As of August 19, 2026. B2B Marshal's production configuration requests the 21 Shopify scopes below. Shopify access remains subject to platform eligibility, protected customer-data approval, restricted-scope approval, and the scopes actually granted to each installation.
Company and customer resources
read_customers,write_customers,read_companies, andwrite_companies: access Shopify business-customer Company and CompanyLocation resources; synchronize company/location identifiers, names, external IDs, counts, lifetime facts, B2B settings, and related summaries; and write B2B Marshal's app-owned company/location credit-projection metafields. B2B Marshal does not store or edit customer contact profiles, customer email, phone, or address fields.
Shopify's API can authorize Company and CompanyLocation resources through customer/company scope families. B2B Marshal requests the configured families for its B2B resource and app-owned metafield workflows; it does not use these permissions to market to customers or create a customer database.
Orders, refunds, transactions, and payment terms
read_orders: read B2B order identity, company/location association, timestamps, financial/fulfillment/return state, amounts, refunds, transaction timing/status, and payment schedules needed for exposure, aging, payment reliability, synchronization, and audit.read_all_orders: extend approved order access beyond Shopify's default recent-order window so full-history reconciliation can establish accurate account coverage. Without an approved and granted scope, B2B Marshal labels coverage as bounded and avoids destructive unseen-history cleanup.write_orders: authorizes Shopify order-resource writes. B2B Marshal's reconciliation of ordinary completed orders is read-only; it does not edit order totals, payment transactions, fulfillment, or customer data. Use of this scope is limited to documented B2B Marshal order-management purposes and remains subject to least-privilege review.read_payment_terms: read order and location payment-term templates, schedules, issued/due/completed timestamps, and balances needed to determine due and overdue state.read_draft_ordersandwrite_draft_orders: identify app-routed B2B review drafts and add or maintain the B2B Marshal review tag, concise merchant note, and app-owned review metadata. Ordinary drafts created directly in Shopify admin are not annotated by B2B Marshal.
Checkout resources
read_payment_customizationsandwrite_payment_customizations: read, create, update, enable, and repair the app-owned payment customization used for configured payment-method and eligible payment-term actions.read_delivery_customizationsandwrite_delivery_customizations: read, create, update, enable, and repair the app-owned delivery customization used for account shipping-option restrictions.read_validationsandwrite_validations: read, create, update, enable, and repair the app-owned cart/checkout validation used for credit holds, credit-policy blocks, order limits, and quantity rules.read_discountsandwrite_discounts: read, create, update, enable, and repair the app-owned automatic free-shipping discount and the combined ORDER + PRODUCT automatic discount used for company/location order-subtotal and product/variant-quantity tiers.
B2B Marshal keeps at most one app-owned Shopify resource per checkout capability rather than creating one resource per company.
Tiered discounts do not require customer contact fields. Shopify supplies the purchasing company/location and applicable cart-line inputs directly to the discount Function at checkout.
Products and shipping
read_productsandwrite_products: authorize product/variant identity reads and versioned app-owned product metafields for the validation architecture. Current static company/location quantity controls resolve from company/location projections. B2B Marshal does not edit product titles, descriptions, prices, inventory, images, or publication status.read_shipping: load active shipping/delivery option titles used in merchant policy editors and refresh them after delivery-profile changes. B2B Marshal does not requestwrite_shippingand does not edit Shopify delivery profiles or carrier-service configuration.
Protected customer data and minimization
Shopify treats order, draft-order, refund, transaction, and related data as protected customer data even when direct contact fields are omitted. B2B Marshal must receive applicable approval and uses selected financial/account fields for the stated exposure, reconciliation, policy, and audit purposes.
B2B Marshal does not request or store customer names, contact email, phone, billing/shipping addresses, product line-item descriptions, or payment card data for these workflows. See the Privacy Policy for the exact stored-data description.