Integration best practices
The habits that make an integration safe, frugal and robust against errors.
Security
- Store tokens and webhook secrets in a secret manager, never in code. A committed token is recognised by its
nf_prefix: revoke it at once. - One token per integration, with only the scopes it needs. Revoking one does not cut the others.
- Verify the signature of every webhook, on the raw body, in constant time.
Safe writes
- Send an
Idempotency-Keyon every creation, and the same key when you retry. - Retry
5xxand429with an increasing delay; never retry a401, a403or a422without changing anything.
Saving rate
- Subscribe a webhook rather than polling; if you poll, space the calls and respect
Retry-After. - Send back the
ETagyou received inIf-None-Match: a304response costs nothing. - Read the issue summary before paginating their occurrences.
Reading figures honestly
nullmeans "not measured", never zero. An average travels with its denominator: read it.- A truncated or blocked crawl (
comparable: false) does not compare. - Rely on
code, never ontitle, which is translated.