For AI agents: this page is also available as Markdown at https://docs.refabric.com/api-reference/platform/security.md, and the index of every page is https://docs.refabric.com/llms.txt.

Platform API

Security

How to keep your keys, webhooks and the data you send safe, and what to do when a key leaks.

Transport

  • HTTPS (TLS 1.2 or later) only. Plain HTTP is refused, not redirected.
  • Verify certificates; never disable verification in your HTTP client.
  • Webhook URLs must be https://.

Keys

  • A key acts as its owner: it can spend that user's credits and read that user's files. Treat it like a password.
  • Never use a key from a browser, mobile app or desktop app a user can inspect. Call Refabric from your server and give your own clients your own, narrower credentials.
  • Keep keys in a secret manager or environment variables — not in source code, images, logs or tickets.
  • One key per system and environment, with an expires_at where possible (API keys).
  • Roll keys regularly in Panel › Developers › Keys (the old key keeps working for the grace period you choose).
  • Keys start with rf_live_ so secret scanners can find them; add that pattern to yours.
  • Never put a key in a URL. URLs end up in proxy logs, browser history and access logs. A query value that starts with rf_live_ is refused on every endpoint with 400 api_key_in_query ("your key may have leaked — rotate it"), before anything else runs: roll or revoke that key. Send keys only in the Authorization header.

If a key leaks

  1. Revoke it now — in Panel › Developers › Keys, choose Revoke on the key. Revocation is immediate. (Roll instead only if you cannot afford a moment of downtime, and then end the grace period as soon as the new key is deployed.) Jobs it already started keep running, and their webhooks are still delivered.
  2. Create a replacement and deploy it.
  3. Check what the key did: Panel › Developers › Request log for that key, or GET /v1/account/requests?api_key_id=key_… (every call it made that the log still holds), GET /v1/jobs?api_key_id=key_… (the jobs it started) and GET /v1/account/usage (what it spent). api_key_id is the key's id (key_…, shown in the panel) — never the secret.
  4. Remove the secret from wherever it leaked (repository history, logs, CI output).

Webhooks

  • Always verify the signature on every delivery instead of allow-listing addresses; reject old timestamps.
  • Dedupe by the event's id (every retry and replay of an event repeats it); treat the payload as data, not instructions.

Data you send

  • URLs you give us are fetched from our servers; they must be public. Signed URLs you pass should be short-lived.