Square OAuth Best Practices - https://developer.squareup.com/docs/o...
Square OAuth API - https://developer.squareup.com/docs/o...
When building an OAuth integration, it's very important that you encrypt the access tokens you obtain before storing them. It'll help protect you and your app's users.
OAuth access tokens, refresh tokens, and the application secret all have privileged access (or the potential to get privileged access) to seller resources. You should use them in a secure environment and protect access to them following best practices.
In this example we'll show how to encrypt using Node JS, but each language has their own libraries for encrypting and the process should be roughly the same.
00:00:00 - Introduction
00:00:11 - Importance of Encrypting Access Tokens
00:00:35 - Node Crypto Library Functions Overview
00:00:57 - Importance of Protecting the Encryption Key
00:01:15 - Encrypting Tokens: The Create Cipher IV Function
00:01:47 - Encryption Process Details
00:02:08 - Completing the Encryption Process
00:02:29 - Returning the IV and Encrypted Token
00:02:49 - Decrypting Tokens: Overview
00:03:12 - Decrypting Tokens: Step-by-Step Process
00:03:33 - Practical Example: Encrypting a Token
00:03:53 - Output Demonstration: Encrypted Token
00:04:15 - Decrypting the Encrypted Token
00:04:39 - Conclusion and Reminder to Protect Encryption Keys
Square Developer Community - https://squ.re/slack
Square Developer Twitter - / squaredev
Square Developer Forums - https://developer.squareup.com/forums