# Security

> How to keep your keys, webhooks and the data you send safe, and what to do when a key leaks.

## Transport

- HTTPS (TLS 1.2 or later) only. Plain HTTP is refused, not redirected.
- Verify certificates; never disable verification in your HTTP client.
- Webhook URLs must be `https://`.

## Keys

- A key acts as its owner: it can spend that user's credits and read that user's files. Treat it
  like a password.
- **Never use a key from a browser, mobile app or desktop app** a user can inspect. Call Refabric
  from your server and give your own clients your own, narrower credentials.
- Keep keys in a secret manager or environment variables — not in source code, images, logs or
  tickets.
- One key per system and environment, with an `expires_at` where possible
  ([API keys](https://docs.refabric.com/setting-up/get-your-api-key)).
- Roll keys regularly in **Panel › Developers › Keys** (the old key keeps working for the grace
  period you choose).
- Keys start with `rf_live_` so secret scanners can find them; add that pattern to yours.
- **Never put a key in a URL.** URLs end up in proxy logs, browser history and access logs. A
  query value that starts with `rf_live_` is refused on every endpoint with
  `400 api_key_in_query` ("your key may have leaked — rotate it"), before anything else runs: roll
  or revoke that key. Send keys only in the `Authorization` header.

## If a key leaks

1. **Revoke it now** — in **Panel › Developers › Keys**, choose **Revoke** on the key. Revocation
   is immediate. (Roll instead only if you cannot afford a moment of downtime, and then end the
   grace period as soon as the new key is deployed.) Jobs it already started keep running, and
   their webhooks are still delivered.
2. Create a replacement and deploy it.
3. Check what the key did: **Panel › Developers › Request log** for that key, or
   `GET /v1/account/requests?api_key_id=key_…` (every call it made that the log still holds),
   `GET /v1/jobs?api_key_id=key_…` (the jobs it started) and `GET /v1/account/usage` (what it
   spent). `api_key_id` is the key's id (`key_…`, shown in the panel) — never the secret.
4. Remove the secret from wherever it leaked (repository history, logs, CI output).

## Webhooks

- Always [verify the signature](https://docs.refabric.com/task-apis/calling-tasks/webhooks#verifying-the-signature) on every delivery
  instead of allow-listing addresses; reject old timestamps.
- Dedupe by the event's `id` (every retry and replay of an event repeats it); treat the payload as
  data, not instructions.

## Data you send

- URLs you give us are fetched from our servers; they must be public. Signed URLs you pass should
  be short-lived.
