Access and safety
Access levels
What each access level allows
| Read-only | Full access | Settings changes | |
|---|---|---|---|
| View members, points, tiers, rewards, referrals, analytics, storefront setup | ✓ | ✓ | ✓ |
| Award, deduct or correct points; redeem or refund rewards; change a member's tier; create referral invites; switch to the new analytics | ✓ | ✓ | |
| Edit your loyalty page design and text | ✓ | ✓ | |
| Create or edit earning rules, rewards, VIP tiers, referral rewards, widget design and shop settings | ✓ (local server) |
With sign-in, you choose Read-only or Full access on the approval screen. Settings changes
are an extra local-server option, not a third sign-in level. With an API key, the key and the
JOY_MCP_ENABLE_* settings decide.
Built-in safeguards
- Your key stays in Joy when you connect with sign-in. The AI tool holds a 5-minute access token and a sign-in that renews while you use it, until you disconnect it or leave it unused for 30 days.
- Read-only means read-only. With sign-in, change tools aren't offered on a read-only connection. A read-only key is refused on every change, whatever the local settings say.
- Previews before big changes. Balance corrections, settings changes, and deductions over 1,000 points or below a zero balance are built to preview first: the assistant shows the result and has to call again to apply it. Your AI tool's approval prompt is the final check.
- A reason for manual point and tier changes. Awards, deductions, corrections, coupon refunds and tier moves need a reason, saved in your Joy activity log next to the change.
- Retry-safe point changes. If an award, deduction or correction times out, the assistant retries with the same key, so Joy applies it once. Asking again in a new message is a new change.
- Store labels. With sign-in, every result Joy sends the assistant is labelled with the store's name and domain. If you use several stores, ask which store an answer came from.
Double-check these before you approve
- Redeeming a reward creates a real discount code and can take up to 30 seconds. If it times out, check the member's activity before trying again.
- Refunding a coupon returns the points automatically. Don't also ask for the points back, or the member gets them twice. If a refund times out, check before retrying.
- A referral invite for someone who isn't a member creates a real Shopify customer and may trigger sign-up rewards. Check the email address: a typo creates an unwanted customer record.
- Loyalty page text changes go live right away, with no preview. Editing your main language also re-translates those lines into your other languages, replacing hand-written translations.
- Loyalty page design changes save as a draft unless you ask to publish, but program and tier icons go live right away, including in emails and the membership card. Reverting undoes only the most recent change, restores the design to your draft, and discards edits made in the Joy admin since then.
- Settings changes can't be retried safely. Asking twice to create a reward creates two rewards. Check the admin if a request seems to fail.
- Widget changes save as a draft by default. If you ask for a live change, it can't be undone.
Manage connections
See what's connected. Every app you approved with Remember this and skip this screen next time ticked is listed in Settings → Developers → AI connections, with its access level. Apps other than Claude, Claude Code, ChatGPT and Codex may show a technical ID instead of a name.
People who connect the same AI tool to the same store (for example two Claude accounts) share one entry. It shows the last access level approved, and Disconnect cuts them all off.
Disconnect. Select Disconnect next to the app. The app can't reconnect without your approval, and any access it still holds expires within 5 minutes. To reconnect, repeat the setup steps.
Change the access level. Disconnect the app, then connect it again and choose the other level.
Regenerating keys in Manage keys stops local (API key) setups that use the old key. It doesn't disconnect sign-in connections — use Disconnect for those.