How can we help you?

Protect Public Links and Webhook Secrets

Product: FeraSurvey Topic: Administration and Security Versions: Applies to all documented versions Current

Handle bearer URLs and signing credentials as secrets throughout their lifecycle.

Audience: Administrators and developers
Editorial status: Public
Product: FeraSurvey

Overview

Handle bearer URLs and signing credentials as secrets throughout their lifecycle.

Key points

  • Public URLs and webhook secrets are shown once.
  • Later lists show prefixes for identification.
  • Rotation invalidates prior values immediately.
  • Secrets should not appear in source control, tickets, logs, or screenshots.
  • Distribution records should identify placement without unnecessarily retaining clear secrets.

Recommended procedure

  1. Classify the survey data and identity requirements.
  2. Choose the least permissive distribution and access model that meets the need.
  3. Protect links, tokens, exports, and integration secrets.
  4. Audit administrative actions and test isolation, retention, and recovery.

Troubleshooting

Sensitive data is exposed

Disable or rotate affected access, preserve evidence, and follow the incident procedure.

The policy is unclear

Keep the article in draft until product, engineering, security, and legal approve the contract.

Related documentation