Skip to content

Wewed developers

Authentication

How supported integrations will authenticate and remain within approved permissions.

Back to Developer Center
API preview

Credentials

API keys, OAuth credentials and webhook signing secrets must be treated as secrets, stored server-side where appropriate and rotated after suspected exposure. Privileged credentials must not be embedded in publicly distributed client code.

Least privilege

A valid credential does not override tenant, wedding, user-role or resource authorization. Integrations should receive only the scopes and wedding access required for the approved purpose.