Security best practices

Guidance for integrating the NU Signal Partners API safely.

Protect secrets

  • API key secrets and viewer-ID salts are shown or known only once. Store them in a secrets manager; never put them in source control, client bundles, logs, or error reports.
  • If a secret is exposed, revoke or rotate it immediately (API keys).

Use keys only on the server

  • Call the API from your backend. Never embed nsp_test_ or nsp_live_ keys in browsers, mobile apps, or other distributed clients.
  • Proxy every client-initiated flow, such as playback-token requests, through your server so the key and viewer salt remain private.

Rotate keys regularly

  • Rotate regularly and whenever exposure is suspected using overlap-and-revoke: create, deploy, verify, then revoke the old key. Revoking a key does not cancel tokens or sessions already issued; they expire by their own TTL, so keep TTLs short.

Hash viewer IDs — no PII

  • viewer_id_hash must be SHA-256(stable_viewer_id + salt), computed on your side. Production accepts exactly 64 lowercase hexadecimal characters. Never send raw email, phone, or device IDs. NU receives and stores no raw PII (Playback API).
  • The same rule applies to playback preferences: send only non-PII preference signals. Values containing @ or spaces are rejected with 422 validation_failed.

Restrict origins and IPs

  • Set allowed_origins so playback tokens are issued only for your domains, and allowed_ips so API requests are pinned to your server addresses (API keys).

Use least-privilege scopes

  • Grant each key only what its component needs; for example, ingestion needs events:write, not settlement:dispute. Separate high-volume and sensitive workloads (Authentication).
  • Keep api_keys:write only on a vault-held operational key. Do not grant key-management scopes to playback or event runtime keys.

Do not expose playback URLs

  • webview_url and signed HLS/DASH manifests are short-lived (default 1,800 seconds, absolute maximum 7,200; Production default cap 1,800) and embed signed tokens. Treat them as bearer secrets: never log them, cache or share them after expires_at, or put webview_url in shareable links. Reissue as needed and open webview_url only inside the viewer’s WebView or iframe.