Security best practices
Guidance for integrating the NU Signal Partners API safely.
Protect secrets
- API key secrets and viewer-ID salts are shown or known only once. Store them in a secrets manager; never put them in source control, client bundles, logs, or error reports.
- If a secret is exposed, revoke or rotate it immediately (API keys).
Use keys only on the server
- Call the API from your backend. Never embed
nsp_test_ornsp_live_keys in browsers, mobile apps, or other distributed clients. - Proxy every client-initiated flow, such as playback-token requests, through your server so the key and viewer salt remain private.
Rotate keys regularly
- Rotate regularly and whenever exposure is suspected using overlap-and-revoke: create, deploy, verify, then revoke the old key. Revoking a key does not cancel tokens or sessions already issued; they expire by their own TTL, so keep TTLs short.
Hash viewer IDs — no PII
viewer_id_hashmust beSHA-256(stable_viewer_id + salt), computed on your side. Production accepts exactly 64 lowercase hexadecimal characters. Never send raw email, phone, or device IDs. NU receives and stores no raw PII (Playback API).- The same rule applies to playback
preferences: send only non-PII preference signals. Values containing@or spaces are rejected with422 validation_failed.
Restrict origins and IPs
- Set
allowed_originsso playback tokens are issued only for your domains, andallowed_ipsso API requests are pinned to your server addresses (API keys).
Use least-privilege scopes
- Grant each key only what its component needs; for example, ingestion needs
events:write, notsettlement:dispute. Separate high-volume and sensitive workloads (Authentication). - Keep
api_keys:writeonly on a vault-held operational key. Do not grant key-management scopes to playback or event runtime keys.
Do not expose playback URLs
webview_urland signed HLS/DASH manifests are short-lived (default 1,800 seconds, absolute maximum 7,200; Production default cap 1,800) and embed signed tokens. Treat them as bearer secrets: never log them, cache or share them afterexpires_at, or putwebview_urlin shareable links. Reissue as needed and openwebview_urlonly inside the viewer’s WebView or iframe.