UnifyIDDeveloper

Operations

Security requirements

Treat authorization artifacts and verified claims as sensitive authentication data throughout their lifecycle.

Required controls

  1. 1Require MFA for developer workspace members
  2. 2Use exact redirect URIs
  3. 3Generate fresh state, nonce, and PKCE values
  4. 4Exchange codes from a protected backend where possible
  5. 5Validate every token claim and signature
  6. 6Use pairwise sub as the account key
  7. 7Request and retain minimum data
  8. 8Redact all secrets and identity claims from logs

Identity isolation

UnifyID binds face assurance to the authenticated account’s verified reference and prevents one browser transaction from completing another account’s authorization. Each OAuth application receives a pairwise subject.

Data excluded from integrations

Raw documents, biometric templates, face embeddings, provider credentials, provider payloads, storage locations, passwords, and internal account IDs are outside the developer claim surface.

Production review

Production requires a complete website, support contact, legal URLs, an active client credential, a working webhook, exact redirect URIs, and administrative review. Restricted document-number access receives additional review.

Incident response

Revoke exposed credentials, rotate webhook secrets, invalidate affected sessions, preserve request IDs, and contact support without including tokens or personal data.

Was this page helpful?
UnifyID Developer Documentation · Version V.1 · Updated July 2026