ShopiPress · Security and data
Security and data
Use the public Storefront token, restrict administrative access and keep commerce and customer data in their authoritative systems.
01Use only the public Storefront token
Never paste a private Admin API credential into ShopiPress. The public Storefront token is used for catalog and cart requests. WordPress administrators who can manage ShopiPress should be limited to trusted users.
02System responsibility
Shopify remains responsible for products, inventory, cart, transactions and checkout. WordPress stores the synchronized publishing records. ShopiPress connects and renders them through the delivered contracts.
03Current security boundary
Use a ShopiPress package obtained from Freemius. Keep license keys, test credentials and backups outside the public web root.