FluxPaySecurity
Security overview
FluxPay signs webhook payloads, enforces API key checks for merchant payment endpoints, and uses session tokens for dashboard access. Merchants should enable endpoint verification and restrict key scope by environment.
Webhook integrityHMAC + timestamp verification
Dashboard accessSession token required
RecommendationRotate keys and secrets periodically