Skip to content

Security

Purpose

Summarize the platform's security baselines for developers and operators.

Overview

  • HTTPS + secure cookies in production
  • CSRF, CORS allowlists (no wildcards in prod)
  • PKCE for public OAuth clients
  • Hashed site secrets, masked AI credentials
  • Stripe webhook signature verification
  • Idempotent financial operations
  • Append-only wallet + audit logs
  • No secrets in mkp.js