Manage apps
Used to read app resources and lifecycle events such as installs, uninstalls and subscription changes.
Security and permissions
Marlo needs enough Partner API access to build app-business reports. It does not use that connection to alter merchant billing, plans or Partner configuration.
What the connection can read
Used to read app resources and lifecycle events such as installs, uninstalls and subscription changes.
Used to read transactions and payouts for revenue, fee, settlement and lifetime-value reporting.
The Partner token is checked directly against Shopify before Marlo accepts the connection.
The accepted token is encrypted before database storage. The product UI retains only a short identifying hint.
Authenticated requests resolve through the active Clerk organization and the corresponding Marlo team before data is read or changed.
Administrative actions—including connection changes, billing management and key creation—require owner or admin access.
MCP credentials are hashed, scoped to one team and expose reporting queries rather than mutation tools.
Sync state, report ranges and incomplete transaction coverage remain visible so missing data is not presented as certainty.
No inflated badge wall
Marlo does not claim external security certification that has not been earned. The useful proof today is narrower: a validated credential, disclosed permission requirements, encrypted storage, authenticated team boundaries, explicit admin roles and local read-only agent access.
7 days free · Card required · Secure checkout by Stripe