master-zapier-plan-draft/packages/zapier-user-docs/12-security.md
George Lambert 345aeeead9
Some checks are pending
offline / test (push) Waiting to run
Bind each customer to a Verae userId for hop tracing
Signup registers/binds a Verae central user and stores veraeUserId. Public access stays the zappier API key. Chain JWTs stay server-side behind tokenRef. Authz, billing, and jobs.watch carry veraeUserId.
2026-09-11 16:18:06 -04:00

927 B

12. Security: what Zapier never sees

  • Zapier never connects to NATS, tree nodes, WORM archives, or api.veraetime.net.
  • NS1 nats-server stays on 127.0.0.1:4222. Operators use scripts/nats-tunnel.sh; it is not a public bind.
  • File bytes and private metadata never go on chain. Private metadata is only on authenticated archive replies.
  • API keys are x-api-key / Bearer tokens on HTTPS. Treat them like passwords; regenerating kills old Zaps.
  • The Verae central JWT from /auth/login is not your Zapier/portal token. Middleware holds it (or re-logins via tokenRef). veraeUserId is the public correlation id (vu_…).
  • Bloom filters are not an access-control list. On a hit, middleware still checks tenant/share before returning private records.

If a trace (simulator or DEBUG_VERAE) ever shows a zapier-platform-app hop with a verae.* subject, that is a bug — do not push the app.