Security Best Practices
This guide covers the security measures you should implement when integrating with Open Pay, from API key management to smart contract safety.API Key Management
Store Secrets Securely
- Environment Variables
- AWS Secrets Manager
- HashiCorp Vault
Use Separate Keys per Environment
Rotate Keys Regularly
- Generate a new API key
- Update your application to use the new key
- Verify the new key works in production
- Revoke the old key
Webhook Signature Verification
Always verify webhook signatures before processing events. This prevents attackers from forging webhook payloads.HTTPS Only
- Always use
https://for your webhook endpoint - Always call the API over
https://olp-api.nipuntheekshana.com - Ensure your TLS certificates are valid and not self-signed in production
- Use HSTS headers on your webhook endpoint
Idempotency Keys
Include anIdempotency-Key header on all POST requests to prevent duplicate operations during retries:
- First request with a given key: creates the resource and caches the response
- Subsequent requests with the same key and parameters: returns the cached response
- Same key with different parameters: returns a
409 Conflicterror - Keys expire after 24 hours
IP Allowlisting
Restrict API key usage to specific IP addresses for an extra layer of protection. Configure this in the Merchant Portal under Integrations > API Keys > IP Restrictions.- Supports individual IPs and CIDR ranges
- Requests from non-allowlisted IPs receive a
403 Forbiddenresponse - Recommended for production server-to-server integrations
Two-Factor Authentication (2FA)
Enable 2FA on your merchant account to protect against unauthorized access to the Merchant Portal and sensitive API operations.Set Up 2FA
Verify and Enable
Operations Requiring 2FA
- API key creation and revocation
- Webhook URL changes
- Withdrawal requests
- Password changes
HMAC Replay Protection
For server-to-server API calls using HMAC authentication (used by SDKs), the platform enforces timestamp-based replay protection:Smart Contract Security
Open Pay’s on-chain escrow contracts implement multiple security patterns:ReentrancyGuard
ReentrancyGuard to prevent reentrancy attacks on fund withdrawal functions.SafeERC20
SafeERC20 library to handle non-standard ERC20 implementations that don’t return a boolean.Ownable
Ownable pattern.Chainlink Price Feeds
Contract Audit Checklist
Key security properties of the escrow contract:- Funds can only be released to the merchant after payment confirmation
- Refunds can only be triggered by the contract owner or after expiration
- Slippage tolerance is configurable (default: 1%) and capped at 5%
- Emergency pause functionality halts all deposits and withdrawals
- Contract is upgradeable via proxy pattern for critical security patches
Security Checklist
Use this checklist to verify your integration is secure:API keys stored in environment variables or secret manager
Separate API keys for dev, staging, and production
Webhook signature verification implemented and tested
Webhook timestamp validation (5-minute window)
All API calls over HTTPS
Idempotency keys on all POST requests
IP allowlisting enabled for production API keys
2FA enabled on merchant account
API keys rotated every 90 days
Error messages sanitized before showing to end users