Security requirements
Non-negotiables for every published app.
Credentials
- Client secrets, refresh tokens and webhook secrets live server-side only.
- Never log tokens. Redact
Authorizationheaders. - Rotate credentials immediately if a laptop, repo or CI secret is exposed, and tell us.
- MFA is enforced on your developer account before live keys are issued.
Data handling
- Store only what your feature needs, and say so in the listing.
- Delete a merchant's data within 30 days of uninstall unless retention is legally required.
- Never resell or share merchant data, and never use it to train models without explicit written consent.
- Honour deletion requests raised through the dashboard within the stated deadline.
Transport
- HTTPS everywhere; TLS 1.2 minimum.
- Exact-match redirect URIs, PKCE for every authorization.
- Verify webhook signatures with a constant-time comparison.
Operational
- Alert on
401/403/429spikes and webhook failures. - Keep an incident contact reachable; we use the support email on the listing.
- Report a suspected breach affecting merchant data within 24 hours.
Violations lead to the app being unpublished and, in serious cases, the organization being suspended.