Skip to content

Security

How TokenGate protects API traffic, credentials and user data.

TLS everywhere

All traffic between your application and TokenGate is encrypted in transit using TLS 1.2 or higher.

No private keys on the website

Wallet authentication, API keys and account credentials are managed only in the external TokenGate application. The public website never requests or stores them.

Provider credential isolation

Backend provider credentials are stored encrypted and never exposed through the public API or documentation site.

Rate limiting

API usage is rate-limited per account to prevent abuse and ensure fair capacity across all users.

Reporting issues

If you discover a security issue, please contact us at security@tokengate.com. We respond to responsible disclosures promptly.