Skip to content

Token Handling Best Practices

  • Never expose your client secret or access token client-side. Both should only ever be held by server-side code — never shipped to a browser, mobile app, or any client the end user controls.
  • Store credentials server-side only, using your platform's secret storage (environment variables backed by a secrets manager, vault, etc.) rather than checking them into source control or configuration files that get committed.
  • Rotate credentials on suspected leak. If a client secret or access token is ever exposed (logs, a committed file, a third-party breach), treat it as compromised and rotate immediately.
  • Use HTTPS everywhere. This is already enforced by the API's base URL (https://api.cloudpay365.com/api/v1/), but make sure nothing in your own stack downgrades or proxies these calls over plain HTTP.

See Authentication for how the client ID/secret and access token are obtained and used, and IP Whitelisting for the network-level counterpart to these credential controls.