Skip to main content
An app’s settings page holds everything that identifies it and connects it to the outside world: its profile, its Shopify credentials, its Meridian SDK credentials, its repository, its Slack workspace, and its email sender.

App profile

The name, description and logo your team sees across the organization. Editable at any time. This page stays open on an app with no plan (one never chosen, a pick waiting for its payment, or a free trial that ended), while the app’s other pages show a “choose a plan” screen. You can still rename the app, change its description, visibility and logo, and cancel it. Its Summary shows No plan with a link to choose one, and the capacity block is left out until there is a plan. The pages under it (domains, email, SDK, integrations) stay closed until then. A suspended organization closes this page too. The Summary panel beside it shows the app’s Hosting (the hosting its plan includes, as “Included with ”, or its Medium or Large upgrade with the price) and its App plan, each with a Change link to its change page for members with Billing: Manage. When the plan or the hosting is set to change at the renewal, the row says what it becomes and when.

Visibility

Whether the app is public or private (see App types). New apps are public. Anyone who can edit the app switches it here, and the change is saved right away, apart from the page’s Save button. It never changes the price. The Summary panel on the right says what the current type gives the app, here and on the create page, where it follows the choice as you switch:
  • Public: for any merchant. Stores (CRM), segments, analytics and reports, emails, automations, plan builder, affiliates and the App Store listing, on top of hosting, database and deploys.
  • Private: for your own store or one merchant’s stores (a custom app). Hosting, database and deploys only. The merchant features are off.
  • Private to public only unlocks features, so it applies at once.
  • Public to private turns live merchant features off, so a dialog lists exactly what stops before you confirm:
    • email sends stop, and calls to /emails/send from the SDK in your merchants’ stores start failing;
    • automations stop: no new run starts, and runs waiting on a delay end without sending;
    • Plan Builder, usage and discounts close, and their API calls are refused;
    • stores (CRM), segments, analytics and reports on store data close;
    • affiliates close;
    • the App Store listing and keywords close, and connecting Shopify is no longer offered.
Nothing is deleted when an app goes private. Its emails, automations, plans and store data stay where they are, and switching back to public turns them on again. A run that ended during the private period is not replayed.

Shopify connection

Connect a Partner organization and app so Meridian can publish to Shopify and read Partner data: the numeric organization ID from your partners.shopify.com URL, plus your app’s credentials. The card shows whether the connection is live, and surfaces a failed attempt rather than hiding it. Disconnecting is available from the same place. Two Shopify credentials are stored here and injected into every environment at deploy time, so your code reads them from the environment instead of holding them: The client secret is write-only: enter it to replace it, and Meridian never shows it back.

Partner API access token

Meridian reads your installs, charges and refunds through the Shopify Partner API, so the connection needs a Partner API access token (it starts with prtapi_). To create one:
  1. In the Partner Dashboard, open Partner settings → Partner API clients → Manage Partner API clients.
  2. Click Create API client and tick the Manage apps and View financials permissions. Create it in the same Partner organization as your app.
  3. Copy the client’s Access token into the connection form.
Only organization owners can create Partner API clients. Without Manage apps, Meridian cannot read app events. Without View financials, the daily transaction sync fails, refunds are missing from MRR and affiliate commissions stop accruing. See Shopify’s guide to Partner API clients.

Meridian SDK credentials

The credentials your app uses to call Meridian’s public API and verify webhooks:
  • Meridian app ID: identifies the app to the SDK. Not a secret; safe to keep in your code.
  • Meridian API key: a server-side secret (mrd_sk_…), shown once when it is created or rotated. The settings page lists every live key with when it was last used and when it expires.
Rotate mints a new key and keeps the previous one working for 7 days, so you can redeploy without downtime. Watch last-used move off the old key, then revoke it early, or let it expire. Revoke stops a key immediately. Use that only for a leak. The API key is what the server SDK and the custom field values API authenticate with. It must never reach a browser, an app bundle, or a Shopify theme. On Meridian hosting, deploys automatically create and inject a separate hosting API key. The card continues to show only your dashboard keys. Rotating here starts the 7-day overlap window for both dashboard and hosting keys, so redeploy your hosted environments before they expire. The next deploy creates a new hosting key automatically. See Credentials and environment.

