927 B
927 B
12. Security: what Zapier never sees
- Zapier never connects to NATS, tree nodes, WORM archives, or
api.veraetime.net. - NS1
nats-serverstays on 127.0.0.1:4222. Operators usescripts/nats-tunnel.sh; it is not a public bind. - File bytes and private metadata never go on chain. Private metadata is only on authenticated archive replies.
- API keys are
x-api-key/ Bearer tokens on HTTPS. Treat them like passwords; regenerating kills old Zaps. - The Verae central JWT from
/auth/loginis not your Zapier/portal token. Middleware holds it (or re-logins viatokenRef).veraeUserIdis the public correlation id (vu_…). - Bloom filters are not an access-control list. On a hit, middleware still checks tenant/share before returning private records.
If a trace (simulator or DEBUG_VERAE) ever shows a zapier-platform-app hop with a verae.* subject, that is a bug — do not push the app.