Skip to main content

Awesome to be able to generate the Api keys ourselves but I noted the keys are visible in the console to all ‘Community Managers’ or ‘Admins’ and checked with our PMs who pointed out that it is usually masked?

See from our PX prod config

Best practice

 

Hi Anirban,

As far as I know, the IDs are visible, but the keys are hidden :-) 

So it shows you the secret once, at generation:

 

And then afterwards it only shows you the ID (which is useful, since it tells you which is which in logfiles etc.).

 


I think there could be scope for a half-and-half approach here though. It can definitely be useful to have the Client ID accessible, but perhaps hide it behind a Spoiler of some sort, so that it helps to prevent accidental leaks in screenshots, just in case!


I think there could be scope for a half-and-half approach here though. It can definitely be useful to have the Client ID accessible, but perhaps hide it behind a Spoiler of some sort, so that it helps to prevent accidental leaks in screenshots, just in case!

Awesome. True. Thanks for expanding with your thoughts Blatoise!


@Blastoise186 what would be the reason to hide it?
I see them as kind of a username (Client ID) and password (Client Secret). Just as everyone knows your userid on this forum, but don’t know your password.


@Blastoise186 what would be the reason to hide it?
I see them as kind of a username (Client ID) and password (Client Secret). Just as everyone knows your userid on this forum, but don’t know your password.

That’s a good point @bas. I was a one-off user in this case and wanted to make sure that we are covered, which I’m happy to learn. 👍🏽


Updated idea statusNewClosed

Reply