Partner obligations
Keep permanent secrets server-side, rotate them on suspicion or schedule, use TLS, validate webhook signatures, use unique idempotency keys and restrict allowed origins and IP ranges.
Prohibited conduct
Do not probe another tenant, evade rate limits, replay requests, expose player hidden information, bypass the launch boundary, manipulate outcomes or run destructive tests outside an approved sandbox.
Vulnerability reporting
Report suspected vulnerabilities privately with reproduction detail and avoid accessing unnecessary data. A monitored security address, safe-harbor language and response targets must be approved before publication.
Platform controls
OKEYHAN uses signed requests, nonce replay protection, short-lived sessions, server authority, tenant isolation, audit evidence, reconciliation and MFA-gated privileged access.