At Cobre, we make security seamless and accessible. Obtaining and using your API keys is straightforward, so you can integrate and operate on our platform securely from day one. Every API request must be made over HTTPS (TLS 1.2 or 1.3), establishing a secure environment for your transactions and protecting against the vulnerabilities of plain HTTP. With Cobre, strong security comes with minimal effort.Cobre strongly advise to consider taking the following security measures when integrating our APIs:
Store API credentials in a secure location - e.g., a vault (e.g., Hashicorp Vault, CyberArk, AWS Secrets Manager)
Rotate API secrets frequently (Recommendation - once a month)
Configure API Whitelisting on both sides (Client and Cobre)
Cobre IPs: 50.17.12.196, 54.173.144.191
To configure Client IPs, a ticket must be sent to soporte@cobre.co
Configure Secure Key for Webhooks
Separate the Dev/Test and Production environments to segregate access - Cobre offers independent environments to facilitate this separation.