API security best practices

Scope narrowly, store secrets properly, rotate on schedule and monitor use.

Updated Sep 10, 2026 1 min read

Short answer

One key per integration, the fewest scopes that integration needs, stored in a secret manager, rotated on a schedule.

Practices that matter

  1. Least privilege. A reporting job needs analytics:read, not write.
  2. Never in the browser. A key in front-end code is public. Call MunchReach from your server.
  3. Never in source control. Use environment variables or a secret manager; add .env to .gitignore.
  4. Rotate. Create the replacement, deploy, verify, then revoke the old key.
  5. Revoke fast. A suspected leak is a leak. Revoking is instant and free.
  6. Verify webhooks. Always check the signature before trusting a payload; an unverified endpoint accepts anything anyone posts to it.

Important notes

MunchReach shows a key's value only once, at creation, and stores only a prefix afterwards. Support cannot recover a lost key — create a new one.

Was this article helpful?

Related articles