With minimum authorization get started
Every integration needs to access as much data and transactions as it needs. Using separate identities by application and workflow, rather than one broad authorized account, makes it easier to limit access and investigate.
Error logging isn't just for the technical team
In case of unsuccessful data transfer, the date, transaction type, relevant registration key and secure error summary must be stored. This way, the operations team can see which order or document will be reprocessed; The technical team also finds the source of the recurring problem faster.
Manage tokens and confidential information
API keys should not be kept in the code repository, screenshots, or public documentation. The person responsible for the access keys, the renewal period and the cancellation process must be clear; Access should be reviewed without delay in case of employee or supplier changes.
Bu içerik genel bilgilendirme amaçlıdır. Mevzuat ve teknik sürüm bilgileri uygulama öncesinde resmi, güncel kaynaklardan doğrulanmalıdır.
