Skip to content

Access control

Customer access to the backoffice is granted over the apps that correspond to them, with the customer profile. From there you configure the app, manage modules and launch campaigns.

The push API is authenticated with an API key, sent in the x-api-key header. The key is generated from the panel.

An API key allows notifying the devices of that app, so it must be used from a server and not from the code of the website or the app.

AWS access is managed following the least privilege principle.

MFA is mandatory for relevant administrative access.

Access to infrastructure and production is restricted to the minimum number of people necessary, and private access mechanisms or VPN are used where applicable.

To build and publish, Reskyt needs access to the project’s developer accounts. The scope is defined at the start: see App Store and Google Play accounts.

See architecture for the additional documentation delivered in an evaluation.