Security and permissions

Reporting access, kept in its lane.

Marlo needs enough Partner API access to build app-business reports. It does not use that connection to alter merchant billing, plans or Partner configuration.

What the connection can read

Manage apps

Used to read app resources and lifecycle events such as installs, uninstalls and subscription changes.

View financials

Used to read transactions and payouts for revenue, fee, settlement and lifetime-value reporting.

01

Credential validation

The Partner token is checked directly against Shopify before Marlo accepts the connection.

02

Encrypted storage

The accepted token is encrypted before database storage. The product UI retains only a short identifying hint.

03

Organization isolation

Authenticated requests resolve through the active Clerk organization and the corresponding Marlo team before data is read or changed.

04

Role gates

Administrative actions—including connection changes, billing management and key creation—require owner or admin access.

05

Read-only MCP

MCP credentials are hashed, scoped to one team and expose reporting queries rather than mutation tools.

06

Visible coverage

Sync state, report ranges and incomplete transaction coverage remain visible so missing data is not presented as certainty.

No inflated badge wall

Claims should be as inspectable as the reports.

Marlo does not claim external security certification that has not been earned. The useful proof today is narrower: a validated credential, disclosed permission requirements, encrypted storage, authenticated team boundaries, explicit admin roles and local read-only agent access.

7 days free · Card required · Secure checkout by Stripe