Skip to content
PEYELIDocumentationPARTNER FIELD GUIDE / 1.3

Search the field guide

Local search · no data sentEsc to close
Partner guide/Integration
Security2 min read

Access follows ownership.

The security model begins with verified identity and current authority, then narrows to the requested operation.

Identity and permission are different checks.

First-party web services verify the user session; mobile services verify bearer credentials. Business authority is read from current membership and role, not accepted merely from client state. Personal operations check account ownership. Sensitive modules add live-session, origin, assurance or bounded-request checks as applicable.

The intended evaluation tenant must demonstrate denied cross-organization access, revoked permissions and disabled capability behavior. Source controls need runtime acceptance; this page does not claim that every deployed setting has been verified.

Sensitive card details belong with the issuer.

Card-provider foundations separate summary/control data from sensitive details. The intended integration opens issuer-hosted short-lived detail surfaces on the cardholder’s device rather than returning PAN, CVV or PIN through ordinary Peyeli records. This boundary requires provider acceptance and a reviewed program.

Evaluate the whole boundary.

Agree on who approves access, how it expires, how revocation is verified, and what happens during an incident. Public documents describe the model; account-specific evidence and confidential security questions belong in an approved review channel.