Partner security
Required before a verified review. Community sandbox keys stay as they are. This page does not collect a card number.
- Use OAuth with PKCE. Access tokens last at most 1 hour. Do not store a refresh token in the client.
- Request only the scopes the app function needs. ledger:read cannot request payouts:write.
- Keep client secrets and webhook signing keys in a dedicated key manager, encrypted at rest.
- Verify x-teddoh-signature and reject a bad signature with 401. teddoh test treats that as a hard fail.
- Send Idempotency-Key on every state-changing call. teddoh test treats a missing duplicate ack as a hard fail.
- Do not store a card number or a card security code.
- Scrub customer data within 30 days of a redact event.
- Score and KYC scopes need the BCEAO data-sharing acknowledgement from graduation.