Skip to content

Security

The Unique API is read-only and exposes only the operational data your integration needs. This page describes the controls that protect it.

  • All traffic is served over HTTPS with TLS 1.2 or newer. Plain HTTP is refused, not redirected.
  • HSTS is enabled on every API and documentation domain.
  • OAuth 2.0 client credentials. Each integration gets its own client_id and client_secret. Access tokens are signed JWTs that expire after one hour; there are no long-lived bearer tokens.
  • Secrets are stored hashed. We cannot read your client_secret after it is issued. If you lose it, we issue a new one.
  • Tenant isolation comes from the token. The locations a request can read are bound to the credentials that obtained the token. No parameter can widen that scope; asking for a location you cannot see returns 403, and asking for a task outside your scope returns 404.
  • Least privilege. Tokens carry scopes (tasks:read, locations:read) and every endpoint checks them. The v1 API has no write operations.
  • Optional IP allowlisting. Credentials can be restricted to your egress IP ranges.

The API returns a fixed, documented set of fields per resource. Internal data such as pricing, approval workflow and the identity of the technicians who performed the work is never included in responses.

  • Secrets are delivered through a one-time secure link, never over email or chat.
  • Each client can hold two active secrets so rotations need no downtime.
  • Revocation takes effect immediately for new tokens; tokens already issued expire within one hour.
  • Per-client rate limits on every endpoint, with a stricter limit on the token endpoint.
  • Repeated failed authentication attempts are throttled.
  • The API runs on Google Cloud. Data is encrypted at rest by Google Cloud and in transit between services.
  • Sandbox and production are separate environments with separate credentials; sandbox contains synthetic data only.
  • Every request is logged with its client_id, endpoint, status, source IP and request_id.
  • Logs never contain access tokens or client secrets.
  • On request, we can provide the access history of your credentials.

Email security@uniqueonthego.com. Include the affected endpoint, the request_id when you have one, and steps to reproduce. We acknowledge reports within one business day.

If you suspect your credentials have leaked, write to the same address. We revoke them first and investigate after.

We ask researchers to act in good faith: do not access data that is not yours, do not degrade the service, and give us reasonable time to fix an issue before disclosing it.