Security practices
- Put secret keys in a secret manager or environment variables, never source code, browser bundles, mobile apps, Git history, logs, screenshots, or support messages.
- Use HTTPS for all Live callback and webhook URLs.
- Verify every webhook with the raw request body and its endpoint signing secret.
- Retrieve payment status server-side before delivering goods or crediting a customer.
- Compare the verified amount and currency with your own order record.
- Use a unique idempotency key for each logical payment attempt.
- Rotate credentials immediately if exposure is possible.
- Give production access only to services and team members that need it.
Environment variable
export SKYPAY_SECRET_KEY='ssk_sand_replace_with_your_key'
Do not expose this value through a frontend variable such as VITE_..., NEXT_PUBLIC_..., or REACT_APP_...; those prefixes intentionally publish values to the browser.