Core Practices
Use HTTPS
Production checkout and merchant access should always run over HTTPS.
Protect API Keys
API keys belong on merchant servers only and should not be exposed in browser JavaScript.
Restrict Sensitive Files
Configuration, library, and storage paths are blocked from direct browser access.
Payment Handling
Hosted checkout keeps payment collection in a controlled flow. Admin review tools should be used only by authorized administrators.
Merchant Responsibilities
Merchants should use strong passwords, rotate keys when needed, restrict access to their systems, and review integration behavior before production use.