A shipping account touches customer addresses, carrier agreements, and billing — here is how ShipCelero protects it and what you can do yourself.

Sign-in and sessions

Authentication is handled by a dedicated identity service (Auth0). Use a strong, unique password, and sign out on shared computers using Sign out in the sidebar. If you suspect your password has leaked, change it under Settings → Account → Login password immediately.

Roles limit access

Give each team member their own login with the least role they need — most people only need User. Reserve Customer admin for those who manage billing, integrations, and the team. See Team members.

Carrier credentials

Carrier credentials are stored encrypted and are never shared with anyone but the carrier itself. Removing a carrier integration under Settings → Integrations stops all new bookings with it immediately; existing shipments are unaffected.

MCP API key hygiene

  • Treat your MCP key like a password — it is shown once and stored only as a hash
  • Give keys the fewest permissions that work; label creation is off by default for a reason
  • Check Last used under Settings → MCP API Access — revoke keys you no longer use
  • If a key may have leaked, revoke or regenerate it — the old key stops working immediately

Label links

Label download links handed to MCP clients are signed and expire after about 15 minutes, so a shared link does not stay usable forever.

Integration access

Shopify, Etsy, and WooCommerce connections only get the access they need for orders and tracking. You can disconnect them at any time from Settings → Integrations (Etsy also from your Etsy account's connected apps).

Reporting a security issue

If you discover a vulnerability or suspect unauthorised access to your account, email support@shipcelero.com right away with as much detail as you can. Please do not test vulnerabilities against other customers' data.