nomiDocumentation
SupportBack to site
  • Getting started

    • Introduction
    • What is Nomi?
    • Quick start
    • Concepts
    • Authentication
  • Credentials

    • Create a credential
    • Issue a credential
    • Credential lifecycle
    • Revoke a credential
    • Verify a credential
    • QR verification
  • Distribution

    • Apple Wallet
    • Google Wallet
    • Email
    • Credential delivery
    • Bulk issuance
  • API

    • API overview
    • Authentication
    • Credentials API
    • Recipients
    • Verification
    • Revocation
    • Webhooks
    • Errors
  • Integrations

    • Moodle
    • WordPress
    • REST API
    • Webhooks
  • Security

    • Authentication
    • API keys
    • Webhook security
    • Data protection
    • Best practices
  • Resources

    • FAQ
    • Glossary
    • Changelog
  1. Documentation
  2. /
  3. Security
  4. /
  5. Best practices

Best practices

The handful of habits that separate an integration that ages well from one that pages somebody.

  • Keep the key on a server. A browser, a handheld scanner and a mobile app all call *your* service; your service calls Nomi. Keys, secrets and tokens stay in the server environment and never reach a page.
  • Send only what a credential needs. attributes accepts anything; a whole personnel or customer record does not belong in one. See Recipients.
  • Send an Idempotency-Key on every write, derived from something stable on your side — an order number, a student id and a term, a payroll run.
  • Pace a long run. One queue with backoff, not many connections racing each other.
  • Be told rather than poll. Subscribe to credential.* instead of asking for a credential every thirty seconds.
  • Verify webhooks before acting, and make the handler idempotent.
  • Suspend before you revoke when the relationship might resume. Revocation is permanent.
  • Preview a policy before applying it. POST /v1/policies/{id}/preview answers who it would affect.
  • Watch credential.channel.failed. A credential that is valid and a pass that never rendered look identical from a dashboard that only reads the credential.
  • Deactivate, do not delete. The history of what somebody held has to keep naming them.
If you are about to write a loop that issues thousands of credentials, read Bulk issuance first. It is shorter than the loop.

FAQ

The questions that come up.

Glossary

The words, defined.

PreviousData protectionNextFAQ

Still stuck?

If this page did not answer it, the Help Center has the operational side of the same question — and a person reads what you send.

Go to the Help Center →
nomi

Digital credential infrastructure. Create, issue and manage credentials from the systems you already use.

Operated by

Country and currency

Platform

  • How it works
  • Templates
  • Lifecycle
  • Developers
  • Pricing
  • FAQ
  • Nomi Academic

Credentials

  • Memberships
  • Employee IDs
  • Student IDs
  • Events & loyalty

Developers

  • Documentation
  • Quick start
  • API reference
  • Webhooks
  • Integrations

Support

  • Help Center
  • Apple & Google Wallet
  • Verification
  • Contact support

Company

  • Request a demo
  • Talk to Nomi
  • Legal
  • Codingraph
PrivacyTermsCookiesSecurityContact

© 2026 Codingraph S.A. All rights reserved.

Nomi is a registered trademark used by Codingraph S.A. under licence.

Billed in USD

Apple Wallet and Google Wallet are trademarks of their respective owners.