Secrets
Never place private keys in browser code, public configuration or documentation.
Handle authentication as part of the integration design: private credentials hear server-side, rights are supposed to be minimal, and store context should not implicitly leak.
Never place private keys in browser code, public configuration or documentation.
Give an integration only the rights that are necessary for its concrete task.
Make key replacement testable and practicable without long-lasting failure.
Explicitly check that credentials and requests cannot work outside the intended store context.
Store isolation →