Security, limitations and troubleshooting

Protect ASP client credentials

Handle the ASP client secret and endpoint settings as privileged integration credentials.

Audience: CRM staffPermission: AdministratorModule v1.0.0
Exact navigationAdmin Area → EmaraTax eInvoicing → Settings → Accredited Service Provider
Before you begin
  • Use the exact navigation above and confirm the intended record, tenant, customer, property, document or date range.
  • Confirm module activation and the stated permission instead of using another staff member’s account.
  • For public, email, provider, finance, signature or destructive actions, use a controlled test record before production use.

What this guide covers

Handle the ASP client secret and endpoint settings as privileged integration credentials. These instructions follow the supplied module’s live menus, controller actions, form fields, model validation and downstream effects.

Exact step-by-step process

  1. Sign in to the staff admin area and open Admin Area → EmaraTax eInvoicing → Settings → Accredited Service Provider.
  2. Confirm that your account meets the access rule: Administrator.
  3. Open the required record or configuration and review its current values before making a change.
  4. Complete the displayed fields or action exactly as described in this guide.
  5. Save, submit, download or confirm the action using the button presented by the module.
  6. Reopen the source record and verify the expected status, output, notification, file or linked record.

Fields, choices and supported possibilities

Sensitive valuesASP client ID and client secret
Storage behaviourStored in CRM options by the supplied module
Category/help-centre/category/emaratax-einvoicing/
Topic/help-centre/topic/emaratax-einvoicing-security-troubleshooting/

Code-backed validations and workflow rules

  • The supplied module does not implement one-way encryption or automatic rotation for the ASP secret.
  • Restrict settings access and rotate provider credentials through the provider’s process.

Expected result and verification

  • The protect asp client credentials workflow completes without bypassing the module’s permission and validation checks.
  • The saved value, generated file, status, notification or linked CRM record is visible from the same workspace.
  • Any validation message remains visible until the source data or setting is corrected.

Security, privacy and operational checks

  • Use least-privilege staff access and do not use another person’s account to reach a hidden action.
  • Review personal, financial, identity and compliance data before sending, exporting or exposing it through a public link.
  • Test configuration, email, public forms, accounting effects and provider connections with controlled records before production-wide use.