API AUTHENTICATION

Treat developer credentials as governed assets.

Scope, rotate, revoke and observe API credentials; use stronger identity flows when user or organisation delegation is required.

API AUTHENTICATION

Developer contract.

Scope, rotate, revoke and observe API credentials; use stronger identity flows when user or organisation delegation is required.

KEYS

API keys

Service-to-service or low-complexity access with explicit scope and rotation.

OAUTH

OAuth/OIDC

Delegated user/organisation access where appropriate.

SCOPE

Scopes

Least-privilege resource/action permissions.

ROTATE

Rotation

Creation, last-used, expiry, rotation and emergency revocation.

LOG

Observability

Request IDs, actor, scope, rate and error monitoring.

SECRETS

Secret handling

Never expose server secrets in client-side code or public repositories.

NEXT STEP

Discuss an integration requirement.

Production integrations require scope, identity, data classification, rate and support requirements.

Talk to the developer platform team →
Get proposalBuy / license