Which Shopify permissions does Atomato request, and why?
The Shopify permissions Atomato requests at install, grouped by the feature that uses them, with the full scope list.
Atomato asks Shopify for a set of permissions, called access scopes, when you install it. Each one is listed below by its Shopify name, such as read_orders, under the feature that uses it.
Campaign content and results
-
read_metaobject_definitions,write_metaobject_definitions,read_metaobjectsandwrite_metaobjects: Atomato saves each message's content, such as its title and description, in your store as metaobjects, and reads it back with any translations. -
write_pixelsandread_customer_events: Atomato adds its web pixel to your store when you install it. The pixel records how shoppers interact with Atomato messages and, after a shopper clicks a campaign, their add to cart and checkout events.
Shopify decides when the pixel runs. See how Atomato works with Shopify's customer privacy settings.
Customers and segments
-
read_customers: search customers for Specific customers, list segments for Specific customer segments, and check whether a signed-in shopper belongs to the segments a campaign targets. -
write_customers: when you install Atomato, it creates five customer segments whose names start with Atomato.
Orders, reports and discounts
-
read_orders: Shopify sends Atomato each new order that includes a product added from NotiSell. Atomato also reads NotiSell orders, and orders that used a NotiEmail signup code, to report them on Analytics. -
write_orders: Atomato tags those NotiSell ordersnotisell, plusnotisell-followed by the ID of the NotiSell message the product came from. -
read_reports: Shopify's reports supply the store figures on Create campaign, such as sessions, Total store revenue on Analytics, and the sales and stock rankings behind NotiSell's Method options. A background job also regularly reads your store's session count for the month and saves it with your Atomato plan details to track plan usage. -
read_discountsandwrite_discounts: in a NotiEmail Success step, Add discount lists your store's discounts so you can pick one. With Unique coupons, Atomato creates and tags a single-use code from that discount for each email address that signs up. NotiSell's Offer incentive creates an automatic discount.
Products, pages, files and languages
-
read_products: product search and Browse in NotiSell, the Cart products targeting rule, products and collections for a Button link, and the product details for NotiSell's Method options. -
unauthenticated_read_product_listingsandunauthenticated_read_selling_plans: Atomato creates a Storefront API token named Atomato Storefront Access Token when you install it. Your storefront uses it to load NotiSell product cards, with variants, prices and subscription options. -
read_content: find your store's pages for a Button link. -
read_files: show your store's images under Select from Files. Images added with Upload new file are saved to your Files. -
read_locales,read_translationsandwrite_translations: list your languages, save what you translate in Settings > Translations, and show shoppers campaign text in their language.
Themes
-
read_themes: list your themes during setup and in Theme Launcher, and check whether the Atomato app embed is on. -
write_themes: Theme Launcher publishes the theme you choose under During event at the start time. If you tick Enable theme switching once the event has ended., it publishes the After event theme at the end time.
Who can use this access
Atomato does this work with your store's access, not each staff member's Shopify permissions. Anyone you let open Atomato can use NotiSell's Offer incentive or Theme Launcher, even if their Shopify account can't manage discounts or themes. See Set up Atomato for a team or agency.
What these permissions don't cover
Connecting Klaviyo, Mailchimp, Omnisend, Drip or SKIO uses an API key you create in that platform, not a Shopify permission. See where Atomato uses your integration API keys.
When you uninstall, Atomato doesn't remove the customer segments or order tags it created. See what happens to your data when you uninstall Atomato.
Full list of scopes
Atomato's install request contains these scopes: unauthenticated_read_product_listings, unauthenticated_read_selling_plans, read_reports, read_customers, read_discounts, read_files, read_inventory, read_locales, read_locations, read_metaobject_definitions, read_metaobjects, read_orders, read_products, read_content, read_themes, read_translations, write_customers, write_discounts, write_metaobject_definitions, write_metaobjects, write_orders, write_products, write_themes, write_translations, write_pixels and read_customer_events.
Was this article helpful?
1