---
title: "Security"
description: "The rules that keep the shared secret, the nonce and the signed URL doing their job."
source: "/docs/security"
updated: "2026-09-24"
---

# Security considerations

The rules that keep the shared secret, the nonce and the signed URL doing their job.

## Checklist

- **Nonce invalidation** - clear `req.session.helixNonce` immediately after a successful callback to prevent replay attacks.
- **Secret management** - store `HELIX_SECRET` in environment variables or a secrets manager. Never commit it to source control.
- **URL signing is server-side** - `createAuthUrl` needs the shared secret, so it must run on your backend. Calling it from browser code would ship the secret to every visitor.
- **Never mutate a signed URL** - appending, dropping or reordering query params after `createAuthUrl` invalidates `sig`. Pass the returned `url` through verbatim.
- **Query normalization** - always normalize `req.query` to a flat `Record` before calling `verifyCallback` to avoid array injection.
- **HTTPS only** - the callback endpoint must be served over HTTPS in production to protect the HMAC signature in transit.
- **Timestamp window** - the SDK rejects callbacks older than a configured time window. Keep server clocks synchronized (NTP).


## Sitemap

See the full [sitemap](https://helix.id/sitemap.md) for all pages.
