Developer Center · Security

API Authentication

Handle authentication as part of the integration design: private credentials hear server-side, rights are supposed to be minimal, and store context should not implicitly leak.

Secrets

Never place private keys in browser code, public configuration or documentation.

Scopes

Give an integration only the rights that are necessary for its concrete task.

Rotation

Make key replacement testable and practicable without long-lasting failure.

Store isolation

Explicitly check that credentials and requests cannot work outside the intended store context.

Store isolation →