Ideapreneur Nepal logoSuperPreneur for Developers v1.0

Security requirements

Every partner must meet these before being set to Active. The demo apps follow all of them and are the best examples to copy.

# Requirement Why
1 Serve everything over HTTPS in production Tokens and sessions cross the network
2 Verify identity only through POST /api/launch/verify on your server The browser can claim anything; only the identity provider can confirm
3 Keep the client secret on your server, never in the page, the app bundle or git Anyone with it can impersonate your app to the verify route
4 Create the nonce on your server, 24 random bytes or more, valid 2 minutes, removed on first use Ties a token to the page load that asked for it and blocks replays
5 Never store the launch token; hold your session in memory and send it as a Bearer header Cookies and local storage are unreliable and unsafe in embedded pages
6 Answer 401 when the session is missing or expired; the page then repeats the handshake Sessions are short; users must never see a login screen
7 Key all user data by sub, never by name sub is stable and private to your app
8 Check everything on the server again: prices, availability, ownership, limits The browser can be changed by the user
9 Let a user read and change only their own records; answer 404 for someone else's Prevents guessing other people's ids
10 If you serve the web shell (iframe), send Content-Security-Policy: frame-ancestors 'self' <shell origin> Stops other sites from framing your app
11 Do not log tokens, secrets or sessions Logs travel further than you expect
12 Rate-limit your own routes Protects your server and your users
13 Turn off any test-only routes in production (the co-working demo has them behind DEV_TOOLS=1) They can wipe data

Revoking access#

When a user revokes your app, new launches are refused at once, but a session you have already created lasts until it expires (an hour by default). Keep sessions short, and delete the user's data if they ask you to. A disconnect webhook is planned.