Security and privacy
How Push protects keys, browser addresses and notification content, and what you should never send.
API keys#
- Push stores API keys only as SHA-256 hashes. It keeps the first 12 characters so you can tell keys apart, and cannot show a key again.
- A revoked key stops working on the next request.
- Live keys are refused from browsers: a
/v1request with anOriginheader and a live key gets403 FORBIDDEN. Test keys still work there, and the connect and events endpoints stay open to browsers because Push's own pages call them. A key in app code can still be copied, so keep keys on your server. See Authentication.
Browser addresses and signing keys#
- Each connected browser's push address and its encryption keys are encrypted at rest with AES-256-GCM.
- Each project has its own VAPID signing key pair. The private key is encrypted at rest and never leaves Push.
- Messages are encrypted end to end for the browser (
aes128gcm), so the vendor's push service cannot read them.
Content retention#
Notification content (title, body, links, images, actions and data) is kept only as long as the project's retention setting allows. Choose it in the project's settings in the dashboard:
| Setting | Content is removed |
|---|---|
| 7 days (default) | 7 days after the notification was created. |
| 30 days | 30 days after the notification was created. |
| Do not keep it | Once sending is done, within about 60 minutes. |
- Content is never removed while an attempt is still
queuedorprocessing; it waits until every attempt has finished. - Statuses, counts and click events stay after the content is gone.
- Notifications, with their attempts, are deleted entirely after 90 days.
What not to send#
WarningNotifications can show on lock screens, shared screens and paired watches. Never put passwords, one-time codes, card numbers or other secrets in a title, body or URL.
What Push connects to#
- Push sends only to the official push services of Google, Mozilla, Apple and Microsoft, and rejects any other address when a browser connects. See supported push services.
- Push never fetches your
icon,badgeorimageURLs. The person's browser does, when it shows the notification.
Browser events#
- When a browser connects it receives an event token: an HMAC signature of its own browser id. It uses that token to report clicks, action buttons and dismissals, and to disconnect itself.
- A token only works for its own browser and that browser's attempts. It cannot read anything, send anything or touch other browsers.
Consent#
- A browser is connected only after a person clicks to enable notifications and allows the browser's prompt. Push never asks on page load.
- The person can disconnect at any time from the connect page, or block notifications in the browser.