Skip to main content
  • Use service-account tokens for automation and grant only necessary tenants and permissions.
  • Store tokens in a secret manager and rotate them on staff or supplier changes.
  • Redact authorization headers, customer data, QR tokens, and redemption tokens from logs.
  • Verify tenant context before displaying or redeeming a voucher.
  • Restrict redemption clients to controlled staff devices and require deliberate confirmation.
  • Revoke credentials immediately after suspected exposure.