Integrate ABlyftConsent & security

Security

How access to ABlyft is protected, what the snippet sends, and what to keep in mind when integrating.

This page lists the security-relevant behavior of the snippet, the REST API and the MCP server that we can describe from how they work. It is not a compliance statement. For questions about certifications, data processing or contracts, contact ABlyft support.

Access to your account

  • Roles. Each team member has one role (viewer, member, admin or owner). The role decides what someone can read and change, in the app, in the API and through the MCP server. See Roles & permissions.
  • API tokens let scripts act on your behalf in the REST API. You create and revoke them in your personal settings under API Tokens, see Authentication.
  • MCP connections let AI assistants act on your behalf. They are authorized with a login step (OAuth) and listed under MCP Connections in your personal settings, where you can revoke them. See MCP server.

Treat tokens like passwords

A token has the permissions of your user within your teams. Store it in a secret manager, never in front-end code or in a repository. If a token may have leaked, revoke it in the token list and create a new one. Prefer Read only tokens when write access is not needed.

What the snippet is

The snippet is a public JavaScript file on the CDN (https://cdn.ablyft.com/s/<project ID>.js). Anyone who knows the URL can read it.

Do not put secrets into the snippet

The snippet contains the configuration of your running experiments, audiences, pages and goals, including the JavaScript and CSS of your variations and your project code. Do not put passwords, API keys or private data into experiment code, helper code or audience rules.

What the snippet sends

The snippet sends events to the tracker, by default https://log.ablyft.com, with navigator.sendBeacon(). A request contains:

PartContent
projectId, source, snippetVersionYour project ID, the fixed value ablyft-snippet and the snippet version
user.experimentsBucketThe visitor's assignments: experiment ID to variation ID
user.attributesThe visitor's browser user agent, the page URL, visitor type (new or returning) and device type (desktop, tablet, mobile)
eventsThe events, each with a type (bucketing, pageview, click, custom, revenue), a value, a timestamp, an ID, and for goals the goal ID and variation IDs

The request has no field for a visitor ID, name or email address. Because the URL and user agent are sent, avoid putting personal data into URLs of pages that run experiments.

The snippet only sends events when the visitor is part of at least one experiment, not for bots, and not when the visitor opted out or the browser sends Do Not Track while Adhere to Do Not Track is on. See Storage & privacy.

Frames

The snippet does not run inside iFrames by default, see Requirements to allow it.

URL parameters can change what a visitor sees

Some URL parameters change what the visitor's own browser shows, for example ablyft_preview and ablyft_set_bucketing. They only affect the browser that opens the URL. Preview mode also turns off goal tracking in that browser. Experiments in preview status are part of the public snippet, so do not rely on a variation staying secret before it launches.

Content Security Policy

If you use a Content Security Policy, see Requirements for the domains to allow and the use of eval.

Next steps

On this page