Short answer
One key per integration, the fewest scopes that integration needs, stored in a secret manager, rotated on a schedule.
Practices that matter
- Least privilege. A reporting job needs
analytics:read, notwrite. - Never in the browser. A key in front-end code is public. Call MunchReach from your server.
- Never in source control. Use environment variables or a secret manager; add
.envto.gitignore. - Rotate. Create the replacement, deploy, verify, then revoke the old key.
- Revoke fast. A suspected leak is a leak. Revoking is instant and free.
- Verify webhooks. Always check the signature before trusting a payload; an unverified endpoint accepts anything anyone posts to it.
Important notes
MunchReach shows a key's value only once, at creation, and stores only a prefix afterwards. Support cannot recover a lost key — create a new one.
Was this article helpful?
