API keys belong in a server secret manager or owner-only local configuration. Use separate test/live keys, the minimum scopes, expirations and immediate revocation after exposure. Do not put keys in client JavaScript, URLs, chat, screenshots or logs.
Account passwords use salted hashing and API keys are stored as hashes. Recoverable provider tracking sessions use AES-256-GCM with versioned independent keys and authenticated tenant, environment and payment identifiers. Key rotation keeps old decrypt keys until their sessions expire.
Ordinary account/payment metadata and merchant links are not all field-encrypted today. Production needs encrypted storage and backups, private networking, least-privilege database access and a verified restore process. Keep encryption keys separate from the database and backup files. Application encryption does not protect against a compromised application holding those keys.
Clients use HTTPS. Database connections currently stay inside private Docker networks without database TLS. Use Coolify’s database controls for private access and backup scheduling, then verify database TLS, encrypted storage and recovery before customer launch. A managed private database is another option.
Developer rules
Validate the customer and order server-side, derive the amount from stored order data, bind the payment ID to that order, and verify status before fulfillment. Webhook receivers will need signature verification, timestamp tolerance and event deduplication when the signed webhook service is implemented.
Guidance: OWASP cryptographic storage and secrets management.
Key setup · Safe polling