GitHub repository

The connected repository Meridian builds from, on the GitHub card of the Integrations page. The card names the linked repository, and Configure shows it with Disconnect above the flow to switch to another one. See Github.

Slack workspace

The workspace the Send Slack message automation action posts into. Connecting opens a standard Slack authorization screen; no token to paste, no Slack app of your own to create. If that screen notes the app is not approved by Slack, that’s Slack’s wording for any app distributed outside its Marketplace, not a problem with the connection. See Send Slack message. The card shows the connected workspace’s name, surfaces a broken connection (a revoked authorization, for example) rather than hiding it, and offers disconnect from the same place. One workspace per app. The same workspace can serve any number of apps, in this organization or in others, and disconnecting one app never affects the rest. The channel a flow posts to is picked per step, in the flow builder.

Email sending domain

Which sender this app’s automation emails go out from: the Meridian platform sender, or one of your organization’s verified sending domains. Domains that haven’t verified yet are listed but can’t be selected.

Cancelling an app

Cancelling is how you stop paying for an app, the same way a downgrade works: it takes effect at the end of the period you have already paid for. From More actions on the settings page, choose Cancel app. To confirm, Meridian emails a 6-digit code to the person asking. The code works once and expires after 15 minutes; nothing happens until it is entered. Cancelling needs the Applications: Delete permission, which owners and admins have by default. Once confirmed:
  • The app’s plan, hosting upgrade and runtime add-ons stop renewing right away. There is no refund for the days left, and the dialog and the confirmation email both show the exact date.
  • The app keeps running as before until that date. Its Shopify connection, stores and analytics keep working; nothing needs to be disconnected first.
  • A smaller plan or hosting size you had scheduled for the renewal is set aside with the cancellation, so the renewal never moves an app that is about to be deleted. The cancel dialog names it.
  • Until that date, Keep the app (on the settings page or the app’s billing page) undoes the cancellation at no cost. It asks for a confirmation first, like every other Keep, and the dialog lists what comes back. Every line renews as before, and the smaller plan or hosting size set aside is scheduled again for the same renewal. If one can no longer be scheduled (its price no longer makes it a downgrade, for example), the app is still kept and a message says to schedule it again from the app’s billing page.
  • While the app is cancelled, its plan and hosting cannot be changed, no capacity or top-up can be bought for it, and its hosting upgrade and add-ons cannot be kept on their own: Keep the app renews them together. Keeping the app needs the same Applications: Delete permission as cancelling it.
  • On that date, Meridian first builds an export of the app’s data and emails a download link to the organization’s owners. Only once the export is safe are the app’s hosting resources released and the app deleted for good: its stores, contacts, events, plans, emails, automations and logs leave Meridian’s database along with it. There is no undo after that date.
An app with nothing paid for that has to run out (no plan, or a free trial) is deleted right away instead, after the same export. While a renewal payment is unpaid, apps cannot be cancelled: update the payment method first, and the app stays exactly as it is meanwhile.

The export

The export is the same zip as the organization’s data export, scoped to the app: a dump of each of its databases taken at the moment of the deletion, its CRM (stores, contacts, subscriptions and usage events) as CSV files, and its configuration (plans, features, events, email templates, automations and segments) as JSON. It stays downloadable for 90 days after the deletion, then it is deleted too. The owners’ email links to the download; anyone in the organization whose role can export its data can open it. The download link itself is created when you click, so nothing in the email can expire or be reused. The files in the app’s object storage are not in the zip: they are kept aside for the same 90 days, and support can hand them over.
Last modified on October 6, 2026