Install the app, then reveal the token
API credentials → Install app → Reveal token once
The Install app step is not optional and is easy to miss. Shopify only creates the access token at the moment the app is installed, so until you click it there is nothing to copy. Once installed, click Reveal token once and a string starting with shpat_ appears. Send that through a secure link rather than plain email or chat, the same way as the theme password above.
Three values look similar, only one is the right one
The API credentials screen also shows a Client ID and a Client secret starting with shpss_. Neither of those is what to send. They identify the app but cannot read anything from your store. The only value we need is the Admin API access token starting with shpat_. If you cannot see that section at all, the app has not been installed yet, so go back and click Install app.
If Install app is greyed out
That means no permissions have been saved yet. Return to the Configuration tab, tick the scopes in the previous step, press Save, and the Install button becomes available.
If the screen closes first
The token itself cannot be recovered, but the fix is quick. Uninstall the app and reinstall it from the same page, which issues a fresh one. About thirty seconds, and nothing is broken.