Security

Control plane, not traffic proxy

Your customers call your API directly. MicroAuth receives account and configuration data plus usage metadata that your integration reports. It does not receive your API request bodies, request headers, query parameters or response bodies.

A control plane, not a proxy. Requests go straight to your API; if MicroAuth is briefly unreachable, your API keeps serving.

Review the integration contract

The documentation covers SDK caching, request accounting, idempotent delivery and production operations.