Skip to main content
Your AvraAPI Client Secret authorizes server-to-server access for a project environment. Treat it with the same care as a database password or payment-provider secret.

Safe storage checklist

  • Keep Client ID and Client Secret in server-side environment configuration or a managed secret store.
  • Use a different credential for Development and Production.
  • Restrict secret-store access to the service that makes AvraAPI requests.
  • Use HTTPS for every request.
  • Keep secrets out of browser code, mobile applications, repositories, CI output, screenshots, URLs, analytics, and error reports.

If a secret may be exposed

1

Rotate the credential

Generate a replacement from the project dashboard immediately. The old secret must be considered unsafe.
2

Deploy the replacement safely

Update your server-side configuration and restart or reload the affected service. Confirm the new credential works in the intended environment.
3

Investigate your delivery path

Remove the secret from logs, commits, CI output, browser bundles, and shared messages. Revoke exposed deploy artifacts if necessary.

UPG additional boundary

UPG uses two separate secret classes: Do not copy a gateway secret into your application’s .env file simply because it was configured in AvraAPI. UPG is designed specifically to avoid that duplication.
An API key visible in a browser network tab is already an incident. Browser code may receive a public checkout session, never an AvraAPI Client Secret.
Last modified on October 1, 2026