Security
Provider credentials
Collect only reviewed credential shapes at the provider authorization boundary.
Provider credentials are not application API keys. The embedded flow validates a provider-discriminated credential shape and sends it only to the connection authorization endpoint over HTTPS.
- Domain0 never returns provider credentials in connection responses or events.
- Host callbacks never receive credential field values.
- The browser UI does not log credential inputs.
- Manual setup never collects provider credentials.
- OAuth and Domain Connect handoffs use provider-specific reviewed flows.
Prefer the provider's narrowest supported credential and revoke temporary credentials after their intended use. Follow the provider's own audit and least-privilege guidance.