As a developer who shares code related to the TopstepX API, I would like a special development account with its own API key.
I noticed myself leaving my PRIVATE API KEY in my source during development. Thatβs my fault and there are ways for me to fix that, but I think I will not be alone and it will become more prevalent as people use the API more. I know Github has free tools to detect security keys in plain-text, but there will be other opportunities to leak one and have issues with your API customers.
I think using a solution like adding a privilege or claim to development tokens to limit the token to practice/development accounts or something on the backend would be a great solution.
Please authenticate to join the conversation.
In Review
π‘ Feature Request
Risk Tools
10 months ago

Adam Marquette
Get notified by email when there are changes.
In Review
π‘ Feature Request
Risk Tools
10 months ago

Adam Marquette
Get notified by email when there are changes.