Watch-IP security and API key handling
This page describes the access controls actually implemented in the Watch-IP API today: how the two key types work, how origins are enforced, how keys can be rotated or revoked, and how to report a security issue. It does not claim a compliance certification or independent security audit — none has been completed as of this writing.
Two key types, two different controls
Publishable keys (used for GET /v1/geo and POST /v1/email/validate) are designed to run in browser code and are not secret — the control is the allowed-origins list configured for the key, checked against the request's Origin/Referer header. Secret keys (used for GET/POST /v1/lookup and POST /v1/risk/check) are server-to-server credentials with no origin check at all, since there's no browser Origin header on a backend call; treat a secret key like a database password, not a public identifier. See authentication for the request format each key type expects.
How origin-locking is enforced
A publishable-key request from an origin not on the key's allowed list gets a 403 with no Access-Control-Allow-Origin header set. The browser blocking that response before your page's JavaScript can read it is the actual enforcement — the JSON error body is secondary. Origin-locking does not make the key itself secret, and it does not stop a non-browser client from sending a forged Origin header; it specifically protects the browser-call surface.
Transport and storage
Traffic to the API and dashboard is encrypted in transit (TLS/HTTPS); the API does not accept plaintext HTTP for key-authenticated requests. API keys are stored hashed (SHA-256), not in plaintext, so a database compromise alone would not expose usable key values.
Rotation and revocation
You can revoke or rotate a key from the dashboard. Revocation is not instant everywhere: key validity is cached for up to 5 minutes after a lookup, so a revoked key can continue to be accepted for up to 5 minutes after you revoke it — factor that into how quickly you can cut off access after a suspected compromise, and rotate proactively rather than relying on revocation alone for a time-sensitive incident.
Rate limiting
Every key is rate-limited per customer account on a fixed one-minute window, shared across whichever endpoints you call — not a per-route budget. This limits the damage a single leaked or misused key can do in a short window, though it is not itself a substitute for rotating a compromised key.
Reporting a security issue
Email security@watch-ip.com if you believe a key has been compromised or you've found a security issue in the API or dashboard. We don't currently run a public bug-bounty program or hold a third-party security certification — if that changes, this page will say so with a date, not a badge.