One page checkout API developer asked full store access

Bmax
Visitor
1 0 0

What access of the store is a NO NO for any API?

I have been trying to get this Breeze.in one-page checkout installed.

The developer then asked me to give the whole store access which I found weird and unsafe. I want to know how i make sure that I am not sharing my store analytics etc with API which can use this to its advantage if they have a similar flagship store like mine

Currently, I have given them the following permission in the API configuration. Any help is greatly appreciated.
Screen Shot 2024-03-13 at 00.40.06.pngScreen Shot 2024-03-13 at 00.40.17.pngScreen Shot 2024-03-13 at 00.41.22.pngScreen Shot 2024-03-13 at 00.44.09.png
Replies 0 (0)