INTEGRATION SECURITY
Treat the browser response as untrusted input.
A token becomes evidence only after your backend verifies it and checks that the returned context matches the protected operation.
Credential boundary
Public keys identify a site; secret keys authenticate server verification and must remain outside browser code, logs, and repositories.
- Store secrets in environment-backed secret storage
- Rotate compromised credentials
- Never log submitted response tokens
Context enforcement
Send the expected site key and action to siteverify, then independently compare the returned hostname and action.
- Exact hostname registration
- Action-specific policy
- Reject unexpected decisions
Failure handling
Tokens expire and are consumed once. Network errors, dependency outages, and malformed responses must not silently authorize the protected action.
- Short outbound timeout
- Fail closed
- Correlate with request_id