Security and recovery
Protect API credentials, HTTPS origins, private artifacts and persistent installation secrets.
Use HTTPS for both public origins. Configure the exact UI and API URLs; the API accepts credentialed browser requests from the configured UI origin. API browser session cookies belong to the API host. The UI does not proxy API traffic.
Use Admin access only for people and clients that need it. Member credentials cannot delete databases or tables. Read-only credentials cannot mutate data. Revoke unused API keys, OAuth connections and sessions.
Was this page helpful?
