--- url: https://docs.youcan.shop/changelog/metafield-write-rules.md --- Only apps can create, update or delete metafields, and only in the namespace equal to their app handle. *** # Metafield write rules * Create, update and delete need a token that belongs to an app. Other tokens get HTTP 403 with `only apps can write metafields`. * An app writes only in the namespace equal to its app handle. A write in another namespace gets HTTP 403. * Reading metafields is unchanged. * The MCP server reads metafields and no longer writes them. * See [Metafields CRUD](/store-admin/metafields/crud).