Sécurité
Recommendations to keep your integration safe.
Key management
- ✅ Store keys in environment variables
- ✅ Rotate keys every 6 months
- ✅ Use separate keys for test and production
- ❌ Never hardcode keys in your source
- ❌ Never commit keys to Git
- ❌ Never send the secret to a browser or mobile app
Transport
- ✅ TLS 1.2 or higher
- ✅ Verify SSL certificates on your HTTP client
- ✅ Use HTTPS for your webhook URL
Server security
- ✅ Keep your dependencies updated
- ✅ Rate-limit your public endpoints
- ✅ Log all API interactions
- ✅ Use a WAF if possible
Compliance
- PCI-DSS — we are the ones storing card data, not you
- RGPD — we are your data processor, you are the controller
- Local regulations apply in each country