INTEGRATION SECURITY

Treat the browser response as untrusted input.

A token becomes evidence only after your backend verifies it and checks that the returned context matches the protected operation.

Maintained documentation3 sectionsAPI contract

Credential boundary

Public keys identify a site; secret keys authenticate server verification and must remain outside browser code, logs, and repositories.

  • Store secrets in environment-backed secret storage
  • Rotate compromised credentials
  • Never log submitted response tokens

Context enforcement

Send the expected site key and action to siteverify, then independently compare the returned hostname and action.

  • Exact hostname registration
  • Action-specific policy
  • Reject unexpected decisions

Failure handling

Tokens expire and are consumed once. Network errors, dependency outages, and malformed responses must not silently authorize the protected action.

  • Short outbound timeout
  • Fail closed
  • Correlate with request_id