Security and API credentials
Connecting a store means trusting Trajekt with a read-only credential. Here's how those are handled and how to keep your connections secure on your side.
Read-only by design
The connections Trajekt asks for are read access to your catalogue and inventory. It doesn't need — and you shouldn't grant — write access to orders, customers or checkout. A read-only custom app can't change your store.
How credentials are stored
Your API tokens are stored to run your feeds and aren't exposed back to the browser once saved. You can update or remove a credential at any time from the feed's settings, which immediately stops Trajekt from reading that source.
Best practice on your side
- Grant the minimum scopes needed — products and inventory read, nothing more.
- If a colleague leaves, rotate the token in your platform and paste the new one into Trajekt.
- Use individual team logins rather than sharing one account.
Your data
Trajekt reads your product data to build feeds. See our privacy policy for how data is handled. If you have specific security questions, contact us.