Handle bearer URLs and signing credentials as secrets throughout their lifecycle.
Overview
Handle bearer URLs and signing credentials as secrets throughout their lifecycle.
Key points
- Public URLs and webhook secrets are shown once.
- Later lists show prefixes for identification.
- Rotation invalidates prior values immediately.
- Secrets should not appear in source control, tickets, logs, or screenshots.
- Distribution records should identify placement without unnecessarily retaining clear secrets.
Recommended procedure
- Classify the survey data and identity requirements.
- Choose the least permissive distribution and access model that meets the need.
- Protect links, tokens, exports, and integration secrets.
- Audit administrative actions and test isolation, retention, and recovery.
Troubleshooting
Sensitive data is exposed
Disable or rotate affected access, preserve evidence, and follow the incident procedure.
The policy is unclear
Keep the article in draft until product, engineering, security, and legal approve the contract.