Security
The Unique API is read-only and exposes only the operational data your integration needs. This page describes the controls that protect it.
Transport
Section titled “Transport”- All traffic is served over HTTPS with TLS 1.2 or newer. Plain HTTP is refused, not redirected.
- HSTS is enabled on every API and documentation domain.
Authentication and access control
Section titled “Authentication and access control”- OAuth 2.0 client credentials. Each integration gets its own
client_idandclient_secret. Access tokens are signed JWTs that expire after one hour; there are no long-lived bearer tokens. - Secrets are stored hashed. We cannot read your
client_secretafter it is issued. If you lose it, we issue a new one. - Tenant isolation comes from the token. The locations a request can read
are bound to the credentials that obtained the token. No parameter can widen
that scope; asking for a location you cannot see returns
403, and asking for a task outside your scope returns404. - Least privilege. Tokens carry scopes (
tasks:read,locations:read) and every endpoint checks them. The v1 API has no write operations. - Optional IP allowlisting. Credentials can be restricted to your egress IP ranges.
Data minimization
Section titled “Data minimization”The API returns a fixed, documented set of fields per resource. Internal data such as pricing, approval workflow and the identity of the technicians who performed the work is never included in responses.
Credential lifecycle
Section titled “Credential lifecycle”- Secrets are delivered through a one-time secure link, never over email or chat.
- Each client can hold two active secrets so rotations need no downtime.
- Revocation takes effect immediately for new tokens; tokens already issued expire within one hour.
Abuse protection
Section titled “Abuse protection”- Per-client rate limits on every endpoint, with a stricter limit on the token endpoint.
- Repeated failed authentication attempts are throttled.
Infrastructure
Section titled “Infrastructure”- The API runs on Google Cloud. Data is encrypted at rest by Google Cloud and in transit between services.
- Sandbox and production are separate environments with separate credentials; sandbox contains synthetic data only.
Logging and audit
Section titled “Logging and audit”- Every request is logged with its
client_id, endpoint, status, source IP andrequest_id. - Logs never contain access tokens or client secrets.
- On request, we can provide the access history of your credentials.
Reporting a vulnerability or incident
Section titled “Reporting a vulnerability or incident”Email security@uniqueonthego.com. Include
the affected endpoint, the request_id when you have one, and steps to
reproduce. We acknowledge reports within one business day.
If you suspect your credentials have leaked, write to the same address. We revoke them first and investigate after.
We ask researchers to act in good faith: do not access data that is not yours, do not degrade the service, and give us reasonable time to fix an issue before disclosing it.