Security & Auth
Security & Authentication
Developer token isolation, two-factor authentication, AES-256-GCM encryption, and SSRF defenses.
Security & Authentication
ZyVOP is built for developers who care deeply about credentials, token isolation, and content security.
Developer Tokens (zv_ prefix)
ZyVOP issues high-entropy developer tokens formatted as:
zv_<48-hex-character-token>- Format:
zv_prefix followed by 48 hexadecimal characters (192 bits of cryptographic randomness). - Scope: Developer tokens authorize the developer REST API and MCP tools, including content creation, scheduling, distribution, and supported read-only analytics. They are not accepted as web-session or GraphQL credentials.
- Revocation: You can instantly rotate or revoke developer tokens from ZyVOP Developer Settings without disrupting your main web session or changing your password.
Two-Factor Authentication (2FA / TOTP)
ZyVOP supports Time-based One-Time Passwords (TOTP) compatible with:
- 1Password
- Google Authenticator
- Apple Passwords & iCloud Keychain
- Authy
Setup Walkthrough
- Navigate to Account Settings → Security.
- Click Enable Two-Factor Authentication.
- Scan the generated QR code with your authenticator application.
- Store your Emergency Backup Codes in a secure location.
- Enter the 6-digit confirmation code to activate.
Third-Party Credential Protection
Connecting publishing platforms (DEV.to, Hashnode, Medium, Bluesky, WordPress) requires storing external API credentials. ZyVOP applies the following safeguards:
- AES-256-GCM Encryption: All integration credentials (API keys, app passwords, OAuth refresh tokens) are encrypted at rest using AES-256-GCM with unique cryptographic initialization vectors (IVs).
- Server-Side Handling: Decryption keys are restricted to the server-side runtime. Integration credentials are designed not to be returned in GraphQL responses, browser payloads, or application logs.
- Local-Only Publishing Option (
--local): If your company's security policies forbid storing external keys in the cloud, you can use the CLI's--localflag to execute cross-posting directly from your local terminal or private CI runner without uploading keys to ZyVOP.
Outbound SSRF Protection
To prevent Server-Side Request Forgery (SSRF) when re-hosting images and calling external webhooks, ZyVOP's HTTP egress engine enforces strict IP filtering:
- Rejects requests to loopback addresses (
127.0.0.0/8,::1). - Blocks private IPv4/IPv6 subnets (
10.0.0.0/8,172.16.0.0/12,192.168.0.0/16). - Denies cloud metadata endpoints (
169.254.169.254). - Enforces strict content-type and maximum byte-length caps on all external media streams.