Transport
- TLS 1.2 or newer
- mTLS when bilaterally agreed
- IP and egress allowlists
- Certificate-expiry monitoring
ASSURANCE · SECURITY
This portal publishes the minimum control profile. Concrete algorithms, certificates, source addresses and rotation windows are frozen in a bilateral profile and delivered over a secure onboarding channel.
Sandbox/test profile only
Production enablement: OFF
No client secret, private key, Gift Card PIN, bank account number, customer identity or production token belongs in email, WhatsApp, a PDF, a Postman export, a URL query string, source control or a support screenshot.
CREDENTIAL DELIVERY
Identify the technical owner. Verify organization, named contacts and escalation authority.
Exchange public material. CSR/JWK, public CA chain, source IP and webhook URL may be reviewed openly.
Deliver secrets once. Use an approved secret manager or one-time secure reveal, never a reusable document link.
Prove possession. Complete signed test calls, callback verification and JWE decryption before UAT.
Rotate independently. Sandbox and production keys rotate on separate schedules with an agreed overlap.
The handoff file contains the full checklist, incident expectations, evidence and provider-specific TBD worksheet.
Provider security profileMarkdown · review baseline and signoff fields↓