[{"data":1,"prerenderedAt":270},["ShallowReactive",2],{"navigation_docs_en":3,"-en-platform-security-and-environments":210,"-en-platform-security-and-environments-surround":265},[4,23,41,51,65,83,182,196],{"title":5,"icon":6,"path":7,"stem":8,"children":9,"page":22},"Getting started","i-lucide-rocket","\u002Fen\u002Fgetting-started","en\u002F1.getting-started",[10,14,18],{"title":11,"path":12,"stem":13},"Quick start","\u002Fen\u002Fgetting-started\u002Fquick-start","en\u002F1.getting-started\u002F1.quick-start",{"title":15,"path":16,"stem":17},"Trust model","\u002Fen\u002Fgetting-started\u002Ftrust-model","en\u002F1.getting-started\u002F2.trust-model",{"title":19,"path":20,"stem":21},"Enterprise integration journey","\u002Fen\u002Fgetting-started\u002Fenterprise-integration","en\u002F1.getting-started\u002F3.enterprise-integration",false,{"title":24,"icon":25,"path":26,"stem":27,"children":28,"page":22},"Storefront","i-lucide-store","\u002Fen\u002Fstorefront","en\u002F2.storefront",[29,33,37],{"title":30,"path":31,"stem":32},"Third-party Storefront","\u002Fen\u002Fstorefront\u002Fthird-party-storefront","en\u002F2.storefront\u002F1.third-party-storefront",{"title":34,"path":35,"stem":36},"Turnstile trust boundary","\u002Fen\u002Fstorefront\u002Fchallenge-and-turnstile","en\u002F2.storefront\u002F2.challenge-and-turnstile",{"title":38,"path":39,"stem":40},"Third-party Storefront public API","\u002Fen\u002Fstorefront\u002Fpublic-api","en\u002F2.storefront\u002F3.public-api",{"title":42,"icon":43,"path":44,"stem":45,"children":46,"page":22},"OAuth and identity","i-lucide-key-round","\u002Fen\u002Foauth","en\u002F3.oauth",[47],{"title":48,"path":49,"stem":50},"Third-party account authorization boundary","\u002Fen\u002Foauth\u002Fauthorization-code-pkce","en\u002F3.oauth\u002F1.authorization-code-pkce",{"title":52,"icon":53,"path":54,"stem":55,"children":56,"page":22},"Developer platform","i-lucide-blocks","\u002Fen\u002Fplatform","en\u002F4.platform",[57,61],{"title":58,"path":59,"stem":60},"Apps, versions, installations, and scopes","\u002Fen\u002Fplatform\u002Fapps-installations-scopes","en\u002F4.platform\u002F1.apps-installations-scopes",{"title":62,"path":63,"stem":64},"Origins, redirects, proxies, and environments","\u002Fen\u002Fplatform\u002Fsecurity-and-environments","en\u002F4.platform\u002F2.security-and-environments",{"title":66,"icon":67,"path":68,"stem":69,"children":70,"page":22},"Runtime extensions","i-lucide-workflow","\u002Fen\u002Fruntime","en\u002F5.runtime",[71,75,79],{"title":72,"path":73,"stem":74},"Installation Webhooks","\u002Fen\u002Fruntime\u002Fwebhooks","en\u002F5.runtime\u002F1.webhooks",{"title":76,"path":77,"stem":78},"Inventory synchronization","\u002Fen\u002Fruntime\u002Finventory-sync","en\u002F5.runtime\u002F2.inventory-sync",{"title":80,"path":81,"stem":82},"Automatic fulfillment providers","\u002Fen\u002Fruntime\u002Fauto-fulfillment","en\u002F5.runtime\u002F3.auto-fulfillment",{"title":84,"icon":85,"path":86,"stem":87,"children":88,"page":22},"API reference","i-lucide-braces","\u002Fen\u002Freference","en\u002F6.reference",[89,93,97],{"title":90,"path":91,"stem":92},"API Reference","\u002Fen\u002Freference\u002Fapi","en\u002F6.reference\u002F1.api",{"title":94,"path":95,"stem":96},"Errors, idempotency, and rate limits","\u002Fen\u002Freference\u002Ferrors-and-limits","en\u002F6.reference\u002F2.errors-and-limits",{"title":98,"path":99,"stem":100,"children":101,"page":22},"Endpoint catalog","\u002Fen\u002Freference\u002Foperations","en\u002F6.reference\u002F3.operations",[102,106,110,114,118,122,126,130,134,138,142,146,150,154,158,162,166,170,174,178],{"title":103,"path":104,"stem":105},"Get the public runtime configuration","\u002Fen\u002Freference\u002Foperations\u002Fget-public-runtime-config","en\u002F6.reference\u002F3.operations\u002F01.get-public-runtime-config",{"title":107,"path":108,"stem":109},"Get the public site bootstrap configuration","\u002Fen\u002Freference\u002Foperations\u002Fget-public-bootstrap","en\u002F6.reference\u002F3.operations\u002F02.get-public-bootstrap",{"title":111,"path":112,"stem":113},"Get public contact