration state stores opaque connection references, never Admin tokens, consumer keys, connector credentials, cookies, cart tokens, or nonces.

What TellWang accepts today

Production currently keeps Shopify/WooCommerce public Tryout capture. This candidate adds Shopline to public capture and lets a customer-facing live_transition reach secure Shopline connection setup, but it is not active yet. Once the matching app, control plane, worker, and template are published together, a Shopify merchant can provide a public source host, attest migration authority, create a journey-unique pair or choose a fresh empty unassigned Preview, recover the journey, and begin its server-owned Shopify authorization action through the configured pilot app. Completing authorization creates one durable source-bound discovery capture. A complete route universe is divided into independently budgeted, digest-bound captures of at most 20 routes. Once representative home, product, collection, page, blog, and cart templates are captured, TellWang builds the editable Preview while the remaining route audit continues. Candidate evidence and launch remain blocked until every declared route completes; TellWang then replaces the sampled execution with the complete audit lineage automatically. Resume retries only failed segments. The control plane retains dormant WooCommerce application-authorization and WordPress connector-pairing foundations, but the server and dashboard cannot start or advance a WooCommerce live migration. Those foundations are not evidence that WooCommerce migration is available.

The candidate release can admit a Preview-only Shopify execution after Preview ownership, full migration OAuth, the managed Storefront runtime, the detected classic or new customer-account connection, all representative reference templates, and the signed template dependencies verify. A classic connection can complete without a public client, but that does not make the migration ready: merchant-assisted account/order/checkout evidence and exact account UI parity remain separate blockers. Once installed, the fixed leased worker imports Shopify MAIN, compiles the compatibility runtime, and deploys to Preview. An accepted candidate is hydrated into storefront/ in canonical Wok Git and deployed from that exact commit. Its receipt keeps the imported source, compiler gzip, Git export, Wok commit, and live-runtime digests separate. Visual definitions and retained assets remain editable; the generated server and commerce provider are protected so a design edit cannot silently replace product, cart, account, or checkout behavior. Failed activation reverts only managed Shopify paths and preserves unrelated Wok edits.

The worker captures that exact Preview against the sealed source segments. Before execution, Import lists Customer Accounts, each known app capability, and each genuinely unknown live API with its exact accepted adapter SHA-256. Multiple scripts, extension assets, proxies, and API calls from one known app appear as one capability; Shopify infrastructure, hCaptcha, and optional telemetry are covered by their owning flows. These bindings come from TellWang's authenticated root-owned registry; merchants never upload adapter modules or secrets. A missing adapter is platform-owned work and blocks admission while Shopify stays live. The pinned gate compares desktop/mobile pixels, DOM landmarks, document height, scroll reach and effects, interactions, console errors, and network failures. Commerce evidence must pass product view, variant selection, cart add/update/remove, search, Customer Accounts, Shopify-hosted checkout handoff, and every discovered app capability or unknown dependency. Missing, duplicate, stale, malformed, wrong-deployment, or failed evidence blocks the report.

After the initial candidate passes, every Git push of the imported Shopify source is only provisional until the authenticated loopback harness reruns the baseline-bound product, variant, cart, checkout, account, search, and discovered-dependency suite. TellWang stores signed evidence bound to the deployment, both Git revisions, runtime digest, and adapter hashes before acceptance. An unavailable harness, failed flow, or adapter drift restores the prior Preview; Shopify remains untouched. URL, SEO, accessibility, and merchant-specific payment canaries remain separate launch gates.

This is not a live Pretti5 migration: no merchant-authorized Pretti5 run has produced passing candidate receipts; no Pretti5 account, app-extension, checkout, or payment canary; merchant review; independent QA; DNS change; theme publication; or rollback drill has passed.

A completed capture is an oracle for implementation and comparison, not storefront code. It keeps migration_ready:false. Unknown platforms or dependencies, missing browser evidence, incomplete source streams, and route-cap exhaustion remain visible and block later parity claims.

Editable-Wok and cutover gate

production import gate
choose and sign the migration-run policy
→ approve the complete versioned Shopify migration contract once + attest source rights
→ stream and verify immutable source artifact
→ reconcile the complete route and dependency inventory
→ provision managed Shopify runtime access, configure accounts when required, compile, and deploy the complete Wok Preview
→ produce browser, session, and commerce evidence for the selected launch candidate
→ block every unknown environment or dependency
→ stop for owner review
→ edit visual Wok source and rerun the post-edit functional contract
→ keep hostname activation as a separate future approval

The release requires one signed published Shopify MigrationTemplate before admission and binds its exact workflow bundle, dependency-only base runtime, and parity profile to the tenant journey. Full-scope Shopify grants use the latest published immutable template. The captured-presentation release is 1.31.0 with the template-first 1.1.43 worker; older template receipts remain immutable. A copied theme's own scripts reach the Storefront API on the Wok hostname, and app scripts load from the vendor's own origin rather than the source shop's signed proxy, so browser cart mutations and app widgets work on the copy. Captured product pages recover their live Shopify variant, price, and availability state without replacing their editable layout, and the evidence probe reads that live selector before capture-redacted controls. Preview-local calls, Shopify's own storefront paths, captcha, and telemetry stay within their owning flows, while known vendor endpoints appear once under the corresponding app. A deterministic evidence mismatch or commerce failure stops for review instead of starting another complete capture. A Preview built before the exhaustive route audit finishes is clearly marked as audit-pending and cannot produce launch evidence. When the audit completes, TellWang upgrades it to the full immutable lineage without deleting the editable Preview. The source storefront's Shopify CDN resources stay on its authorized Shopify origin while internal navigation stays on the Preview. The source importer, compiler/runtime, fixed production worker, Shopify driver, Preview deployment bridge, candidate evidence producer, and parity verifier are wired behind that boundary. Pretti6 authorization, capture, source import, and grouped app preflight are active. Release still requires a deployed editable Preview that passes every browser, customer-account, cart, checkout, and configured-app journey before Pretti5 authorization or any separately approved hostname cutover. WooCommerce remains dormant and is not startable.

Before the initial host switch

No finite run proves every behavior of an arbitrary storefront. Reports must state the exact routes, states, environments, dependencies, browser conditions, and commerce journeys tested. Missing or unknown evidence fails closed.

This page is the merchant setup contract. The candidate release contains the Shopify authorization, managed Storefront runtime, detected account connection, complete segmented capture, signed-template admission, fixed-worker execution, compatibility runtime, exact Preview deployment, candidate evidence, parity verification, and editable Wok handoff. For current endpoint shapes and capture limits, read the API reference. No production Shopify migration template or authorized Pretti5 execution has been published or run.