Helix.ID
Sign In

Security · 2 min

v0.2.1 · Updated 17 Sep 2026View as Markdown

Security considerations

The rules that keep the shared secret, the nonce and the signed URL doing their job.

Checklist

  • Nonce invalidation — clear req.session.helixNonce immediately after a successful callback to prevent replay attacks.
  • Secret management — store HELIX_SECRET in environment variables or a secrets manager. Never commit it to source control.
  • URL signing is server-side — createAuthUrl needs the shared secret, so it must run on your backend. Calling it from browser code would ship the secret to every visitor.
  • Never mutate a signed URL — appending, dropping or reordering query params after createAuthUrl invalidates sig. Pass the returned url through verbatim.
  • Query normalization — always normalize req.query to a flat Record before calling verifyCallback to avoid array injection.
  • HTTPS only — the callback endpoint must be served over HTTPS in production to protect the HMAC signature in transit.
  • Timestamp window — the SDK rejects callbacks older than a configured time window. Keep server clocks synchronized (NTP).