Security¶
Purpose¶
Summarize the platform's security baselines for developers and operators.
Overview¶
- HTTPS + secure cookies in production
- CSRF, CORS allowlists (no wildcards in prod)
- PKCE for public OAuth clients
- Hashed site secrets, masked AI credentials
- Stripe webhook signature verification
- Idempotent financial operations
- Append-only wallet + audit logs
- No secrets in
mkp.js