Security

Operate API access with clear boundaries

Practical controls for API keys, account access, request data, and incident response—without unsupported certification claims.

Last updated: 2026-08-28

Protect credentials

Store HippoAPI keys in server-side secret storage or environment variables. Never ship a production key in browser, mobile, desktop, or public repository code.

Use separate keys for development, staging, and production. Apply expiry, quota, model, and IP restrictions when they fit the deployment, and revoke a key immediately if exposure is suspected.

Account and request visibility

Use the console to review keys, wallet activity, and request logs. Account security features shown in the console depend on the current deployment configuration.

Do not send secrets or regulated data unless your organization has completed its own risk review and agreed suitable data-processing terms with HippoAPI.

Report a security issue

Send a concise report to [email protected] with the affected URL, impact, reproduction steps, and a safe way to contact you. Do not include live credentials or exploit customer data.

HippoAPI does not claim certifications, audit reports, or contractual security controls on this public page. Enterprise requirements should be confirmed in writing before purchase.