API keys & integrations
6 live · 1 revoked · secrets shown once at creation, masked forever after — even here
| Integration | Secret | Scopes | Env | Rotated / next | Last used | |
|---|---|---|---|---|---|---|
Stripe · webhook signing payments events in |
wh_••••••••8B1 | payment_intent.*, refund.* | live | 2 Sep → 1 Dec | 4s ago | |
Stripe · restricted key refunds service out |
rk_live_••••9C4 | refunds:write · disputes:read | live | 2 Sep → 1 Dec | 6m ago (RET-01187 auto) | |
Afterpay · merchant BNPL checkout |
ap_live_••••77A | payments:capture · refunds | live | 14 Aug → 12 Nov | 22m ago | |
AusPost · shipping labels labels + locker drops |
apc_••••31F | labels:write · tracking:read | live | 30 Jul → 28 Oct | 9:00pm locker batch queued | |
StarTrack · tracking webhook scan events in |
stx_••••D02 | consignments:read | live | 30 Jul → 28 Oct | 4:30pm miss event (CF-12) | |
BI warehouse · read-only nightly sync, IP-allowlisted 203.0.113.0/24 |
bi_ro_••••5E9 | orders:read · no PII columns | live | 1 Sep → 30 Nov | 2:00am sync | |
Marketplace sync program ended Aug |
mk_••••00X | was: catalogue:read | revoked 12 Aug | — | revocation logged + partner notified |
Key rules
Secrets print once, at creation, to the creator's screen — then only hashes exist anywhere, including this table.
Every key = least scopes + an expiry; "no expiry" is not an option in the form.
Live keys need an IP allowlist or mTLS where the partner supports it (BI + Stripe do).
Kill = instant 401 everywhere + page to key owner; used twice this year, both drills < 90s.
Rotation calendar
AusPost + StarTrack28 Oct · owner ops
BI read-only30 Nov · owner data eng
Stripe pair + Afterpay1 Dec · owner Dan
Marketplace purge12 Nov · auto
Rotations are dual-key: new secret overlaps old for 24h so a Tuesday rotation never becomes a checkout outage.