What should I do if a client secret is exposed?
Rotate the secret immediately from the API client settings, update your server environment, and review recent API activity for unexpected requests.
powered by amerencio
Rotate the secret immediately from the API client settings, update your server environment, and review recent API activity for unexpected requests.
Support
Gerelateerde vragen binnen Security.
Security
Does XWMS support two-factor authentication?Yes. XWMS supports authenticator-based 2FA. When 2FA is active, verification prompts use your authenticator code instead of sending an email code.
Security
Why does XWMS ask for a verification code?Verification codes protect account access, OAuth provider connections, account unlock, and sensitive account changes. The required method depends on your account security settings.
Security
Does XWMS send email codes when 2FA is enabled?No. For verification flows that use the standard account verification helper, XWMS uses the authenticator code when 2FA is enabled and only sends email codes when 2FA is not enabled.
Security
How should I protect my API client secret?Store client secrets only on your backend or server environment. Never expose a client secret in frontend JavaScript, public repositories, screenshots, or browser-readable configuration.
Security
What is domain verification for API clients?Domain verification proves that a website is allowed to use a specific XWMS client. This helps prevent untrusted websites from using your OAuth or API setup.
Security
Why does OAuth show a warning for unverified websites?XWMS warns users when an OAuth website is not verified. This helps users understand that the website has not yet completed the XWMS domain verification process.
Live support
Je moet ingelogd zijn om een supportticket te starten.
InloggenWelkom terug. Start een ticket of laat je vraag achter.
Bekijk Amerencio Studio Ontdek Studio