Security requirements
Every partner must meet these before being set to Active. The demo apps follow all of them and are the best examples to copy.
| # | Requirement | Why |
|---|---|---|
| 1 | Serve everything over HTTPS in production | Tokens and sessions cross the network |
| 2 | Verify identity only through POST /api/launch/verify on your server |
The browser can claim anything; only the identity provider can confirm |
| 3 | Keep the client secret on your server, never in the page, the app bundle or git | Anyone with it can impersonate your app to the verify route |
| 4 | Create the nonce on your server, 24 random bytes or more, valid 2 minutes, removed on first use | Ties a token to the page load that asked for it and blocks replays |
| 5 | Never store the launch token; hold your session in memory and send it as a Bearer header | Cookies and local storage are unreliable and unsafe in embedded pages |
| 6 | Answer 401 when the session is missing or expired; the page then repeats the handshake |
Sessions are short; users must never see a login screen |
| 7 | Key all user data by sub, never by name |
sub is stable and private to your app |
| 8 | Check everything on the server again: prices, availability, ownership, limits | The browser can be changed by the user |
| 9 | Let a user read and change only their own records; answer 404 for someone else's |
Prevents guessing other people's ids |
| 10 | If you serve the web shell (iframe), send Content-Security-Policy: frame-ancestors 'self' <shell origin> |
Stops other sites from framing your app |
| 11 | Do not log tokens, secrets or sessions | Logs travel further than you expect |
| 12 | Rate-limit your own routes | Protects your server and your users |
| 13 | Turn off any test-only routes in production (the co-working demo has them behind DEV_TOOLS=1) |
They can wipe data |
Revoking access#
When a user revokes your app, new launches are refused at once, but a session you have already created lasts until it expires (an hour by default). Keep sessions short, and delete the user's data if they ask you to. A disconnect webhook is planned.