SimplyParseDocs

Security

How API access, webhook deliveries and your data are protected, and what to do on your side.

API access

  • Every request is authenticated with an API token: Authorization: Token <token>. See Authentication.
  • Tokens can have an expiry, and you can deactivate or delete them at any time in Settings → API Tokens. They stop working immediately.
  • Tokens act for the account that created them. Keep them on your servers, never in browser or mobile code.

In transit

The API and the app are served over HTTPS. Use https:// URLs for your webhooks too, so payloads and secret headers are encrypted on the way to you.

Webhook deliveries

  • Every delivery is signed with X-SimplyParse-Signature, an HMAC-SHA256 of the payload. See Verify signatures.
  • Add a secret header with a random value to each webhook and check it in your receiver. The signature proves integrity; the secret proves the sender.
  • Respond only with a status code. Don't echo payload data back.

Your data

  • Documents, parsed data and integrations belong to your organization's account.
  • Parsers have a Retain Processed Data setting. Turn it off and set a retention period to have processed data archived automatically after that many days. Archived entries no longer appear in API responses.
  • Templates in the library are shared starting points. Using one creates a private copy, and nothing you process with your copy is visible to anyone else.

Your checklist

  • Tokens are stored in a secrets manager or environment variables, not in code.
  • Each integration and environment has its own token.
  • Webhook endpoints use HTTPS, check a secret header and verify signatures.
  • Webhook handlers are idempotent on entry_id.
  • Retention settings match your data policy.

On this page