Skip to main content

How to send Tie your credentials securely

Tie asked me for API credentials or a secret key. What is the safest way to send them?

T
Written by Tim Hughes

During setup, Tie asks for a few credentials so we can connect to your store and your email platform. None of them are account passwords, and none of them let anyone log in as you. This article covers which values are actually sensitive and the safest way to get them to us.

What we ask for, and what is sensitive

Credential

Sensitive?

What it is

Shopify Client ID

No

An identifier for the custom app in your store

Shopify secret

Yes

Treat it like a password

Klaviyo Public API Key (Site ID)

No

Public by design

Klaviyo Private API Key

Yes

Klaviyo shows it one time only

Tie never asks for your Shopify or Klaviyo account password, and never asks for admin login access to your accounts.

Send anything sensitive through a single-use link

For the values marked Yes above, the safest route is a link that can only be opened once, so the credential is destroyed the moment we read it and cannot sit in a message or an inbox waiting to be found later.

If your team already has a tool for this, use it. Otherwise, plenty of customers use a free single-use secret service, such as onetimesecret.com, which needs no account. Tie does not endorse any particular tool, so use whatever your own security policy allows.

However you generate it, the flow is the same:

  1. Put the value into the tool and generate the link.

  2. Send the link to your Tie contact.

  3. We open it once and confirm we have it.

If you set a passphrase, send that in a separate message from the link. If the link turns out to have already been opened by the time we get to it, we will tell you and ask for a fresh one.

The link itself is safe to send over Slack or email. It is the credential that must not travel that way.

What not to use

Please do not send a sensitive value in a plain email, and do not post one in your shared Slack channel. In both places the value persists in sent folders, channel history, forwards, notifications, and backups on both sides, outside anyone's control, and it cannot be reliably pulled back.

For the values marked No in the table above, there is nothing to protect, so email or Slack is fine.

If none of this works on your side, tell your Tie contact and we will sort out a method that does.

After we receive them

Your Tie contact confirms receipt, and the credential goes into Tie's internal credential vault, where access is limited to the people working on your account.

If a credential ever needs to be replaced, whether it was rotated, revoked, or simply stopped working, tell your Tie contact and send the new value the same way. Nothing on your side needs to be undone first.

Did this answer your question?