Connecting AllHub does not touch a single line of your store: how it really works

AllHub Team3 min read

Most store owners ask the same sensible question before connecting anything: “If I connect AllHub, what are you going to put inside my store?” The answer is simple: nothing.

No plugin, script, server file or line in your theme. This is not a request to trust a promise. AllHub is designed to work without asking for the route that would allow it to install that code.

A secure connection between AllHub agents and an online store without installing codeAI-generated content
The connection reads the information it needs; it does not install code or change your storefront.

Why does it matter that we install nothing?

Anyone who has run an ecommerce store knows the pattern: an abandoned plugin, an extension asking for excessive permissions or a script that becomes a vulnerability. They all depend on code installed inside the store.

The useful question is therefore: “Can this provider write code inside my store?” AllHub cannot. We do not request permission to edit a Shopify theme, and we upload no file or plugin to WooCommerce. That door is not part of the connection.

How does AllHub connect to an online store?

AllHub reads the catalogue through the official routes provided by Shopify, WooCommerce, Wix and Amazon for external services. It is the documented access each platform provides and controls, not a back door.

You create the connection from your platform’s own admin and can revoke it there. We use the authorised information to prepare a working copy of the catalogue in Europe so the agent can answer shoppers quickly.

  • Shopify: uninstall the app from your admin.
  • WooCommerce: delete the key under WooCommerce → Settings → Advanced → REST API.
  • Wix: revoke the API key from your dashboard.
  • Amazon: withdraw the authorisation in Seller Central.

What happens when a shopper wants a product?

The Conversational Storefront Agent helps shoppers find products in natural conversation. It can show options, variants, prices and availability, then prepare the wishlist or cart the shopper requested.

AllHub’s role ends there. Once the selection is ready, the shopper goes to your store’s checkout. AllHub does not charge, process the payment or receive the money. Your store charges the customer, confirms the order and sends tracking information.

AllHub supports discovery and selection. Checkout, payment and tracking remain with the store.

Creating that cart is the one exception to catalogue reading, and it happens only because the shopper asks for it. It cannot change products, prices, stock, customers, existing orders or your theme.

What happens to the information on AllHub’s side?

How are credentials protected?

Credentials are encrypted and separated for each account. Where the platform allows it, temporary permissions expire automatically and have a narrower scope than the original credential.

Can an agent invent a new action?

No. Every action is drawn from a fixed, reviewed allowlist. Anything outside it is rejected before reaching the platform. External content is also filtered to reduce prompt-injection risk. Stores are isolated, relevant events are logged, and store data is stored in the EU.

What can each agent read, and what can it never touch?

AllHub is not a black box with total access. Every agent has a narrow job and receives only the information needed to do it. Reading data to prepare a recommendation is not permission to change the store.

Narrow permissions: reading what is needed is not controlling the store.

Conversational Storefront Agent

It reads public catalogue data and helps the shopper choose. It cannot access margins or customer lists, change the store or handle payment.

Store Brain Agent

It analyses aggregate store figures and shopper question categories. It can recommend an action, but cannot change prices, launch campaigns or edit product pages.

Demand Forecast Agent

It reads sales history and stock levels to produce forecasts. It cannot replenish inventory, place supplier orders or make decisions with your money.

Research, Competition and Reputation Agents

Research and Competition read public external sources. Reputation analyses reviews and prepares drafts, but cannot publish on your behalf or write changes to your store.

Which principles limit the connection?

  • Sovereignty. Your catalogue remains yours, and you can disconnect from your platform.
  • Least privilege. Each agent receives the narrowest permission it needs.
  • Reversibility. You can revoke access without waiting for our team.
  • Honesty. We explain concrete exceptions and limits instead of promising absolute security.

In summary

Connecting AllHub changes no code in your store. It reads the information needed to turn the catalogue into a conversation, help shoppers find products and prepare their selection.

The money, checkout, order confirmation and tracking stay with your store. If you disconnect AllHub, there is no plugin to maintain, script to remove or theme to repair.

Your store remains your store before, during and after connecting AllHub. We help shoppers find what they want; you keep control of the purchase, payment and customer relationship.

Written by AllHub Team · AI Agents for Ecommerce

We build the AI agent team that sells, supports and grows ecommerce stores — EU-hosted, GDPR-first.

This article was created with the help of AI and reviewed by our team. We take great care over every post and every translation, but the odd mistake can still slip through. If you find one, write to us: you will be helping us improve.

Keep reading

Is it safe to connect AI agents to your online store? | AllHub