Keep integrations and credentials safe
Understand which installation details are public and which authentication or payment credentials must never enter a storefront.
An embed is not an administrator credential
A public widget identifier is used to load a customer-facing experience. It is not permission to manage accounts, billing, or private conversations. Use only the dashboard-generated public installation code in your store.
Keep secrets off the client
Never paste database credentials, private API keys, payment secrets, session cookies, or internal service tokens into a theme, tag manager, browser console snippet, or support screenshot. Do not reuse example code from an unverified source.
If something was exposed
Remove the exposed material from the public location and notify the responsible administrator or provider so credentials can be revoked or rotated. Removing a screenshot does not invalidate the secret it contained. Use a private support channel and redact unrelated customer information.
Dashboard labels may currently be in German. Available controls and modules depend on your package and release. If a control described here is missing, check your workspace or contact support.
Still need a hand?
Tell us what you’re trying to do. Please leave out passwords and personal customer data.