Skip to main content

Security practices

  • Put secret keys in a secret manager or environment variables, never source code, browser bundles, mobile apps, Git history, logs, screenshots, or support messages.
  • Use HTTPS for all Live callback and webhook URLs.
  • Verify every webhook with the raw request body and its endpoint signing secret.
  • Retrieve payment status server-side before delivering goods or crediting a customer.
  • Compare the verified amount and currency with your own order record.
  • Use a unique idempotency key for each logical payment attempt.
  • Rotate credentials immediately if exposure is possible.
  • Give production access only to services and team members that need it.
Environment variable
export SKYPAY_SECRET_KEY='ssk_sand_replace_with_your_key'

Do not expose this value through a frontend variable such as VITE_..., NEXT_PUBLIC_..., or REACT_APP_...; those prefixes intentionally publish values to the browser.