TL;DR
You can own every pixel and ad account and still lose server-side tracking the day the agency leaves. The keys that let data in belong to whoever created them: the GA4 API secret to a data stream, a Meta token to some business's system user [5], the Google Ads connection to one person's Google login [3]. Each goes quiet differently, and GA4's never produces an error at all [1]. So the handover has an order: alarm on, swap, prove with a real order, and only then revoke.
Key Takeaways
- List every destination's credential and the account that issued it. On the free plan that's one item, the GA4 API secret [8]; on Plus it's one per connected destination, and one per pixel where a channel runs several.
- Create a fresh GA4 secret under Admin → Data Streams → your stream → Measurement Protocol and paste it into your tracking app before anyone deletes the old one [2].
- Generate the Meta Conversions API token from a system user in the client's own business, never the agency's [5].
- Reconnect Google Ads under a client-owned login, then re-pick the ads account and the conversion action. The reconnect alone sends nothing.
- Turn on a GA4 purchase alert before revoking anything, because GA4's Measurement Protocol reports no errors, even for a bad secret [1].
- Remove collaborator accounts only after every destination is proven with a real order. Shopify can't undo a collaborator removal [7].
The credential column nobody writes down
Who owns the Business Manager, the pixel and the ad account is settled in the agency standardisation guide, along with the per-store record. This is the layer underneath. Server-side tracking writes into those assets with a credential, and the credential has its own owner.
| Destination | What lets data in | Whose it is | Survives the agency leaving? |
|---|---|---|---|
| Shopify (the tracking app itself) | A store-level offline access token | The store | Yes, until the app is uninstalled [6] |
| GA4 | Measurement ID plus a Measurement Protocol API secret | The property's data stream | Yes, unless someone deletes or rotates the secret [2] |
| Meta | Conversions API access token | The business whose system user generated it [5] | Only if that business is the client's |
| Google Ads | An OAuth grant, sometimes through a manager account | One person's Google login | Only while that login and any manager link stay in place [3][4] |
| TikTok, Reddit, Pinterest, Snapchat, OpenAI Ads, Klaviyo | A token or key from each platform | The account that generated it | Only if that account is the client's |
The first row is the reassuring one. Shopify's documentation separates online tokens, which "are tied to the staff member who opened your app", from offline tokens, which belong to the store and stay valid until the app is uninstalled [6]. WeltPixel Conversion Tracking runs on the store-level kind, so removing the developer who installed it doesn't stop it.
Every other row can break on handover day. Open the app's settings and look at each connected destination; you've probably got one made by someone who hasn't worked with you in a year.
Why does a dead credential look like a quiet week?
Because none of these failures reaches the storefront. Orders keep coming in and the browser pixels keep firing. Only the server-side copy stops, in three different ways.
GA4 is the worst of them. Google's documentation says the Measurement Protocol "does not return HTTP error codes, even if an event is malformed or missing required parameters", and that its validation server "does not validate the api_secret" [1]. A sender using a deleted secret gets the same answer as one using a live secret, so no sending tool can see the difference, ours included. The app can check the secret's format on save and nothing more. The only place a dead secret shows is GA4 itself, as purchases that stop matching Shopify's orders.
Google also tells you to rotate that secret. The API reference describes it as "Private to your organization. Should be regularly updated to avoid excessive SPAM" [2]. An outgoing developer tidying up on the last day, doing exactly what Google recommends, can switch off your server-side GA4 purchases and nobody notices for weeks.
Token-based destinations fail more visibly. When you save Meta, TikTok, Reddit, Pinterest, Snapchat, OpenAI Ads or Klaviyo credentials, the app sends a test call to check them. A token that dies later makes sends fail, and the app counts those as failed in its accuracy figure. You'll see that figure when you open the app; nobody gets an email. The alerting guide covers what can alarm you.
Meta's setup page gives no expiry rule for Conversions API tokens, so plan around the owner: the token acts for whichever business's system user generated it [5].
What does a Google Ads connection depend on?
A person. The app connects to Google Ads through an OAuth grant from whoever clicked Connect, and the accounts it can upload to are the ones that login can reach. Google lists the ways a refresh token stops working, including "The user has revoked your app's access" and "The refresh token has not been used for six months" [3].
Agencies usually reach client accounts through a manager account. Google's rule for API calls is that "If your access to the customer account is through a manager account, this header is required and must be set to the customer ID of the manager account", and "The authenticated user must have access to this account" [4]. Together those mean that if the connection was made by an agency employee through the agency's manager account, unlinking that manager account or removing that person cuts the path the uploads take.
The fix has a trap in it. When you reconnect Google Ads under a different Google login, the app clears the selected ads account and conversion action, because the new login may reach different accounts. Until you pick both again, nothing goes to Google Ads, even though the connection itself looks fine. Your advanced options (Enhanced Conversions, the admin-order exclusion, the no-click-ID upload) are kept through the reconnect.
