domain
Security

Security model

Keep authority narrow across server, browser, provider, and webhook boundaries.

Domain0 uses distinct credentials for distinct trust boundaries.

CredentialHolderScope
Platform API keyYour serverOne bound application
Connection bearer tokenUser browserOne connection + exact origin + short expiry
Provider credentialDomain0 authorization boundarySelected provider operation; never returned
Webhook signing keyDomain0 + your receiverVerify untouched delivery bytes