ZYVOPDOCS
MULTI-PLATFORM SYNC
Security & Auth

Security & Authentication

Developer token isolation, two-factor authentication, AES-256-GCM encryption, and SSRF defenses.

Security & Authentication

ZyVOP is built for developers who care deeply about credentials, token isolation, and content security.


Developer Tokens (zv_ prefix)

ZyVOP issues high-entropy developer tokens formatted as:

zv_<48-hex-character-token>
  • Format: zv_ prefix followed by 48 hexadecimal characters (192 bits of cryptographic randomness).
  • Scope: Developer tokens authorize the developer REST API and MCP tools, including content creation, scheduling, distribution, and supported read-only analytics. They are not accepted as web-session or GraphQL credentials.
  • Revocation: You can instantly rotate or revoke developer tokens from ZyVOP Developer Settings without disrupting your main web session or changing your password.

Two-Factor Authentication (2FA / TOTP)

ZyVOP supports Time-based One-Time Passwords (TOTP) compatible with:

  • 1Password
  • Google Authenticator
  • Apple Passwords & iCloud Keychain
  • Authy

Setup Walkthrough

  1. Navigate to Account Settings → Security.
  2. Click Enable Two-Factor Authentication.
  3. Scan the generated QR code with your authenticator application.
  4. Store your Emergency Backup Codes in a secure location.
  5. Enter the 6-digit confirmation code to activate.

Third-Party Credential Protection

Connecting publishing platforms (DEV.to, Hashnode, Medium, Bluesky, WordPress) requires storing external API credentials. ZyVOP applies the following safeguards:

  1. AES-256-GCM Encryption: All integration credentials (API keys, app passwords, OAuth refresh tokens) are encrypted at rest using AES-256-GCM with unique cryptographic initialization vectors (IVs).
  2. Server-Side Handling: Decryption keys are restricted to the server-side runtime. Integration credentials are designed not to be returned in GraphQL responses, browser payloads, or application logs.
  3. Local-Only Publishing Option (--local): If your company's security policies forbid storing external keys in the cloud, you can use the CLI's --local flag to execute cross-posting directly from your local terminal or private CI runner without uploading keys to ZyVOP.

Outbound SSRF Protection

To prevent Server-Side Request Forgery (SSRF) when re-hosting images and calling external webhooks, ZyVOP's HTTP egress engine enforces strict IP filtering:

  • Rejects requests to loopback addresses (127.0.0.0/8, ::1).
  • Blocks private IPv4/IPv6 subnets (10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16).
  • Denies cloud metadata endpoints (169.254.169.254).
  • Enforces strict content-type and maximum byte-length caps on all external media streams.

On this page