Partner security

Required before a verified review. Community sandbox keys stay as they are. This page does not collect a card number.

  1. Use OAuth with PKCE. Access tokens last at most 1 hour. Do not store a refresh token in the client.
  2. Request only the scopes the app function needs. ledger:read cannot request payouts:write.
  3. Keep client secrets and webhook signing keys in a dedicated key manager, encrypted at rest.
  4. Verify x-teddoh-signature and reject a bad signature with 401. teddoh test treats that as a hard fail.
  5. Send Idempotency-Key on every state-changing call. teddoh test treats a missing duplicate ack as a hard fail.
  6. Do not store a card number or a card security code.
  7. Scrub customer data within 30 days of a redact event.
  8. Score and KYC scopes need the BCEAO data-sharing acknowledgement from graduation.

Verified tier only. This form does not accept a card number and does not mint a key.

Partner security · Teddoh