Secrets
- Do not publish TenantApiToken on GitHub or in public customer files.
- Do not share bot token in public channels.
- Website OAuth secret must remain server-side only (encrypted).
Staff access
Apply least privilege — grant integration access only to those who truly need it.
Rotation
If a secret leaks, rotate in Discord/dashboard immediately and update affected scripts.