API Keys and Service Configuration

RanchAssist users use the tool; administrators configure integrations

RanchAssist users should not need to understand or manage developer infrastructure.

Normal RanchAssist tools must not ask users for Mapbox tokens, API keys, secret keys, client secrets, bearer tokens, OAuth access tokens, service-account keys, API base URLs, or similar deployment credentials.

Mapbox-enabled tools

Mapbox-enabled RanchAssist tools receive approved browser-safe configuration automatically from the deployment. A missing map configuration should produce an administrator/configuration message rather than a token-entry form.

Private secrets stay server-side

Private credentials are not supposed to be placed in project files, browser storage, exports, email summaries, URLs, or normal user-visible logs.

If you see a credential field

A normal RanchAssist end-user workflow should not contain one. Treat that as a deployment or product issue rather than entering a private credential into the interface.


Was this article helpful?