Skip to content

Resources/Protect

Provider access

Prepare provider access safely

Confirm the account path and minimum access needed without sending credentials through a public form or report.

Audience
Engineering and security reviewers preparing an approved provider connection.
Question
How can Loometry run the agreed comparison without broad or browser-exposed credentials?
01

Confirm technical fit before sharing access

Start with non-secret facts: provider, endpoint, model identifiers, account or gateway arrangement, region constraints, rate limits, and the required assessment timing.

  1. 01

    Verify that both options are visible to the approved account.

  2. 02

    Identify any gateway or network path that changes the request.

  3. 03

    Estimate an assessment budget and provider-side limit.

02

Use the narrowest approved credential

Provider credentials stay server-side and are used only for the agreed work. They must not appear in public forms, prompts, browser storage, screenshots, reports, or source control.

  1. 01

    Create or select a credential scoped to the required provider capability when available.

  2. 02

    Set spend and rate limits appropriate to the assessment.

  3. 03

    Agree who can provide, rotate, and revoke access.

  4. 04

    Remove or rotate the credential after the agreed work.

03

Keep access facts out of the customer presentation

The assessment identifies the provider path and configuration needed to interpret the result. It does not reproduce secrets, customer records, or unnecessary internal identifiers.

Worked example

Example: safe first contact

Good: “We use Provider A through an internal gateway and are considering Provider B this quarter.” Not suitable for the form: API keys, confidential prompts, customer records, or gateway credentials.