Skip to main content

Integration Management

What Is Integration Management​

Integration Management is for white-label and SaaS customers that need to connect external systems or automated workflows. Separate credentials and callback settings by environment, create them with least privilege, and establish rotation and incident-handling procedures.

Why Credentials and Callback Settings Require Extra Care​

If settings such as agents, OAuth applications, API Keys, Webhooks, and IP Allowlists are exposed or configured incorrectly, customer data may be disclosed or services may be interrupted. Keep test and production credentials separate and grant access according to least privilege.

How to Manage Integration Settings​

Agents and OAuth Applications​

Agent Management shows connected parties, models or applications, associated users, and activation status. OAuth applications manage third-party authorized connections. Before enabling them, confirm the purpose, data scope, and owner.

Agent Management:Connected Parties, Models, and Status List

Agent Management:Activation Status Filter

OAuth application:authorizationapplicationList

API Keys​

Confirm the customer, use case, and environment (test or production).

Create the key with least privilege and record its owner and purpose.

Deliver the key only through a secure channel. Do not place it in documents, email bodies, or code repositories.

Rotate keys regularly. Before disabling one, confirm that callers have switched to the replacement.

Security note: Keys are usually displayed in masked form on the page. If the full key is shown only at creation, save it securely at that time; if it is lost, create a new one rather than trying to recover it from logs or screenshots.

API Keys: Key Type and Environment List

Webhooks​

Webhooks push events such as card transactions and 3DS to the customer system. When configuring one, confirm the callback URL, subscribed events, activation status, signature verification, and retry policy.

Use an HTTPS callback URL and keep test and production environments separate.

Subscribe only to events required by the business to reduce noise and exposure.

The receiver must verify the signature before processing the message and deduplicate by event ID.

Monitor failure rates and latency, and ensure retries are idempotent.

Webhook:Callback URL and Subscribed Event List

Webhook:subscribed eventsFilter

Webhook:Activation Status Filter

IP Allowlists​

An IP Allowlist restricts the source addresses that can access the API. Prefer fixed public IP addresses or explicit CIDR ranges and avoid overly broad networks. Before changing the list, confirm that existing production traffic will not be blocked.

IP Allowlist:Source IP and Status List