✦Developers

API security

How the KERN ERP and KERN CRM APIs keep your company's data safe — and what you can do on your side.

Keys are never stored

KERN keeps only a one-way hash of each API key and client secret. The key is shown once when it's created; nobody at Codeverse can read it back. Keys carry a recognisable prefix (kern_live_, kern_test_, kern_secret_) so secret scanners can spot a leaked one.

Least access wins

Every call must pass three checks: the client's scopes (per module and screen, read or write), the permissions of the role it acts as, and your plan. A client can never do more than the role you chose — and never act as the platform owner.

Stop access at once

Revoke a key, or a whole client with all its keys and tokens, and it stops on every server immediately. Rotate keeps the old key for 24 hours so you can switch without downtime. Clients can be given an end date, and a company admin can switch all API access off with one button.

Short-lived tokens

OAuth access tokens last 15 minutes and stop the moment their client is revoked. Tokens for the API can't be used to sign in to KERN, and a person's KERN sign-in can't call the API.

IP allow-lists

Limit a client to the addresses or ranges your servers call from; anything else is refused.

An isolated sandbox

Sandbox keys only ever reach a separate copy of your company with sample data. Nothing in it sends emails or messages or uses AI credits. The docs' Try it accepts sandbox keys only.

Signed webhooks, safe addresses

Every webhook delivery is signed (HMAC-SHA256 with a per-webhook secret) and time-stamped. Webhooks go to public https addresses only — never to private or internal networks — checked when saved and before every delivery, with no redirects followed.

Safe retries

Writes need an Idempotency-Key, so a repeated request never creates a duplicate.

Limits and logs

Rate limits per client and monthly limits per plan protect the service. Every call is logged for 30 days — path, result, timing and address, never the data itself — and your admins can see it in KERN.

Encryption in transit

The API is served over HTTPS only.

No silent changes

The published API is frozen: a build check stops any change that would break it, and changes are announced in the changelog.

Your side

  • Keep keys on your servers — never in a web page, a mobile app or a public code repository.
  • Use one API client per application, with only the access it needs, and an IP allow-list where you can.
  • Check every webhook's signature and time-stamp before trusting it.
  • Rotate keys regularly, and revoke at once if one may have leaked.

If you find a security issue, please tell us through contact uswith the details and we'll respond quickly. Please don't test against other companies' data.

Found a security issue?