channels","\u002Fen\u002Freference\u002Foperations\u002Fget-public-contact","en\u002F6.reference\u002F3.operations\u002F03.get-public-contact",{"title":115,"path":116,"stem":117},"List current published legal documents by locale","\u002Fen\u002Freference\u002Foperations\u002Flist-public-legal-documents","en\u002F6.reference\u002F3.operations\u002F04.list-public-legal-documents",{"title":119,"path":120,"stem":121},"Get the published Storefront decoration","\u002Fen\u002Freference\u002Foperations\u002Fget-public-storefront-decoration","en\u002F6.reference\u002F3.operations\u002F05.get-public-storefront-decoration",{"title":123,"path":124,"stem":125},"Get the public store security configuration","\u002Fen\u002Freference\u002Foperations\u002Fget-public-store-security-config","en\u002F6.reference\u002F3.operations\u002F06.get-public-store-security-config",{"title":127,"path":128,"stem":129},"Search public products","\u002Fen\u002Freference\u002Foperations\u002Fsearch-public-products","en\u002F6.reference\u002F3.operations\u002F07.search-public-products",{"title":131,"path":132,"stem":133},"List public categories","\u002Fen\u002Freference\u002Foperations\u002Flist-public-categories","en\u002F6.reference\u002F3.operations\u002F08.list-public-categories",{"title":135,"path":136,"stem":137},"Get the installation credential identity","\u002Fen\u002Freference\u002Foperations\u002Fget-installation-credential-identity","en\u002F6.reference\u002F3.operations\u002F09.get-installation-credential-identity",{"title":139,"path":140,"stem":141},"Get the installation credential readiness","\u002Fen\u002Freference\u002Foperations\u002Fget-installation-credential-readiness","en\u002F6.reference\u002F3.operations\u002F10.get-installation-credential-readiness",{"title":143,"path":144,"stem":145},"List the public product catalog","\u002Fen\u002Freference\u002Foperations\u002Flist-public-products","en\u002F6.reference\u002F3.operations\u002F11.list-public-products",{"title":147,"path":148,"stem":149},"Get a public product by slug","\u002Fen\u002Freference\u002Foperations\u002Fget-public-product","en\u002F6.reference\u002F3.operations\u002F12.get-public-product",{"title":151,"path":152,"stem":153},"Get a public store profile","\u002Fen\u002Freference\u002Foperations\u002Fget-public-merchant","en\u002F6.reference\u002F3.operations\u002F13.get-public-merchant",{"title":155,"path":156,"stem":157},"List public products for a store","\u002Fen\u002Freference\u002Foperations\u002Flist-public-merchant-products","en\u002F6.reference\u002F3.operations\u002F14.list-public-merchant-products",{"title":159,"path":160,"stem":161},"List public categories for a store","\u002Fen\u002Freference\u002Foperations\u002Flist-public-merchant-categories","en\u002F6.reference\u002F3.operations\u002F15.list-public-merchant-categories",{"title":163,"path":164,"stem":165},"Get a public product for a store","\u002Fen\u002Freference\u002Foperations\u002Fget-public-merchant-product","en\u002F6.reference\u002F3.operations\u002F16.get-public-merchant-product",{"title":167,"path":168,"stem":169},"Get the current API Key identity and scopes","\u002Fen\u002Freference\u002Foperations\u002Fget-api-key-identity","en\u002F6.reference\u002F3.operations\u002F17.get-api-key-identity",{"title":171,"path":172,"stem":173},"List public categories with an API Key","\u002Fen\u002Freference\u002Foperations\u002Flist-api-key-catalog-categories","en\u002F6.reference\u002F3.operations\u002F18.list-api-key-catalog-categories",{"title":175,"path":176,"stem":177},"List public products with an API Key","\u002Fen\u002Freference\u002Foperations\u002Flist-api-key-catalog-products","en\u002F6.reference\u002F3.operations\u002F19.list-api-key-catalog-products",{"title":179,"path":180,"stem":181},"Get a public product with an API Key","\u002Fen\u002Freference\u002Foperations\u002Fget-api-key-catalog-product","en\u002F6.reference\u002F3.operations\u002F20.get-api-key-catalog-product",{"title":183,"icon":184,"path":185,"stem":186,"children":187,"page":22},"Examples","i-lucide-code-xml","\u002Fen\u002Fexamples","en\u002F7.examples",[188,192],{"title":189,"path":190,"stem":191},"Minimal Nuxt Storefront","\u002Fen\u002Fexamples\u002Fnuxt-storefront","en\u002F7.examples\u002F1.nuxt-storefront",{"title":193,"path":194,"stem":195},"Webhook