Apiable

Platform

Security and compliance

Security mechanisms in Apiable: Authorization Server credentials in AWS Secrets Manager, portal MFA, an audit log, signed outbound webhooks, SSL through AWS Certificate Manager, and scoped OAuth2 access enforced on your gateway. For compliance documentation, contact Apiable.

This page lists security mechanisms in Apiable, each tied to how the product works. Apiable is a control plane: it configures access on your gateway and authorization server, keeps the Authorization Server credentials you give it in a secrets store, and records activity. For formal compliance documentation, contact Apiable.

How does Apiable store Authorization Server credentials?

In AWS Secrets Manager. When you connect an Authorization Server, the client IDs and secrets you enter are written to Secrets Manager, not to the configuration record in Apiable's database. Apiable reads them back when an operation needs them.

This covers both kinds of credential an Authorization Server integration can hold: the Dynamic Client Registration client and the admin client. The stored record keeps non-secret settings such as the server URL and the connection status. See Authorization Servers for connecting one.

Does Apiable support multi-factor authentication?

Yes, for your API Portal. Under Multi-factor Authentication, each portal is set to ON, OPTIONAL or OFF, which decides whether users who sign in to the portal must, may or cannot use a second factor.

SettingWhat it means for portal users
ONEvery user needs at least one additional factor beyond username and password each time they sign in.
OPTIONALEach user chooses whether to turn on a second factor.
OFFUsers sign in with username and password only.

Changing the setting sends a request to Apiable, which applies it to your portal's sign-in. The control stays locked and shows a notice until the change is in force. The control is available to the Organisation Owner, Organisation Admins and Portal Admins. See Portal security and MFA for the full flow.

Does Apiable keep an audit log?

Yes. The audit log records activity in your dashboard and your API Portal, on separate Dashboard and Portal tabs. You can search it, filter by actor, event type and time range, and expand an entry to see its details.

The detail view does not show fields whose names mark them as secrets, such as those containing password, secret, token, key or credential. See Audit log for the filters and event types.

Are Apiable's outbound webhooks signed?

Yes. Each outbound webhook delivery is signed with HMAC-SHA256, following the Standard Webhooks specification, using the signing secret of the webhook. The delivery carries three headers and a versioned signature.

ElementValue
Signing secretBase64, prefixed whsec_
Headerswebhook-id, webhook-timestamp, webhook-signature
AlgorithmHMAC-SHA256, signature version v1

See Webhooks for the payload and the verification steps.

How is SSL handled for custom domains?

Apiable provisions certificates through AWS Certificate Manager with DNS validation. When you add a custom domain, Apiable requests the certificates and gives you CNAME records to add at your DNS provider. The certificate is issued before your portal switches over.

You do not upload or manage certificates yourself. See Custom domain for the step-by-step flow and the validation states.

How is API access secured?

Through credentials and scoped OAuth2 access enforced on your own gateway. Apiable provisions an API key or OAuth client per subscription, your authorization server issues tokens carrying the granted scopes, and your gateway checks them before a request reaches your backend.

Scope-based access control runs with the Authorization Servers Apiable connects to: Keycloak, Auth0 and Duende. With Duende, a client's scopes are set at registration. A gateway either issues OAuth natively or binds an external Authorization Server. Because the gateway enforces access at request time, the access boundary lives on your infrastructure. See Access control and The no-proxy model.

What about compliance certifications and audits?

Contact Apiable for current compliance documentation. This page describes the security mechanisms in the product rather than certifications or audit results.

Where to next