This article explains how the credentials for Overe client apps are secured, whether they expire, and what to do if you think a credential has been exposed. Client apps are used to access the Overe API. To create one, see Creating Apps to access Overe's API.
â
How client app authentication works
When you create a client app in Organization Settings > Client Apps, Overe generates a set of OAuth2 credentials: a client_id and a client_secret.
These credentials are not sent with your API calls. Your application exchanges them for a short-lived bearer access token, and that token is what is presented on each API request. Access tokens expire automatically, so your application requests a new one as needed.
Authentication for client apps is built on AWS Cognito, Amazon's managed identity service, rather than a custom authentication system. Credential storage, token issuance and token validation all use Cognito's standard mechanisms.
â
Do client app credentials expire?
No. Client app credentials do not expire by default, and there is currently no option to set an expiry date. This is intentional. Client apps are normally used for automation, and a scheduled expiry would break any workflow that depends on the credentials.
The access tokens issued from those credentials are short-lived and expire automatically.
If your security policy requires periodic credential rotation, create a new client app, update your automation to use the new credentials, and then delete the old client app.
â
Detecting unauthorised use
Any request made with credentials or tokens that are invalid, revoked, or not authorised for the requested resource is rejected at authentication.
The platform is also covered by AWS Cognito's standard authentication monitoring. This is platform-level protection. It does not include per-customer behavioural monitoring of API usage, such as anomaly detection on call patterns or source IP addresses for an individual client app.
To limit the impact of a leaked credential, we recommend that you:
Give each client app only the access level it needs.
Create a separate client app for each automation or integration, so you can revoke one without affecting the others.
Store the
client_secretin a secrets manager or vault, never in source code or shared documents.
What to do if a credential is leaked
If you suspect that a client app's credentials have been exposed:
Go to Organization Settings > Client Apps and delete the affected client app. This invalidates its credentials immediately.
Create a new client app with the access level you need.
Update your automation or integration with the new
client_idandclient_secret.
If you need help investigating a suspected leak, contact Overe support.
â
How to revoke a client app
To revoke a client app, delete it. Deletion takes effect immediately and invalidates both the client credentials and any access tokens that have already been issued from them. You do not need to revoke tokens separately, and a previously issued token cannot remain valid after the client app is deleted.
