Marketplace Connection Security and Data Policy

Official API & Authorised Integration Guide

Marketplace Connection Security and Data Policy

Credential encryption, access controls, webhook validation, logs and data retention policy.

Credential security

  • Sodium secretbox is preferred.
  • AES-256-GCM is used as fallback.
  • WordPress salts derive the encryption key.
  • Secrets are masked in admin and logs.

Data isolation

  • Connections, jobs, events and logs are user/company scoped.
  • Disconnect removes locally stored credentials.
  • Log retention is configurable.
Last updated: 09 Oct 2026 · Live connection depends on seller credentials, API scopes and platform approval.
Scroll to Top