Proactive security hardening
Following recent security news in the Shopify app space, we strengthened how install tracking is authenticated, including optional signed requests.
Why we built it: when a security incident hit another Shopify affiliate platform, we chose to get ahead of it rather than wait.
Security is something we would rather be early on than catch up to. After a recent incident elsewhere in the Shopify app space, we ran a proactive review and tightened how PartnerDock authenticates install tracking.
Among the changes, you can now send install reports as a signed request, so your tracking token never has to travel over the wire. It is optional and fully backward compatible, so nothing you have already set up needs to change. If you would like to adopt it, the steps are in our click-tracking guide.
Most of this happens quietly in the background. Your program keeps running exactly as before, with an extra layer of protection.
