Security
Landlords trust you with their tenants' personal and financial data. These are the rules DOOLAE enforces, and the ones you are responsible for.
What DOOLAE guarantees
- Isolation. Each request acts on one landlord account that connected your application, and everything it reads or changes is scoped to that account. An ID from another account behaves exactly like an ID that doesn't exist (
404). - Least privilege. A request can use a scope only if your key, your application and the landlord's grant all include it.
- Test mode is synthetic. Test keys reach only your sandbox. Its payments and LINE messages are simulated.
- No forged payments. No endpoint can mark a bill or payment as paid. Payment status comes only from the payment provider's signed confirmation.
- No credentials. The API never returns:
- landlords' sign-in details;
- LINE channel secrets, LINE access tokens or LINE user IDs;
- payment provider credentials or references.
- Keys are never stored. DOOLAE keeps only an HMAC fingerprint of each key. Keys sent in URLs are refused, and keys never appear in DOOLAE's logs.
- Explicit fields only. Responses contain only the fields documented in the API reference. Requests with undocumented fields are refused (
unknown_parameter), so nothing can be mass-assigned. - Signed webhooks with a timestamp, so receivers can refuse forged and replayed deliveries. DOOLAE delivers only to public HTTPS addresses.
Your responsibilities
Keep keys on your server
- Store keys in environment variables or a secret manager. Never put them in source code, mobile apps, browser JavaScript, logs, screenshots, tickets or URLs.
- Use separate keys per environment and per service, and give each only the scopes it needs.
- Rotate keys regularly, and revoke a key the moment you suspect it leaked. Revocation takes effect on the next request.
- Set an expiry on keys for temporary jobs.
Browser and mobile apps
API keys are secrets, and anything shipped to a browser or a phone can be extracted. Call the DOOLAE API from your backend, and give your frontend your own session or token. CORS is allowed only:
- from origins you list on the application (for development tools using test keys);
- from the developer portal's Try it out.
Requests from any other origin get 403 origin_not_allowed.
Webhooks
- Verify every signature, and refuse timestamps older than 5 minutes.
- Make your handler idempotent: de-duplicate on the event ID.
- Respond quickly, then process in the background.
Tenant data (PDPA)
Tenant names, phone numbers, email addresses and payment history are personal data under Thailand's Personal Data Protection Act.
- Collect only what you need, for the purpose the landlord approved.
- Store it encrypted.
- Delete it when the landlord disconnects your application, unless the law requires you to keep it.
- Report suspected breaches to DOOLAE within 72 hours.
Messages to tenants
Only send messages about the tenancy: bills, payments, building notices. Never send advertising. Respect each tenant's choice to turn messages off; DOOLAE enforces it.
Reporting a vulnerability
Email [email protected] with the details and the request_id values involved. Please don't test against accounts that aren't yours. Use your sandbox.