JWT Token Best Security Practices#
The client credentials created in your Telegram channel, and the tokens obtained with them, allow operations to be performed on your behalf. You should take some measures to protect them. Here are some tips:Rotate your client credentials periodically: create new ones with /addclientcredentials, switch your integration over, and revoke the old ones with /removeclientcredentials.
Define only the necessary scope; do not grant access to unnecessary scopes.
Never store the token in publicly accessible locations.
Never share this token with third parties.
Never store this token in cloud services.
Never commit this token to version control systems (such as Git/GitHub).
Do not hard-code this token directly into programming code.
A legacy token, issued by the removed /apitoken command, cannot be invalidated from your side. It stays valid until the expiry date it was given at creation, up to 365 days after it was issued. If you suspect one was compromised, contact us immediately in your Telegram channel.
API Usage and Security Guidelines#
When integrating with our API, it is crucial to adhere to the following best practices to ensure secure and reliable operation: 1. Authentication#
Ensure proper authentication of your end users before allowing access to our services. This step is essential to avoid exposing our API indirectly, such as through a proxy, and ensures that only legitimate users are accessing the API. 2. Anti-DDOS Measures#
Implement effective anti-DDOS mechanisms on your side, such as a hashcash or CAPTCHA system, to prevent malicious users from leveraging your service to launch denial-of-service attacks. These measures help protect both your infrastructure and ours. 3. Deposit API: Address Validation#
Our deposit API includes a feature that allows partners to specify an end-user's DePix address for greater flexibility. However, this functionality can be exploited by malicious actors if they gain unauthorized direct or indirect access to the API (e.g., through your site or service). They can generate QR codes for deposits with arbitrary addresses for their benefit. Authenticate Users: Rigorously authenticate your users to ensure only legitimate access.
Monitor Usage: Implement monitoring to detect and address any suspicious or dishonest use of the deposit API.
By following these guidelines, you can help secure your integration and contribute to a safe API ecosystem.Modified at 2026-10-10 02:10:27