Legal
API Security
Authentication, OAuth, JWT, rate limits, IP restrictions, webhooks, and versioning for Khodi Mart APIs.
Last updated: July 2026
1. Authentication
Seller, supplier, warehouse, and admin APIs require authenticated sessions. Production clients should send bearer JWT access tokens issued after successful login. Unauthenticated access is limited to public catalogue / marketing endpoints.
2. OAuth (marketplaces)
- Marketplace integrations use OAuth authorization code (or partner-equivalent) flows.
- Tokens are stored encrypted server-side (AES-256-GCM).
- Frontend never receives long-lived marketplace refresh tokens.
- Disconnect deletes credential material and stops sync workers.
- Consent scopes follow least privilege for the features you enable.
3. JWT
- Short-lived access tokens; refresh handled by the Platform auth flow.
- Claims encode role and subject; APIs enforce role and tenant (seller_id) scope.
- Tokens must not be logged, committed to git, or embedded in public URLs.
- Compromise response: rotate password / revoke sessions and reconnect integrations if needed.
4. Rate limits
APIs and marketplace worker calls are rate-limited to protect platform stability and respect partner quotas. Exceeding limits returns HTTP 429 where applicable. Repeated abuse may result in temporary blocks under the Acceptable Use Policy.
5. IP restrictions
Enterprise customers may request IP allowlisting for sensitive admin or webhook endpoints under a signed agreement. Standard multi-tenant SaaS accounts use authenticated access without fixed IP binding.
6. API versioning
Public and partner APIs are versioned (e.g. /api/v1/...). Breaking changes are communicated via Docs / Release Notes. Deprecation windows are provided where feasible. See /api-docs for the developer portal roadmap.
7. Webhooks
- Where webhooks are offered, verify signatures / shared secrets before trusting payloads.
- Rotate secrets if compromised.
- Idempotency: design consumers to handle duplicate deliveries safely.
- TLS required for webhook endpoints in production.
8. Token refresh & sync logs
Marketplace refresh is performed server-side by workers. Sync and connect/disconnect events are audit-logged without storing secrets in log lines. Failed refreshes surface as connection health issues in the seller Integrations UI.
9. Contact
API security questions: security@khodi.in. Developer portal: /api-docs. General Docs: /docs.
Also see Trust Center, Privacy, Terms, Security, Compliance, Cookies, DPA, Disclosure, and Help.
