ASSURANCE · SECURITY

No credential in the document. No financial trust by assumption.

This portal publishes the minimum control profile. Concrete algorithms, certificates, source addresses and rotation windows are frozen in a bilateral profile and delivered over a secure onboarding channel.

BASELINE PROFILE

Sandbox/test profile only

Production enablement: OFF

PROHIBITED

Never send production secrets through the integration pack.

No client secret, private key, Gift Card PIN, bank account number, customer identity or production token belongs in email, WhatsApp, a PDF, a Postman export, a URL query string, source control or a support screenshot.

01

Transport

  • TLS 1.2 or newer
  • mTLS when bilaterally agreed
  • IP and egress allowlists
  • Certificate-expiry monitoring
02

Client identity

  • Partner-scoped OAuth client credentials
  • Least-privilege scopes
  • Independent UAT/production clients
  • Secret-manager references only
03

Message integrity

  • Signed callback/request profile
  • Raw-body verification
  • Timestamp and nonce validation
  • Key ID and rotation overlap
04

Sensitive delivery

  • Gift credential encrypted as JWE
  • Partner-owned public JWK
  • No-store response policy
  • No plaintext secret in logs or tickets
05

Financial replay safety

  • Idempotency-Key on every financial POST
  • Canonical request hash
  • Unique provider event/reference constraints
  • At-least-once delivery, one financial effect
06

Operations

  • 24/7 rail kill switch
  • Recovery stays active when creates stop
  • Immutable audit and maker-checker
  • Security and settlement escalation paths

CREDENTIAL DELIVERY

Separate channel, one-time reveal, verifiable ownership.

  1. 1

    Identify the technical owner. Verify organization, named contacts and escalation authority.

  2. 2

    Exchange public material. CSR/JWK, public CA chain, source IP and webhook URL may be reviewed openly.

  3. 3

    Deliver secrets once. Use an approved secret manager or one-time secure reveal, never a reusable document link.

  4. 4

    Prove possession. Complete signed test calls, callback verification and JWE decryption before UAT.

  5. 5

    Rotate independently. Sandbox and production keys rotate on separate schedules with an agreed overlap.

Download the detailed security profile

The handoff file contains the full checklist, incident expectations, evidence and provider-specific TBD worksheet.

Provider security profileMarkdown · review baseline and signoff fields