简体中文
Getting started

Trust model

Understand the public documentation, platform, store, installation, user, and provider trust boundaries.

Trust model

Authorization is the intersection of platform capability, app approval, immutable app version, active installation, store and market binding, granted OAuth scopes, current user or service role, legal consent, and rate/risk policy. A permissive Origin or successful CORS preflight grants none of these.

Sandbox and production have separate installations, credentials, events, quotas, mappings, and fulfillment intents. Sandbox requests cannot change production inventory, orders, or delivery state.

All resource identifiers remain server-authoritative. A client-supplied tenantId, storeId, userId, scope, product ID, or provider reference is only a lookup key and never proof of ownership.

Copyright © 2026