Account and security
The Aikey365 console manages account settings, API keys, wallet information, and usage.
Account protection
The current platform code includes capabilities for two-factor authentication, passkeys, and OAuth bindings. Visibility depends on platform configuration.
Recommended practices:
- Enable additional authentication methods when available.
- Do not reuse passwords.
- Review old OAuth bindings and API keys.
- Use dedicated production keys rather than personal development keys.
API credentials are separate from web sessions
API requests normally use:
http
Authorization: Bearer YOUR_API_KEYDo not mix browser session credentials with API keys.
Do not embed server keys in public clients
A browser or downloadable app cannot safely protect a long-lived backend secret.
Prefer:
text
Browser / App -> Your Backend -> Aikey365 APIYour backend can apply user authentication, rate limits, auditing, and business rules before calling Aikey365.
If a key may be exposed
- Disable or delete it in the console.
- Create a replacement key.
- Update deployed services.
- Review usage and logs for unexpected calls.
- Check source repositories, CI logs, screenshots, and chat history for leakage.