Keep keys on your server.
Do not embed secret API credentials in browser JavaScript, public repositories or customer-facing pages.
Understand the practices and responsibilities that support a safer payment journey.
Payment security depends on how the platform, the merchant and the customer handle each step. These principles help your business use Flux responsibly.
Review the integration documentation for the controls relevant to your application and keep your credentials private.
Do not embed secret API credentials in browser JavaScript, public repositories or customer-facing pages.
Use the documented status verification flow. A successful-looking screen is not a substitute for a trusted transaction result.
Use a strong, unique password. Review suspicious account activity and contact support if credentials may be exposed.
A request timeout does not establish failure. Follow up using the original transaction reference before retrying a payout.
Contact merchant support with the payment reference and a description of the issue. Avoid sending passwords, secret keys or full payment credentials.
Open support ↗