Protect Accounts, Credentials & Providers
Protect passwords, provider tokens, API keys, app secrets, webhook secrets, mobile sessions, and authorized users.
Security rules
- Use unique accounts and strong passwords.
- Enable available multi-factor authentication.
- Use least-privilege roles and provider scopes.
- Store secrets in protected fields or a secret-management service.
- Never place permanent tokens or keys in ordinary email, tickets, screenshots, mobile code, browser code, or repositories.
- Rotate an exposed credential immediately.
- Remove access when staff, vendors, or systems change.
- Review API keys, webhooks, AI, payment, Meta, Telegram, email, Google, and mobile access regularly.
Who should use it
Workspace owners, billing users and authorized account users.
Where to find it in Wemblo
Wemblo -> Account / Security Settings
Before you begin
- Confirm the correct workspace and account owner.
- Review the current plan, term and usage.
- Use verified billing or privacy contact details.
- Do not send passwords, permanent tokens or payment-card details.
Main concepts and fields
| Concept / Field | Meaning or Use |
|---|---|
| Account | One person's sign-in. |
| Workspace | Business environment. |
| Credential | Password, key, token or secret. |
| Role | Controls access. |
| Audit | Review of users, integrations and activity. |
Step-by-step instructions
- Open Wemblo -> Account / Security Settings.
- Confirm the correct workspace and authorized account.
- Review the current status, term, usage or request type.
- Enter or select the required information.
- Review price, effective date, consent or retention effects.
- Submit or save.
- Complete verification where required.
- Confirm the result and keep the reference.
Test and verification
- Complete one successful path with fictional data.
- Complete one invalid, failure or permission path.
- Confirm the result appears in the correct workspace and module.
- Confirm the correct person or team can review and continue the work.
Common issues and solutions
| Issue | What to Check |
|---|---|
| Change is not active | Workspace, effective date, payment verification or manual review. |
| Usage looks incorrect | Base allowance, add-on allowance, provider usage and reset date. |
| Request cannot be completed | Account authority, required verification and outstanding billing/security review. |
| Notification is missing | Billing contact, email, app notification and spam folder. |
Security, privacy, consent, cost and provider notes
- Use only data the business is authorized to process.
- External provider charges, policies, approvals, limits and availability remain separate.
- Do not expose passwords, API keys, tokens, webhook secrets, payment credentials or private customer data.
- Use human review for sensitive, regulated, urgent, financial or final decisions.
Last reviewed:

