P
PassTools
Wallet pass management
Security
Security and trust
Learn how PassTools protects account access, workspace data, provider credentials, activity history, and public pass links.
Security overview
Workspace APIs
Protected
Membership and permission checks
Provider mode
Controlled
Credentials stay out of status views
Public links
Limited
Non-guessable IDs and request limits
Workspace isolation
PassTools checks workspace membership and permissions before returning protected account data.
In place
Protected APIs require workspace permissions.
Development access headers are blocked in hosted environments.
Account membership is verified on the server.
Account sign-in
PassTools uses database-backed authentication with email and password plus short-lived, signed browser sessions.
Implemented
Passwords are stored only as versioned, salted hashes.
Browser sessions use secure, HttpOnly cookies with CSRF and origin checks.
Password reset, recovery, and invitation delivery require configured messaging.
Application-managed MFA is planned and is not currently available.
Provider credentials
Wallet, billing, email, and SMS connections require credentials from the provider account owner.
Setup required
Credential values are not shown in provider status views.
Paddle is the supported billing connection.
Signed wallet passes require Apple and Google provider credentials.
Audit and operations
PassTools records account activity and shows provider job status for operational review.
Available
Activity records include the signed-in user when available.
Provider jobs expose current processing status.
Operational checks support release and incident review.
Public endpoints
Public pass links use non-guessable identifiers and request limits to reduce misuse.
Protected
Public pages return only the fields needed to display a pass.
Unavailable wallet actions do not return signed passes.
Request limits protect public pass routes.
Privacy and terms
The privacy and terms pages are drafts and are not final legal policies.
Legal review required
Draft privacy and terms pages are available for review.
Each page clearly identifies its draft status.
Final wording requires legal approval.
Before you go live
Complete these account-specific steps before using PassTools with live customer data.
Review MFA requirements and configure password-recovery delivery
Required
Add Apple and Google Wallet credentials
Required
Connect Paddle and verify billing notifications
Required
Approve email and SMS senders
Required
Configure your production domain and monitoring
Required
Complete legal review of privacy and terms
Required
Ready to create your first pass?
Create a sandbox to design templates, add recipients, and explore the pass lifecycle.
PassTools
Create and manage Apple Wallet and Google Wallet pass programs, campaigns, approvals, and integrations.
Product
Features
Pricing
Developers
Docs
Security
Demo
Privacy
Terms
Help