A revoked grant is caught when someone checks or re-enables the channel in the app. Between those moments, uploads just fail.
Swap, prove, then revoke
Run this while the outgoing team can still answer questions. If they also edited the theme, run the theme-change triage too; if the tracking app is changing as well, the app-switch guide sets that cutover.
- Turn on the GA4 purchase alert. It watches GA4 itself, the only place a dead secret shows, so it goes on before anything changes.
- Swap every credential for a client-owned one. In GA4, go to Admin → Data Streams → your stream → Measurement Protocol, create a new secret and paste it into the app [2]. For Meta, generate a token from a system user in the client's business (the Meta Conversions API setup guide walks the screens). Reconnect Google Ads under a client-owned login and re-pick the account and conversion action. Regenerate the rest from client-owned platform accounts.
- Place one real order and prove each destination.
| Destination | Where to look | What proves it | When |
|---|---|---|---|
| Meta | Events Manager, the client's dataset | Purchase received from the server | Same day |
| Google Ads | The conversion action you re-picked | The order counted as a conversion | Hours later (why early zeros mislead) |
| TikTok, Reddit, Pinterest, Snapchat, OpenAI Ads | Each platform's events view | The purchase received server-side | Same day |
| Klaviyo | The customer's profile, activity log [9] | A Placed Order event | Same day |
| GA4 | Reports → Monetization → Overview [10] | Purchases tracking Shopify's order count | Over the following days |
- Only then revoke. Remove the agency's collaborator accounts. Shopify warns that removal is permanent ("You can't undo this action"), and Settings → Users → Security → Collaborators has a "Generate new code" button that makes old request codes stop working [7]. Ask the agency to delete its old tokens and unlink its manager account at the same time.
- Recheck GA4 against Shopify a week later. A gap that opens on the revoke date points at a credential still tied to the old owner.
Every credential in WeltPixel Conversion Tracking [8] lives in the store's own app settings, per destination, so a handover is a swap and a test order rather than a rebuild. For the broader post-change pass, the 10-point checklist covers what this one leaves out.
FAQ
Does removing a collaborator account stop my tracking app?
Removing the person doesn't stop an app that runs on a store-level token, which lasts until the app is uninstalled [6]. What can stop is any destination credential that person's own accounts issued, such as a Google Ads login or a Meta token from their business.
How do I know if my GA4 API secret stopped working?
Only from GA4 itself. The Measurement Protocol returns no errors for a bad secret and its validation server doesn't check the secret [1], so compare GA4 purchases with Shopify orders and set a GA4 alert on purchases.
Should I rotate the GA4 API secret when an agency leaves?
Yes, if they had access to it; Google recommends regular rotation anyway [2]. Create the new secret, paste it into your app, confirm purchases still arrive, then delete the old one.
Why does Google Ads show connected but record nothing after a reconnect?
Reconnecting under a different Google login clears the selected ads account and conversion action. Pick both again, and allow several hours before judging the result.
Sources
- Google for Developers, "Validate events" for the GA4 Measurement Protocol (no HTTP error codes; validation server does not validate
api_secret), developers.google.com/analytics/devguides/collection/protocol/ga4/validating-events, accessed September 28, 2026 - Google for Developers, GA4 Measurement Protocol reference (
api_secretlocation and rotation advice), developers.google.com/analytics/devguides/collection/protocol/ga4/reference, accessed September 28, 2026 - Google for Developers, "Using OAuth 2.0 to Access Google APIs" (refresh token expiration), developers.google.com/identity/protocols/oauth2, accessed September 28, 2026
- Google Ads API, "API call structure" (
login-customer-idvia a manager account), developers.google.com/google-ads/api/docs/concepts/call-structure, accessed September 28, 2026 - Meta for Developers, "Get started" with the Conversions API (system users and token generation), developers.facebook.com/docs/marketing-api/conversions-api/get-started, accessed September 28, 2026
- Shopify developer documentation, "Access tokens" (online vs offline tokens), shopify.dev/docs/apps/build/authentication-authorization/access-tokens, accessed September 28, 2026
- Shopify Help Center, "Collaborator accounts" (removal, new request codes), help.shopify.com/en/manual/your-account/users/security/collaborator-accounts, accessed September 28, 2026
- WeltPixel Conversion Tracking, Shopify App Store listing (free plan covers GA4; Plus $39/month for all nine destinations), apps.shopify.com/weltpixel-conversion-tracking, accessed September 28, 2026
- Klaviyo Help Center, "Understanding profiles in Klaviyo" (profile activity log), help.klaviyo.com/hc/en-us/articles/115005247088, accessed September 28, 2026
- Google Analytics Help, "Monetization overview report", support.google.com/analytics/answer/13409465, accessed September 28, 2026