Security practices
Keep credentials safe, scope access to each learner, and end access when it should end.
Keep API keys on your server
Section titled “Keep API keys on your server”API keys act on behalf of your whole workspace. Never put them in a browser bundle, a mobile app or a public repository. Your backend calls WireVoD; learners only ever receive playback sessions.
- Create one key per integration, with the smallest scope that works.
- Store keys in a secret manager. Only the
wvk_<prefix>part is safe to log. - Rotate by creating a new key, deploying it, then revoking the old one.
Give every learner their own access
Section titled “Give every learner their own access”- Create a playback session after your own checks: enrolment, subscription or payment.
- Keep session lifetimes short and close to the expected viewing time.
- End sessions with
/v1/playback/sessions/{id}when access should stop. - Use content protection for paid lessons: it protects the video itself, not only the link to it.
What WireVoD does for you
Section titled “What WireVoD does for you”- Isolation: every resource belongs to exactly one workspace, and isolation is verified automatically with every change to the platform.
- Credentials: keys and session secrets are never stored in readable form; user tokens are short-lived and refreshed securely.
- Uploads: upload URLs are personal to each part and expire within an hour; every part is verified before processing.
- Playback: every request is verified against the session; ended sessions stop working everywhere within about two minutes.
- Protection: protection keys are never stored or logged by WireVoD, and licences end with the session.
Found a vulnerability? Email security@wirevod.online.