Security
Control plane, not traffic proxy
Your customers call your API directly. MicroAuth receives account and configuration data plus usage metadata that your integration reports. It does not receive your API request bodies, request headers, query parameters or response bodies.
Your customers
call your API with their key
Your API
auth, limits & metering in‑process
MicroAuth SDK insideMicroAuth
portal · billing · control plane
Credential protection
- Passwords use Argon2id hashes.
- API keys are shown once and stored as SHA-256 hashes.
- TOTP and connected Stripe secrets are encrypted at rest.
- Session cookies are secure and HTTP-only in production, with CSRF checks on cookie-authenticated mutations.
Workspace and customer isolation
SaaS users act within a workspace and role. In a developer portal, billing, keys, usage, plans and members belong to a customer team. Every authenticated team-scoped request names that team with X-MicroAuth-Workspace-ID. The API then verifies the portal tenant, current membership and required role. The header selects scope; it does not replace authorization.
Billing integrity
- Stripe signatures are checked against the unmodified webhook body.
- Accepted webhooks are stored in a durable database inbox before acknowledgement.
- Usage and external credit operations use stable idempotency keys for safe retries.
- A failed subscription payment has a 7-day recovery grace period before billing suspension.
Retention
Processed or ignored raw Stripe webhook events and terminal checkout coordination rows are removed after 90 days. Dead webhook events and subscription replay tombstones are removed after 365 days. SDK usage idempotency receipts are removed after 60 days. Financial ledgers, usage aggregates and audit records currently remain with their owning account data because they support billing, disputes and security review.
Read thecomplete security and retention policyand our privacy policy for deletion details.
Report a vulnerability
Send security reports tosecurity@microauth.com. Do not include active credentials, customer API payloads or unrelated personal data in the initial message.
Review the integration contract
The documentation covers SDK caching, request accounting, idempotent delivery and production operations.