API

API Credential Security and Rotation

Govern API key, secret, and token issuance, transfer, storage, rotation, and revocation.

Burton AI WMS API Customer Admin / Implementation / Security Owner 7 min Standard Version 2026.08 Updated 2026-08-25 Owner: Burton Product Documentation Quarterly review
0assets 2026-08-25Updated on

01 Principles

Credentials follow least privilege, environment separation, named ownership, and traceable change. Test and production must not share credentials.

02 Lifecycle

  1. A customer platform admin creates authorization or credentials in the official portal.
  2. Transfer them through a controlled channel to named implementation personnel; never place them in public docs, screenshots, or ticket text.
  3. After configuration, record only validation results, not plaintext secrets or tokens.
  4. Rotate on the customer security schedule and after personnel changes.
  5. Revoke immediately when a channel is retired, exposure is suspected, or the engagement ends.

03 Access and Audit

Limit Integrations and sensitive settings to administrators. Record channel, environment, owner, effective time, and validation result for issuance, rotation, and revocation without storing secret values.

04 Incident Response

When exposure is suspected, revoke or rotate first, then review authorization scope, activity logs, abnormal synchronization, and unknown request sources.