How it connects

One approval, on the platform’s own screen.

The person who administers a store or a site approves the connection where they already sign in. Mawnitor asks for read access and nothing more.

  1. 01
    Register once.

    You register one app with Shopify, once. It connects every store you look after.

  2. 02
    Send a link.

    The store’s administrator opens it and approves on Shopify’s own screen.

  3. 03
    Reading begins.

    From then on, the theme is read on every pulse, walk and sweep.

  1. 01
    Send a signed link.

    Nothing is installed to start.

  2. 02
    Approve on WordPress.

    The administrator signs in to their own site and presses Approve on the application-password screen. That password works on the API only.

  3. 03
    Add the companion plugin.

    To read theme files: four read-only routes, nothing it sends anywhere on its own, no update channel.

Where the tokens live

Each connection’s token is sealed with AES-256-GCM and kept apart from the site record.

AES-256-GCM

If you were sent a link

Your agency uses Mawnitor to watch the site they look after for you.

Approving lets it read. You can remove the access at any time from your own Shopify admin or WordPress profile, and the site leaves Mawnitor when you do.

What it can see, in detail