Safe storage checklist
- Keep Client ID and Client Secret in server-side environment configuration or a managed secret store.
- Use a different credential for Development and Production.
- Restrict secret-store access to the service that makes AvraAPI requests.
- Use HTTPS for every request.
- Keep secrets out of browser code, mobile applications, repositories, CI output, screenshots, URLs, analytics, and error reports.
If a secret may be exposed
1
Rotate the credential
Generate a replacement from the project dashboard immediately. The old secret must be considered unsafe.
2
Deploy the replacement safely
Update your server-side configuration and restart or reload the affected service. Confirm the new credential works in the intended environment.
3
Investigate your delivery path
Remove the secret from logs, commits, CI output, browser bundles, and shared messages. Revoke exposed deploy artifacts if necessary.
UPG additional boundary
UPG uses two separate secret classes:
Do not copy a gateway secret into your application’s
.env file simply because it was configured in AvraAPI. UPG is designed specifically to avoid that duplication.
