order:read or order:update and access to that shop. Dashboard permission ceilings still apply (viewOrders / editOrders).
List
order:read
Query:
Get
order:read
{orderId} may be the cuid id or the public ORD-… value. An order that belongs to another shop returns 404.
Detail adds seller note (human-readable only) and customFieldResponses. License key strings are not included — use dashboard fulfillment for that.
Update
order:update
Only the mutations the dashboard already supports:
note— same as dashboard order note (updateOrderNote)markDelivered: true— same as fulfillment “mark delivered” (paid/processing/completedwith deliverable content)
status values are rejected (400). Pending orders cannot be marked delivered. markDelivered: false is ignored as a no-op and returns 400.