What is your developer-dependent CMS actually costing you? Calculate your costs and get a full report
What is your developer-dependent CMS actually costing you? Calculate your costs and get a full report
Architects
This guide covers security best practices for Agility CMS implementations, including API security, authentication, and access control.
This guide covers security best practices for Agility CMS implementations, including API security, authentication, and access control.
Best Practices:
Tick Enable secure delivery on each webhook in Settings > Webhooks. Agility then signs every request with that webhook's own whsec_ signing secret, and your endpoint verifies the signature before it acts on the payload. See Verifying Signed Webhooks.
Don't check the instance Security Key on a webhook endpoint. Agility never sends it with a webhook; it is used for preview key validation.
whsec_ signing secretAgility CMS uses role-based access control:
Agility CMS automatically sanitizes:
Next: Integrations - Integration patterns