adobe-security-basics
Adobe Integration Security Baseline
Overview
Establish least privilege, credential rotation, webhook authenticity, signed-URL custody, log minimization, and destructive-action controls. This workflow produces a reviewable artifact and evidence before any live side effect.
Prerequisites
- Current first-party Adobe documentation for every selected service, API version, auth flow, limit, and lifecycle.
- Named product, identity, security, data, budget, release, and operations owners appropriate to the scope.
- Synthetic or approved non-production fixtures with secret and content canaries.
Current Contract
Effective authority combines credential type, organization/project/workspace, scopes, product profiles, service entitlement, resource ownership, and operation. Event authenticity requires recipient and signature validation or mTLS; a syntactically valid JSON body is not trusted. Recheck the dated evidence map before relying on mutable product behavior.
Authentication
Store secrets server-side, redact signed URLs as bearer capabilities, rotate by overlap-and-verify, and delete the old secret only after last-use evidence proves cutover.