Skip to content

Billing and security / Security and privacy

Security and privacy

How Push protects keys, browser addresses and notification content, and what you should never send.

API keys#

  • Push stores API keys only as SHA-256 hashes. It keeps the first 12 characters so you can tell keys apart, and cannot show a key again.
  • A revoked key stops working on the next request.
  • Live keys are refused from browsers: a /v1 request with an Origin header and a live key gets 403 FORBIDDEN. Test keys still work there, and the connect and events endpoints stay open to browsers because Push's own pages call them. A key in app code can still be copied, so keep keys on your server. See Authentication.

Browser addresses and signing keys#

  • Each connected browser's push address and its encryption keys are encrypted at rest with AES-256-GCM.
  • Each project has its own VAPID signing key pair. The private key is encrypted at rest and never leaves Push.
  • Messages are encrypted end to end for the browser (aes128gcm), so the vendor's push service cannot read them.

Content retention#

Notification content (title, body, links, images, actions and data) is kept only as long as the project's retention setting allows. Choose it in the project's settings in the dashboard:

SettingContent is removed
7 days (default)7 days after the notification was created.
30 days30 days after the notification was created.
Do not keep itOnce sending is done, within about 60 minutes.
  • Content is never removed while an attempt is still queued or processing; it waits until every attempt has finished.
  • Statuses, counts and click events stay after the content is gone.
  • Notifications, with their attempts, are deleted entirely after 90 days.

What not to send#

WarningNotifications can show on lock screens, shared screens and paired watches. Never put passwords, one-time codes, card numbers or other secrets in a title, body or URL.

What Push connects to#

  • Push sends only to the official push services of Google, Mozilla, Apple and Microsoft, and rejects any other address when a browser connects. See supported push services.
  • Push never fetches your icon, badge or image URLs. The person's browser does, when it shows the notification.

Browser events#

  • When a browser connects it receives an event token: an HMAC signature of its own browser id. It uses that token to report clicks, action buttons and dismissals, and to disconnect itself.
  • A token only works for its own browser and that browser's attempts. It cannot read anything, send anything or touch other browsers.
  • A browser is connected only after a person clicks to enable notifications and allows the browser's prompt. Push never asks on page load.
  • The person can disconnect at any time from the connect page, or block notifications in the browser.