For AI agents: this page is also available as Markdown at https://docs.refabric.com/api-reference/platform/security.md, and the index of every page is https://docs.refabric.com/llms.txt.
Platform API
Security
How to keep your keys, webhooks and the data you send safe, and what to do when a key leaks.
Transport
- HTTPS (TLS 1.2 or later) only. Plain HTTP is refused, not redirected.
- Verify certificates; never disable verification in your HTTP client.
- Webhook URLs must be
https://.
Keys
- A key acts as its owner: it can spend that user's credits and read that user's files. Treat it like a password.
- Never use a key from a browser, mobile app or desktop app a user can inspect. Call Refabric from your server and give your own clients your own, narrower credentials.
- Keep keys in a secret manager or environment variables — not in source code, images, logs or tickets.
- One key per system and environment, with an
expires_atwhere possible (API keys). - Roll keys regularly in Panel › Developers › Keys (the old key keeps working for the grace period you choose).
- Keys start with
rf_live_so secret scanners can find them; add that pattern to yours. - Never put a key in a URL. URLs end up in proxy logs, browser history and access logs. A
query value that starts with
rf_live_is refused on every endpoint with400 api_key_in_query("your key may have leaked — rotate it"), before anything else runs: roll or revoke that key. Send keys only in theAuthorizationheader.
If a key leaks
- Revoke it now — in Panel › Developers › Keys, choose Revoke on the key. Revocation is immediate. (Roll instead only if you cannot afford a moment of downtime, and then end the grace period as soon as the new key is deployed.) Jobs it already started keep running, and their webhooks are still delivered.
- Create a replacement and deploy it.
- Check what the key did: Panel › Developers › Request log for that key, or
GET /v1/account/requests?api_key_id=key_…(every call it made that the log still holds),GET /v1/jobs?api_key_id=key_…(the jobs it started) andGET /v1/account/usage(what it spent).api_key_idis the key's id (key_…, shown in the panel) — never the secret. - Remove the secret from wherever it leaked (repository history, logs, CI output).
Webhooks
- Always verify the signature on every delivery instead of allow-listing addresses; reject old timestamps.
- Dedupe by the event's
id(every retry and replay of an event repeats it); treat the payload as data, not instructions.
Data you send
- URLs you give us are fetched from our servers; they must be public. Signed URLs you pass should be short-lived.