domain
Security

Provider credentials

Collect only reviewed credential shapes at the provider authorization boundary.

Provider credentials are not application API keys. The embedded flow validates a provider-discriminated credential shape and sends it only to the connection authorization endpoint over HTTPS.

  • Domain0 never returns provider credentials in connection responses or events.
  • Host callbacks never receive credential field values.
  • The browser UI does not log credential inputs.
  • Manual setup never collects provider credentials.
  • OAuth and Domain Connect handoffs use provider-specific reviewed flows.

Prefer the provider's narrowest supported credential and revoke temporary credentials after their intended use. Follow the provider's own audit and least-privilege guidance.