Integration Management
What Is Integration Management
Integration Management is for white-label and SaaS customers that need to connect external systems or automated workflows. Separate credentials and callback settings by environment, create them with least privilege, and establish rotation and incident-handling procedures.
Why Credentials and Callback Settings Require Extra Care
If settings such as agents, OAuth applications, API Keys, Webhooks, and IP Allowlists are exposed or configured incorrectly, customer data may be disclosed or services may be interrupted. Keep test and production credentials separate and grant access according to least privilege.
How to Manage Integration Settings
Agents and OAuth Applications
Agent Management shows connected parties, models or applications, associated users, and activation status. OAuth applications manage third-party authorized connections. Before enabling them, confirm the purpose, data scope, and owner.
Agent Management:Connected Parties, Models, and Status List
Agent Management:Activation Status Filter
OAuth application:authorizationapplicationList
API Keys
Confirm the customer, use case, and environment (test or production).
Create the key with least privilege and record its owner and purpose.
Deliver the key only through a secure channel. Do not place it in documents, email bodies, or code repositories.
Rotate keys regularly. Before disabling one, confirm that callers have switched to the replacement.
| Security note: Keys are usually displayed in masked form on the page. If the full key is shown only at creation, save it securely at that time; if it is lost, create a new one rather than trying to recover it from logs or screenshots. |
API Keys: Key Type and Environment List
Webhooks
Webhooks push events such as card transactions and 3DS to the customer system. When configuring one, confirm the callback URL, subscribed events, activation status, signature verification, and retry policy.
Use an HTTPS callback URL and keep test and production environments separate.
Subscribe only to events required by the business to reduce noise and exposure.
The receiver must verify the signature before processing the message and deduplicate by event ID.
Monitor failure rates and latency, and ensure retries are idempotent.
Webhook:Callback URL and Subscribed Event List
Webhook:subscribed eventsFilter
Webhook:Activation Status Filter
IP Allowlists
An IP Allowlist restricts the source addresses that can access the API. Prefer fixed public IP addresses or explicit CIDR ranges and avoid overly broad networks. Before changing the list, confirm that existing production traffic will not be blocked.
IP Allowlist:Source IP and Status List