The secret never travels over the network
AliExpress authentication is signature-based: your app secret is not sent inside the request, only used to produce its signature. That is an important difference from platforms like Mirakl that send the key raw — even if the key leaked, it could not be read from network traffic. On the Stokzone side it is stored encrypted and never shown again after entry.
The access and refresh tokens are obtained during authorisation and renewed automatically on expiry; no manual intervention is needed. The optional seller ID field is used to map incoming notifications to the right shop — with a single shop it can be left empty.