Documentation version
DeveloperApplies to 1.0.0

Security and integration notes

Key considerations for API keys, browser-visible tile credentials, geolocation and CSV handling.

Google browser API key

A browser key is visible to site visitors by design. Protect it with appropriate Google Cloud referrer and API restrictions rather than attempting to hide it in front-end JavaScript.

Custom XYZ tokens

Any credential embedded in a browser tile URL is visible to visitors. Use only tokens designed for client-side use.

Geolocation

Near Me uses browser permission and local distance calculation. Velox does not persist visitor coordinates.

CSV

The import/export workflow includes validation and spreadsheet-injection protection. Administrators should still treat bulk files as data inputs requiring review.

External services

Site owners are responsible for provider terms, notices, attribution and applicable privacy obligations.