Security
How TokenGate protects API traffic, credentials and user data.
TLS everywhere
All traffic between your application and TokenGate is encrypted in transit using TLS 1.2 or higher.
No private keys on the website
Wallet authentication, API keys and account credentials are managed only in the external TokenGate application. The public website never requests or stores them.
Provider credential isolation
Backend provider credentials are stored encrypted and never exposed through the public API or documentation site.
Rate limiting
API usage is rate-limited per account to prevent abuse and ensure fair capacity across all users.
Reporting issues
If you discover a security issue, please contact us at security@tokengate.com. We respond to responsible disclosures promptly.
