MyDesk · Questions and answers

How to protect secret API keys in a guest registration integration?

Store and use secret API keys on the backend so that they are not exposed in frontend code, URLs, or client-facing calls, including their headers. Let the backend make the API calls that require the key, and protect access to the backend with authentication and access control. Continuously review the security of the integration.

Originally published

Generally

Svar fra den eksisterende vidensbase. Kontrollér jeres opsætning, og kontakt support, hvis svaret ikke passer til den version, I bruger.

Store and use secret API keys on the backend so that they are not exposed in frontend code, URLs, or client-facing calls, including their headers. Let the backend make the API calls that require the key, and protect access to the backend with authentication and access control. Continuously review the security of the integration.

Page coming soon

Explore the platform on our homepage

Book a demo

Open the booking calendar in a new window ↗