Report suspected vulnerabilities privately to security@makepay.io.
- Load MakePay credentials at runtime from a secret manager or platform secure configuration.
- Do not ship merchant key secrets in client-side game binaries.
- Verify webhooks with
makepay::WebhookVerifierbefore granting entitlements. - Use server-side transports for purchases that affect balances, credits, or durable goods.