Documentation Mercado Libre
Check out all the necessary information about APIs Mercado Libre.
Documentation
Security practices, validations and requirements for integrators
How to read this documentation
Each section includes:
| Element | Description |
|---|---|
| Why is it important? | Explanation of the risk and importance of using the best practice |
| Examples: correct vs incorrect | Visual comparison of what is right and wrong |
| How to verify? | Concrete steps to check whether you comply with the best practice |
| Self-diagnosis questions | Answer Yes/No to evaluate the adoption of the practice in your integration |
Governance and compliance
Introduction
Security Responsibility
Security in a service- and API-oriented architecture does not rest on a single actor, but is distributed under a shared responsibility model that delimits the obligations of Mercado Libre and those of the integrator. Mercado Libre assumes responsibility for platform security, which involves protecting the global infrastructure, data centers, network protocols, and the availability of API endpoints. This responsibility spans from the physical layer to the digital layer that hosts the marketplace services.
For its part, the integrator is responsible for security within its application and for managing the data it extracts or processes. This includes the security of their applications, the operating system configurations of their servers, the installation of security patches, the management of their databases, and access control to their internal systems. A security failure on the integrator's side, such as a misconfigured database or code vulnerable to injections, is the direct responsibility of the integrator. Transparency in this division allows both parties to focus their security resources effectively, ensuring that the protection of seller information is airtight throughout the entire data journey.