Skip to content

Secure

This section covers the SDK’s security surface: authenticating callers from verified tokens, verifying your authorization coverage in CI, and controlling how secret field values are stored, redacted, and transported. Use these guides when you need a service to know who is calling, to confirm it enforces access control correctly, or to protect sensitive data in your domain model.

For a conceptual overview of the security model, see Security posture.