verification","\u002Fen\u002Fexamples\u002Fwebhook-verification","en\u002F7.examples\u002F2.webhook-verification",{"title":197,"icon":198,"path":199,"stem":200,"children":201,"page":22},"Versions and support","i-lucide-life-buoy","\u002Fen\u002Foperations","en\u002F8.operations",[202,206],{"title":203,"path":204,"stem":205},"Versions, migrations, and changelog","\u002Fen\u002Foperations\u002Fversions-and-migrations","en\u002F8.operations\u002F1.versions-and-migrations",{"title":207,"path":208,"stem":209},"Support and security disclosure","\u002Fen\u002Foperations\u002Fsupport-and-security","en\u002F8.operations\u002F2.support-and-security",{"id":211,"title":62,"body":212,"description":258,"extension":259,"links":260,"meta":261,"navigation":262,"path":63,"seo":263,"stem":64,"__hash__":264},"docs_en\u002Fen\u002F4.platform\u002F2.security-and-environments.md",{"type":213,"value":214,"toc":254},"minimark",[215,219,223,226,242,245,248,251],[216,217,62],"h1",{"id":218},"origins-redirects-proxies-and-environments",[220,221,222],"p",{},"Production redirect URIs and browser Origins are exact HTTPS values with no credentials or fragments. Redirect URI matching includes path and registered query semantics. An Origin allowlist enables browser response access; it does not grant an OAuth scope or resource ownership.",[220,224,225],{},"A third-party reverse proxy must not display, embed, or imitate the Ayalink sign-in page; collect email, password, or MFA; or forward a global-session Cookie, authorization code, or token. Users sign in only on the official Ayalink authorization domain. The third party receives only its own app's minimal, short-lived, revocable grant. Origin, CORS, Host headers, tenant IDs, slugs, and proxy network location grant no authority.",[220,227,228,229,233,234,237,238,241],{},"A BFF is same-origin with the third-party application, stores only that application's OAuth grant, and uses an ",[230,231,232],"code",{},"HttpOnly",", ",[230,235,236],{},"Secure",", appropriately ",[230,239,240],{},"SameSite"," application-session Cookie. It must not replace the Ayalink authorization server, request an Ayalink password or MFA, forward an Ayalink Cookie to a merchant domain, or infer tenant ownership from Host headers. Server-side grants stay out of browser bundles, URLs, logs, and analytics.",[220,243,244],{},"A malicious proxy can use a look-alike domain, TLS termination, and injected scripts to record every account factor. Users should verify the official authorization domain. After suspected phishing, revoke the app\u002Finstallation grant from an official entry point, sign out, update the password, reconfigure MFA, and report through the official security channel.",[220,246,247],{},"Sandbox and production use different clients, installations, secrets, quotas, Webhook endpoints, mappings, intents, and data domains. A sandbox token is rejected by production even if its app and store identifiers look similar.",[220,249,250],{},"Environment-managed settings are read-only in Merchant\u002FAdmin and show their source. Secret values are displayed once at creation or rotation, then only as masked metadata. A missing encryption key or provider credential fails closed; the UI must not claim the capability is active.",[220,252,253],{},"DPoP, refresh-token rotation, token-family replay detection, and the user grant-management entry point are unavailable or pending security review. This page does not claim support for them. API Reference publishes no OAuth endpoint or request\u002Fresponse example before that review completes.",{"title":255,"searchDepth":256,"depth":256,"links":257},"",2,[],"Keep sandbox and production isolated and prevent Origin, redirect, and reverse-proxy confusion.","md",null,{},true,{"title":62,"description":258},"b7E9bkbHwO3A8xgiKGuuYQWZ8_DSUepqZazuN_LMWRw",[266,268],{"title":58,"path":59,"stem":60,"description":267,"children":-1},"Model immutable app versions and store-bound installations with least-privilege scopes.",{"title":72,"path":73,"stem":74,"description":269,"children":-1},"Verify installation-scoped Webhooks, rotate secrets, reject replay, and operate retries and dead-letter recovery.",1785955324321]