Security
A control plane, not a traffic proxy
Your customers call your API directly. MicroAuth receives account and configuration data plus the usage counts your integration reports. It never sees your request bodies, headers, query parameters or responses.
Credentials
- Passwords are stored as bcrypt hashes. Nobody at MicroAuth can read them.
- API keys are shown once and stored as SHA-256 hashes. Your API checks keys by hash too, so verifying a key never sends the key itself to MicroAuth.
- SDK secrets and two step verification secrets are encrypted at rest. Recovery codes are stored as hashes and each one works once.
- Two step verification codes can't be replayed: each code is accepted once.
- Stripe is connected through Stripe Connect. MicroAuth stores your Stripe account ID and never holds your Stripe secret keys.
Sessions and requests
- Session cookies are HTTP only, and secure in production. Each developer portal has its own session, so signing in to one API's portal means nothing on another.
- Every request that changes data is checked against the site it came from, which blocks cross site request forgery.
- Sign in and verification code endpoints are rate limited per account and per network.
- All traffic uses TLS, including developer portals on custom domains.
Workspace and customer isolation
Everyone in the dashboard acts inside a workspace with a role: owner, admin, editor or viewer. Every request is checked against that role. In a developer portal, keys, usage, billing and members belong to one customer account, and each member's role decides what they can see and change.
Billing integrity
- Stripe webhooks are verified against their signature and stored in a durable inbox. Subscriptions and payments are read back from Stripe before they are applied, so events that arrive out of order can't roll anything back.
- Every balance change is a ledger entry with a unique reference, so retried webhooks and repeated API calls never credit or charge twice.
- Usage reports are idempotent, and each request is billed at the price that admitted it, even if you change prices before the report arrives.
- Every night, each customer's balance is checked against the sum of their ledger, and any difference is flagged to us.
Retention
- Processed Stripe webhook events are deleted after 90 days.
- Usage receipts, kept to ignore duplicate reports, are deleted after about 45 days.
- Hourly usage and the activity log are kept for 13 months.
- Expired sessions and sign in codes are deleted shortly after they expire.
- Ledger entries and payment records are kept while the account exists, because they back up billing, disputes and tax records.
- The database is backed up every day. Each backup is checked after it is written and kept for 14 days.
The privacy policy explains what we collect and how to ask for deletion.
Report a vulnerability
Send security reports to security@microauth.com. Please don't include working credentials, customer API payloads or unrelated personal data in your first message. We read these reports first and reply as fast as we can.